ICAM Operations Engineer – Enterprise Authentication Services
Posted 10hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
ICAM Operations Engineer sustaining enterprise authentication and federation services for millions of DoD identities. Supporting GDIT’s mission-critical remote IAM operations.
Responsibilities:
- Provide Tier III operational support for enterprise Identity Provider services used by millions of DoD users
- Perform daily operations, monitoring, and troubleshooting of Microsoft ADFS infrastructure
- Investigate and resolve incidents involving authentication, federation trust, certificates, tokens, claims rules, and identity assertions
- Manage ITSM incident, problem, and change tickets with engineering, cybersecurity, and infrastructure teams
- Support enterprise onboarding and integrations by validating application configurations and federation behavior
- Troubleshoot SAML, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication issues
- Perform certificate lifecycle management, configuration updates, monitoring reviews, health checks, and patch validation
- Maintain authentication policies, claims rules, attribute mappings, and token issuance configurations
- Support enterprise SSO, MFA, Conditional Access, and phishing-resistant authentication
- Contribute to Zero Trust operational readiness
- Participate in Agile support and continuous improvement activities
- Document procedures, incident resolutions, troubleshooting steps, and system behaviors
Requirements:
- Active Secret Clearance at minimum; Interim Secret Clearances are not allowed
- U.S. citizenship required
- Bachelor’s Degree in a related technical discipline, or equivalent combination of education, technical certifications or training, or work experience
- DoD 8570/8140 IAT Level II certification (Security+ CE or higher)
- Minimum of 5 years of experience, including at least 3 years supporting IAM, Authentication, Federation, or ICAM-related technologies
- Hands-on experience with Microsoft ADFS in enterprise operational environments
- Strong understanding of authentication, authorization, and federation concepts
- Familiarity with SAML, OAuth, OIDC, WS-Federation, certificates, and related identity technologies
- Experience with PKI, certificate-based authentication, smart cards, or MFA
- Experience supporting application integrations with identity/federation platforms
- Familiarity with Active Directory, LDAP, and enterprise identity repositories
- Strong troubleshooting skills for identity/ADFS issues and Tier III diagnostics
- Ability to document findings and communicate technical issues effectively
- Desired: experience with ADFS farms, WAP, load balancers, disaster recovery, modern identity platforms, DoD ICAM, NIST 800-63, phishing-resistant/passwordless authentication, PowerShell, monitoring, performance tuning, PKI/certificate services, CAC authentication, DoD credentialing, Docker, or Kubernetes
Benefits:
- Comprehensive medical plan options, including plans with Health Savings Accounts
- Dental plan options
- Vision plan
- 401(k) plan with company match
- Full-flex work weeks
- Paid vacation, sick, personal, holiday, parental, military, bereavement, and jury duty leave
- Typically 15 days of paid leave per calendar year
- 10 paid holidays per year
- Up to 160 hours of paid family leave in a rolling 12-month period for eligible employees
- Short- and long-term disability benefits
- Life insurance
- Accidental death and dismemberment insurance
- Personal accident insurance
- Critical illness insurance
- Business travel and accident insurance
- AI-powered career tool identifying career steps and learning opportunities
- Internal mobility team supporting career goals
- Award-winning culture of innovation and military-friendly workplace


















