Live opening · Posted 1 day ago

Senior IdAM Engineer IRES - SSFB/HSV/FBEL

Amentum (formerly PAE) · 3 Locations
Workday
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyAmentum (formerly PAE)
Location3 Locations
SkillsPython, Java, AWS, Azure
SourceWorkday
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
7 min from Workday publishing this role to us finding it
7 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,024 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Position Title: Senior IdAM Engineer
Location: Schriever Space Force Base, Colorado Springs, CO, Redstone Arsenal, Huntsville, AL or Fort Belvoir, VA
Relocation Assistance: None available at this time
Remote/Telework: NO - Not available for this position
Clearance Type: DoW Secret
Shift: Day shift
Travel Required: Up to 10% of the time
Description of Duties:
As a Senior IdAM Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, deploying, automating, securing, and sustaining the Identity, Credential, and Access Management (IdAM / ICAM) ecosystem underpinning the Missile Defense Agency’s (MDA) unified digital environment.
In this role, you will help advance NGE’s hybrid and multi-cloud identity modernization strategy by implementing robust Identity Governance and Administration (IGA) workflows, federation and Single Sign-On (SSO) services, enterprise directory integrations, and DoD/NSS Public Key Infrastructure (PKI) aligned with the Zero Trust Security Model. You will work across engineering, cybersecurity, hybrid cloud, infrastructure, contract consortium performers, and Government stakeholder teams to deliver resilient identity services across on-premises and cloud-hosted mission environments.
You will play a key role in standardizing identity lifecycle automation, enhancing authentication security, eliminating credential risks, strengthening access controls, and ensuring continuous compliance with DoD, DISA, and MDA security requirements.
Description of Duties
Identity Governance & Administration (IGA):
· Implement, deploy, configure, and sustain SailPoint IdentityIQ (IIQ) solutions, including Operations & Maintenance (O&M), platform upgrades, capability enhancements, and enterprise application onboarding.
· Design and customize identity lifecycle management workflows (joiner, mover, leaver), certification campaigns, role-based/attribute-based access controls (RBAC/ABAC), custom Java rules, and compliance reporting.
Federation & Single Sign-On (SSO):
· Engineer, deploy, and maintain PingIdentity PingFederate services to enable secure, federated Single Sign-On (SSO) across enterprise and mission partner applications.
· Lead application onboarding and integration utilizing modern authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and phishing-resistant Multi-Factor Authentication (MFA).
Hybrid Cloud Identity Integration:
· Implement and sustain secure identity and access architectures across hybrid multi-cloud environments, including Microsoft Entra ID (Azure AD) and Amazon Web Services (AWS IAM and AWS IAM Identity Center) operating within DoD IL5/IL6 boundaries.
· Ensure secure synchronization, conditional access policy enforcement, and seamless identity interoperability between on-premises domains and cloud service providers.
Directory Services & Authentication:
· Configure, optimize, and administer Microsoft Directory Services, including Active Directory Domain Services (AD DS) and Active Directory Federation Services (AD FS), maintaining high availability and schema integrity.
· Maintain Kerberos, LDAP/S, and federated trust configurations across complex multi-forest and segmented enterprise environments.
DoD & NSS Public Key Infrastructure (PKI):
· Deploy, maintain, and support DoD and National Security Systems (NSS) Public Key Infrastructure (PKI) components, including Certificate Authorities (CAs), hardware tokens (CAC/PIV/SIPR tokens), Certificate Validation services (OCSP/CRL), and certificate lifecycle management.
· Ensure cryptographic enforcement and certificate-based authentication across all network boundaries, endpoints, and server infrastructure.
Zero Trust Architecture & Security Compliance:
· Implement dynamic, identity-centric security policies and controls supporting the DoD Zero Trust Strategy and NIST SP 800-207.
· Harden identity platforms and services in accordance with DISA STIGs, Risk Management Framework (RMF), and MDA cybersecurity requirements to support continuous Authorization to Operate (cATO).
Consortium & Cross-Functional Engineering Collaboration:
· Collaborate with multi-contractor consortium performers, systems engineers, network architects, DevSecOps teams, and Government personnel to standardize identity interfaces and integration protocols.
· Serve as an identity integration focal point during Joint Interoperability Test events, cross-domain coordination, and enterprise cutovers.
Automation & Scripting:
· Develop and maintain automated provisioning scripts, API integrations (SCIM, REST), and administrative routines utilizing PowerShell, Bash, Python, or Java to streamline identity operations and eliminate manual configuration drift.
Documentation & Engineering Governance:
· Author and maintain comprehensive engineering deliverables, including Low-Level Designs (LLDs), Interface Control Documents (ICDs), standard operating procedures (SOPs), deployment runbooks, and test/validation plans.
Technology Evaluation & Continuous Improvement:
· Research and assess emerging IdAM/ICAM technologies, cloud identity features, and PAM/IGA enhancements to optimize security posture, scalability, and user experience across NGE.
Stakeholder Reporting & Technical Communication:
· Provide technical status, risk analysis, and engineering recommendations to program leadership and Government stakeholders.
· Translate complex identity, PKI, and federation requirements into actionable engineering plans and mission outcomes.
Resumes, in month and year format, must be submitted with application in order to be considered for the position. The selected candidate may be assigned as an employee for one of our teammate companies.
Basic Requirements:
· Must have 12, or more, years of general (full-time) work experience
o May be reduced with completion of advanced education
· Must have 6, or more, years of dedicated Identity, Credential, and Access Management (IdAM / ICAM) experience.
· Must have 1, or more, years of experience in technical leadership, mentoring, or engineering management roles.
· Must have direct experience supporting the IRES contract or previous technical experience supporting the Missile Defense Agency (MDA).
· Must have demonstrated, hands-on, engineering proficiency across enterprise identity solutions, specifically:
· Must have a combination of experience, or familiarity, with the following:
o SailPoint IdentityIQ (IIQ) (deployments, lifecycle workflows, rules, and connectors).
o PingIdentity PingFederate (SAML, OAuth2, OIDC, MFA federation).
o Microsoft Directory Services (AD DS, AD FS).
o Cloud Identity Management (Microsoft Entra ID, AWS IAM).
o DoD / NSS Public Key Infrastructure (PKI) (Certificate Authorities, validation, and token integration).
· Must hold a current DoW 8140/8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+ CE, CISSP).
· Must have an active DoW Secret security clearance with the ability to obtain a Top Secret clearance (or active Top Secret).
· Must have an active DoW Secret Security Clearance
Desired Requirements:
· Have an active DoW Top Secret clearance.
· Have a Bachelor’s degree, or higher, in Computer Science, Information Technology, or Cybersecurity.
· Professional certifications in core tools:
o SailPoint Certified IdentityIQ Engineer / Architect
o Ping Identity Certified Professional
o Microsoft Certified: Identity and Access Administrator Associate (SC-300)
o AWS Certified Security – Specialty
· Have experience integrating identity solutions with Privileged Access Management (PAM) platforms (e.g., CyberArk) and enterprise ITSM systems (e.g., ServiceNow).
· Have experience with Model-Based Systems Engineering (MBSE) concepts and Agile/SAFe methodologies within DoD/MDA environments.
This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.
Compensation Details:
$175,000 – $220,000
The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.
Benefits Overview:
Our health and welfare benefits are designed to support you and your priorities. Offerings include:
Health, dental, and vis

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App