Lead Identity and Access Management (ICAM) EngineerLeidos
Description
Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers. advanced enterprise-level identity solutions.
Candidate MUST:
Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance
Primary Responsibilities:
- Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services.
- Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms.
- Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles.
- Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations.
- Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping Identity, CyberArk).
- Provide technical leadership, mentoring, and peer review for IAM engineering staff.
- Support incident response and forensic investigations involving identity-related events.
- Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies.
- Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap.
Required Qualifications:
- Bachelor’s degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor’s degree. With a Master’s degree, 10 years of general experience is required.
- 8+ years of progressive experience focusing on identity and access management.
- 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture.
- Hands-on experience with at least two of the following IAM platform categories:
- IGA: Microsoft Identity Manager
- PAM: CyberArk, Beyond Trust
- SSO/Federation: Okta, Microsoft Entra ID, Ping Identity
- Directory Services: Active Directory, Azure AD/Entra ID, LDAP
- Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles).
- Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM).
- Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos.
- Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM).
- Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures.
- Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA).
- Strong experience with Entra B2B and B2C for external identity management.
- Experience with Entra AD Connect, including custom synchronization rules.
- Strong proficiency in PowerShell and Graph API for identity management automation.
- Familiarity with Zero Trust architecture and identity-related security best practices.
Preferred Qualifications:
- Relevant certifications, hold at least one or two of the following, aligned to seniority:
- CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- CyberArk Defender/Sentry/Guardian
- Okta Certified Professional/Consultant/Administrator
- Ping Identity Certified Professional
- CompTIA Security+
- Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp).
- Experience with Azure AD Verifiable Credentials and decentralized identity concepts.
- Understanding of biometric authentication methods and their Azure AD integration.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
August 5, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
