IAM Architect
CACI International Inc · Vienna, VA · 2 days ago
OTHR$132k–$290k/yrFull-time
About the role
CACI is seeking a skilled SailPoint Identity and Access Management (IAM) Architect to join a dynamic, high-performing team responsible for operating and maintaining an IdentityIQ platform for a government customer. As an IAM architect, you will provide technical leadership and guidance to program managers and key stakeholders, focusing on enterprise-level projects and solutions. In this capacity, the IAM Architect will design solutions that are to be executed by the IAM engineer team, playing a pivotal role on the team and helping to deliver next-generation IAM services.
Responsibilities
- Design IAM solutions to support PIV/Certificate Base Authentication, FIDO 2.
- Facilitate and support IAM integration into business applications and third parties, including Single Sign On enablement using modern protocols (SAML, OAuth, Open ID Connect).
- Collaborate with customers to define organization constructs/naming conventions and user access roles.
- Provide guidance with the development of process and workflows to support IAM operation activities such as user onboarding, user lifecycle management and privilege access management.
- Engage with, and advise stakeholders within the business on Identity and Access Management best practices.
- Define, improve, and support Azure Entra ID, Certificate Lifecycle Management and Privileged Access Management within the organization.
- Identify areas for delivery of automated solutions (e.g. onboarding/offboarding) and maturation of existing process.
- Work collaboratively alongside Microsoft Azure, Network, and Security Architects to ensure comprehensive integration and alignment across platforms.
- Coordinate with vendors to evaluate, test, and implement new technology solutions to enhance the IAM environment.
Qualifications
- Ability to obtain Department of Homeland Security (DHS) Entry On Duty (EOD) - Active EOD preferred.
- BA/BS + 10 years of applicable experience; AA + 15 years’ applicable experience.
- Experience in the Identity space with a background in identity management tools.
- Strong knowledge of HSPD12 and implementation of government smart card authentication.
- Expert knowledge of authentication with SAML, OAuth, OpenID, WSO2, and Kerberos.
- Prior experience in providing RBAC solutions for cloud solutions (e.g. Azure).
- Strong scripting and automation abilities including PowerShell.
- Understanding of Microsoft Azure PIM, Access Reviews, Service Principles, Managed Identities and ABAC.
- Strong knowledge of enterprise PKI integration with SCEP and ACME clients.
- Experience in creating technical architecture documentation.
- Strong communication and written skills.
- Desired: ITILv3 or v4 Foundation’s certification, Previous DHS or DoD experience, Microsoft Azure Fundamentals, CompTIA A+, or Network+, or Security+, Experience with Azure Cloud, scripting, and automation.
Pay
The proposed salary range for this position is $131,800 - $290,000.