IAM Lead
ICF · Richmond, VA · 4 days ago
OTHR$108k–$184k/yrFull-time
About the role
This role is contingent upon a contract award. ICF is seeking an IAM Lead to architect, implement, and operate the identity and access management platform for a federal technology program.
Responsibilities
- Architect, configure, and maintain identity platforms including Entra ID, Entra External ID, and Okta, covering authentication, authorization, provisioning, and lifecycle management across all users, applications, and devices.
- Configure and enforce phishing-resistant authentication for all users, including passkeys, FIDO2 security keys, WebAuthn, and biometrics.
- Drive the transition away from legacy authentication methods toward a fully passwordless posture.
- Define and implement Zero Trust access rules based on user risk, device health, location, and behavior using risk-based and conditional access policies.
- Design, configure, and operate authorization models including RBAC, PBAC, and ABAC, with fine-grained permissions and attribute-based access rules aligned to job function and least-privilege principles.
- Manage privileged accounts and administrative roles using privileged access management (PAM) and just-in-time elevation, ensuring that standing admin access is minimized and all elevated access is logged and time-bound.
- Build and maintain HR-driven joiner, mover, and leaver automation, including automated provisioning, license assignment, role changes, access revocation, and data archival triggered by HR system events.
- Federate external identities including partners, contractors, and external collaborators using Entra External ID or equivalent, including self-service registration, verification workflows, and consent management.
- Configure identity proofing and verification to NIST IAL and AAL levels where required, coordinating with cybersecurity and compliance teams on assurance requirements.
- Integrate applications and APIs with identity platforms using OIDC, OAuth2, SAML, and SCIM for single sign-on and automated provisioning.
- Maintain identity data quality and consistency across directories, HR systems, and applications, including synchronization, schema management, and attribute mapping.
- Support compliance and audit activities by producing access reports, certifications, attestations, and evidence of controls.
- Document identity architectures, configurations, standards, and runbooks.
- Provide guidance to application teams on how to onboard to central identity platforms and implement authentication best practices.
Requirements
- Bachelor's degree or equivalent 7+ years of experience in identity and access management engineering or a related discipline.
- 3+ years of hands-on experience designing and operating Entra ID or Okta in production environments, including conditional access, lifecycle management, and federation.
- 2+ years implementing PAM solutions and just-in-time elevation controls for privileged accounts.
- 2+ years configuring authorization models including RBAC, PBAC, or ABAC in enterprise environments.
- 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies.
- U.S. Citizenship required due to federal contract requirements.
Qualifications
- Experience implementing NIST SP 800-63 identity assurance levels (IAL/AAL) in a federal context.
- Experience federating external identities using Entra External ID, including self-service registration and consent workflows.
- Familiarity with FISMA, NIST 800-53, and Zero Trust architecture requirements as they apply to identity and access.
- Experience integrating identity platforms with HR systems for automated joiner, mover, and leaver workflows.
- Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Okta Certified Administrator, or equivalent.
- Experience supporting identity incident response including account takeover, phishing, and access abuse investigations.
Skills
- Strong understanding of identity and access management concepts and standards.
- Hands-on experience with IAM tools and technologies such as Entra ID, Entra External ID, Okta, and similar platforms.
- Knowledge of NIST guidelines and best practices for identity assurance and zero trust.
- Experience with authorization models and access control mechanisms like RBAC, PBAC, and ABAC.
- Ability to manage and secure privileged accounts and access.
- Proficiency in scripting languages and automation tools for identity management tasks.
- Experience with HR systems and integration with identity platforms.
- Strong communication and collaboration skills with cybersecurity and enterprise architecture teams.
Benefits
Not specified.
Pay
$108,006.00 - $183,610.00
Schedule
Remote-friendly position with occasional onsite requirements in the Washington, DC Metro area.