ICAM Architect
FANTOM CORPORATION · Chantilly, VA · 1 wk ago
On-siteArt & CreativeFull-time
Responsibilities
- Define and maintain the enterprise ICAM architecture supporting the modernization of Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS)
- Lead the transition from legacy Policy Decision Point (PDP) technologies to modern authorization frameworks
- Design end-to-end architectures supporting identity services, authorization workflows, policy management, attribute services, and resource lifecycle management
- Develop architecture artifacts including sequence diagrams, data models, interface specifications, and system design documentation
- Partner with Technical Leads and engineering teams to validate modernization roadmaps, architectural decisions, and cloud migration strategies
- Design modern Policy Enforcement Point (PEP) and Policy Information Point (PIP) services supporting Attribute-Based Access Control (ABAC), dynamic policy evaluation, and event-driven authorization
- Develop enterprise authorization services, policy lifecycle automation, resource registration, and attribute orchestration capabilities
- Provide technical guidance to software engineering, DevOps, and operations teams throughout the development lifecycle
- Conduct architecture reviews, technical risk assessments, and compliance evaluations to ensure modernization objectives are achieved
- Drive improvements in automation, observability, deployment pipelines, scalability, resilience, and operational efficiency
- Evaluate emerging identity technologies, authentication methods, authorization frameworks, and integration patterns to improve enterprise ICAM capabilities
- Serve as a trusted technical advisor to program leadership, supporting strategic planning, budgeting, customer engagements, and long-term modernization initiatives
Requirements
- Must possess an active Top Secret Security Clearance
- Willingness to obtain a polygraph upon hire
- Bachelor's degree in Computer Science, Engineering, Information Technology, or another STEM discipline with 12+ years of relevant experience, or a Master's degree with 10+ years of relevant experience
- Strong experience designing distributed systems, microservices architectures, and cloud-native applications
- Experience supporting Identity, Credential, and Access Management (ICAM), enterprise identity services, or authorization and policy management platforms
- Strong understanding of Zero Trust architecture principles and enterprise security frameworks
- Experience translating mission requirements into scalable technical architectures and engineering solutions
- Experience working within Agile development environments, including Program Increment (PI) Planning and iterative software delivery
- Excellent communication, leadership, and stakeholder engagement skills
- Ability to obtain CompTIA Security+ certification within 90 days of hire
Desired Qualifications
- Experience with Kubernetes, OpenShift, or other container orchestration platforms
- Experience developing or integrating applications using Java and/or Python
- Experience with GitOps methodologies and modern DevSecOps practices
- Enterprise Architecture certifications such as TOGAF, Zachman, or equivalent
- Expertise with enterprise identity and authorization standards including X.509, SAML, OAuth2, OpenID Connect (OIDC), and LDAP
- Experience architecting enterprise ICAM solutions using Oracle Identity Management or similar enterprise identity platforms
- Experience designing Attribute-Based Access Control (ABAC), Role-Based Access Control (RBAC), Policy-as-Code, and Zero Trust access models
- Experience supporting Department of Defense or Intelligence Community identity and authorization systems