ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
GDIT has an opportunity for an Identity Provider (IdP) Engineer supporting a large line of business delivering enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by helping design, integrate, operate, and maintain enterprise Identity Provider services that provide secure authentication and federation for more than 4 million DoD enterprise identities. This is an onsite position at USA MD Fort Meade.
About the role
The ideal candidate has at least 3 years of hands-on experience supporting authentication or identity systems and is eager to grow deeper into enterprise ICAM technologies. Strong foundational skills in Microsoft Active Directory Federation Services (ADFS), authentication protocols, and troubleshooting are essential. This role provides opportunities to work with senior engineers, contribute to mission-critical authentication services, and expand your technical skillset across large-scale identity platforms.
Responsibilities
- Support the design, configuration, and sustainment of enterprise Identity Provider (IdP) services used by millions of DoD users.
- Assist in administering and maintaining Microsoft Active Directory Federation Services (ADFS) infrastructure supporting authentication and federation.
- Help configure federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.
- Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
- Collaborate in onboarding and integrating applications into the authentication and federation ecosystem.
- Help develop and maintain authentication policies, claims rules, attribute mappings, and token issuance configurations.
- Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication mechanisms.
- Work with cybersecurity, Active Directory, cloud, infrastructure, and application teams to deliver secure authentication services.
- Contribute to Zero Trust Architecture objectives through modern authentication and federation capabilities.
- Assist in monitoring, troubleshooting, and resolving authentication, federation, trust, certificate, and token issues.
- Support the development of resilient, highly available authentication services for mission-critical workloads.
- Help create technical documentation including architecture diagrams, SOPs, integration guides, and operational procedures.
- Participate in Agile development activities and continuous improvement efforts.
- Identify technical risks and contribute to identity modernization initiatives.
Requirements
- Active Secret Clearance (Interim Secret not allowed).
- US Citizenship required.
- Bachelor’s degree in a related technical field, or equivalent combination of education, certifications, and experience.
- DoD 8570/8140 IAT Level II certification (Security+ CE or higher).
Qualifications
- Minimum 3 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM-related technologies.
- Experience supporting or implementing Microsoft ADFS in enterprise environments.
- Strong understanding of authentication, authorization, and federation concepts.
- Familiarity with SAML, OAuth, OIDC, WS-Federation, and related identity technologies.
- Experience with PKI, certificate-based authentication, smart cards, or MFA.
- Experience supporting application or API integrations with identity/federation platforms.
- Familiarity with Active Directory, LDAP, and enterprise identity repositories.
- Ability to configure or support claims rules, attribute mappings, or token policies.
- Experience working with Windows or Linux server environments.
- Ability to document technical findings and communicate effectively.
- Self-starter with a desire to learn and grow in enterprise identity operations.
Skills
- Authentication Protocols
- Secure Authentication
- Single Sign-On (SSO)
Desired Skills & Knowledge
- Experience with ADFS farms, Web Application Proxy (WAP), load balancers, or disaster recovery setups.
- Exposure to modern identity platforms such as Microsoft Entra ID, PingFederate, PingAccess, Okta, or Keycloak.
- Familiarity with DoD ICAM or federation initiatives.
- Understanding of NIST 800-63 Identity Assurance models.
- Exposure to phishing-resistant authentication or passwordless technologies.
- Experience supporting Zero Trust concepts.
- Basic PowerShell scripting for ADFS or identity operations.
- Experience with monitoring, performance tuning, or troubleshooting authentication issues at scale.
- Familiarity with PKI/certificate services, CAC authentication, or DoD credentialing.
- Awareness of container technologies (Docker, Kubernetes).
Benefits
- Comprehensive medical, dental, and vision plan options.
- 401(k) plan with company match (pre and post-tax contributions up to IRS annual limits).
- Full-flex work week to support work/life balance.
- Paid time off including vacation, sick, personal time, holidays, parental, military, bereavement, and jury duty leave.
- Short and long-term disability benefits, life insurance, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance.
- AI-powered career tool for identifying career steps and learning opportunities.
- Internal mobility team focused on career growth.
Pay
The likely salary range for this position is $140,250 - $189,750. Salary will be set based on experience, geographic location, and possibly contractual requirements.
Schedule
- Scheduled Weekly Hours: 40
- Travel Required: Less than 10%
- Telecommuting Options: Remote Work Location (onsite at USA MD Fort Meade)