ICAM Lead
Maximus is a trusted federal partner supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with proven operational excellence, and a commitment to mission success for our customers. Joining Maximus means becoming part of a collaborative, mission-driven organization where teamwork, accountability, and professional growth are core to how we operate. We invest in our workforce through training, education, and career development, empowering professionals to deliver high-impact solutions while contributing to outcomes that matter at a national scale.
This position is contingent upon contract award and position availability. Selected candidates will receive a contingent offer of employment, which will become final only upon successful contract award to Maximus, availability of the position, and receipt of authorization to proceed. Ability to obtain and maintain a Public Trust is required. An active Public Trust and/or DHS suitability is preferred. U.S. citizenship or U.S. national status is required. This role is hybrid, allowing for remote work, but requires the ability to work onsite at one of the following locations in Northern Virginia: Springfield, Herndon, or Ashburn.
About the role
The ICAM Lead serves as the technical authority for enterprise Identity, Credential, and Access Management. This role provides architectural leadership for directory, federation, and Single Sign-On solutions, supports external partner identity integrations, and ensures secure, compliant access across IT and OT environments while coordinating closely with operations and cybersecurity teams.
Responsibilities
- Provide accountable technical leadership for Identity, Credential, and Access Management (ICAM) services, including on-premises, cloud, and hybrid platforms.
- Architect, manage, and evolve directory services, federation, and Single Sign On (SSO) capabilities to meet changing mission, security, and operational requirements.
- Oversee role-based access control (RBAC), privileged access management, and PIV-based MFA, enforcing least-privilege principles and compliance with agency security policies.
- Plan and execute ICAM technology refresh and lifecycle strategies, ensuring continuity, scalability, and alignment with federal standards.
- Coordinate closely with operations, cybersecurity, and incident response teams to maintain service availability, auditability, and compliance.
- Maintain comprehensive ICAM architecture documentation, audit trails, and reporting to support compliance, inspections, and continuous improvement.
- Support for IT and OT environments with 24x7 operational coverage.
Requirements
- Ability to obtain and maintain a Public Trust clearance.
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or a related field (or equivalent experience).
- Ability to work onsite as needed in one of the work locations in Northern Virginia: Springfield, Herndon, or Ashburn.
- 10+ years supporting enterprise identity, directory, or access management services.
- Experience with enterprise ICAM/IAM architecture supporting directory services, federation, and SSO.
- Experience supporting Identity federation for external partners and interagency integrations.
- Familiarity with privileged account management, RBAC, MFA, and service account governance.
- Experience leading ICAM lifecycle planning and technology refresh execution.
- Proficiency with security frameworks, including FISMA, NIST 800-53, and Zero Trust principles.
Skills
- Experience supporting large federal enterprises with complex IT/OT footprints.
- Hands-on experience with cloud-based identity platforms (Azure AD / Entra ID, hybrid identity).
- Strong stakeholder communication skills across engineering, cybersecurity, and operations teams.
- Experience contributing to architecture governance boards or enterprise design reviews.
- One or more of the following certifications (or equivalent): CISSP, CISM, or CCSP.
- Microsoft Identity & Access or Azure Identity certifications.
- Relevant IAM/ICAM industry certification.
Pay
Annual salary range: $100,000 – $140,000. Maximus compensation is based on various factors including job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Other rewards may include short- and long-term incentives as well as program-specific awards.
Benefits
- Health insurance coverage.
- Life and disability insurance.
- Retirement savings plan.
- Paid holidays and paid time off.