Identity, Credential, and Access Management (ICAM) Analyst
Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation — empowering our teams to deliver meaningful outcomes in complex, high-security environments.
About the role
Spry is seeking an Identity, Credential, and Access Management (ICAM) subject matter expert (SME) with deep understanding and experience in federal identity policies, guidance, and technical implementations. You will work with clients to formulate, design, and evaluate architectures and technical solutions using ICAM enabling technologies (e.g., Microsoft Active Directory, MS Azure, Radiant Logic, SailPoint, Ping). Key activities include contributing to current and future-state DoD identity capabilities, ensuring ICAM compliance with federal guidance (e.g., NIST), and supporting government ICAM authorities (e.g., OSD/DISA). You will also assist in Agile development efforts as part of a diverse team supporting an enterprise-wide federal ICAM program.
Responsibilities
- Provide recommendations on ICAM standards, policies, and technical implementations for program members.
- Translate complex technical issues into high-level messages for non-technical stakeholders.
- Support future ICAM enhancements, such as adoption of Fast Identity Online 2 (FIDO) password-less standards.
- Provide ICAM governance support for MFA, Encryption, and Automated Dynamic Access Control (ADAC) work streams.
- Recommend lifecycle management for emerging technologies.
- Work with internal and external ICAM program stakeholders (federal and commercial) to execute a strategic ICAM roadmap.
- Facilitate and support meetings with program team members and client stakeholders to drive ICAM future-state capabilities.
- Work cross-functionally across program teams.
- Author and review Knowledge-Based (KB) articles to disseminate knowledge within the ICAM program.
- Perform continual improvement and risk management activities, including providing mitigation strategies.
- Participate in long-term planning and vendor engagement working sessions.
- Demonstrate a strong problem-solving mindset with the ability to perform stakeholder analysis for complex programs.
- Work closely with ICAM vendors to ensure their products align with ICAM Zero Trust Architecture (ZTA) roadmaps and presidential directives.
Requirements
- Active Secret Clearance.
- 15+ years of combined experience in Information Security and Identity & Access Management, including developing, implementing, and overseeing IT requirements.
- 5+ years of experience working with major cloud services (Azure, AWS) and proficiency with cloud technologies.
- Knowledge of and experience with architecting solutions adhering to Federal Identity, Credential, and Access Management (FICAM) policies, directives, and standards.
- Knowledge of IAM and ICAM policies and standards (e.g., HSPD-12, FIPS 201, NIST 800-63, NIST SP 800-53 Rev 5).
- Understanding of ICAM as a foundational element of Zero Trust architecture.
- Knowledge of implementing IAM tools in an enterprise environment.
- Experience with Active Directory (AD), Azure AD, AD Federated Services (ADFS), common ICAM standards (e.g., OAuth 2.0, OIDC, SAML, SCIM, FIDO2, XACML, ABAC, RBAC), multi-factor authentication solutions (AAL2 and AAL3), single sign-on, and entitlement management.
- Familiarity with Azure DevSecOps tools and processes.
- Hands-on experience managing or supporting complex technical ICAM implementations and Federal Public Key Infrastructure (FPKI).
- Experience working on large-scale ICAM implementations with a strong understanding of the DoD ICAM Strategy, Federal ICAM (FICAM) Architecture, and service-level strategies.
- Strong understanding of Azure AD concepts, including enterprise applications, application registrations, managed identities, service principals, conditional access framework, authentication strengths, SCIM, and Azure AD User Provisioning.
Preferred Qualifications
- Ability to see the big picture while aligning detailed tasks with organizational goals.
- Strong oral and written communication skills, with the ability to tailor messaging for technical and non-technical audiences.
- Proficient in multi-tasking and prioritizing tasks independently based on organizational priorities.
- Experience managing various stakeholders (technical and non-technical) and collaborating to achieve common goals.
- Experience working with Agile methods and Scrum processes.
- Demonstrated ability to understand complex technical issues and communicate them to non-technical stakeholders.
- Excellent diagnostic, critical thinking, and analytical skills.
- Ability to understand CC/S/A challenges and recommend appropriate strategies and technical solutions.
Benefits
- Medical Coverage: Cigna — 4 options:
- Traditional PPO Open Access Plus Network
- 2 HDHP PPO Open Access Plus Network options
- HDHP EPO Open Access Plus Network
- Dental Coverage: Cigna — PPO Base & Buy-Up Plans.
- Vision Coverage: Principal — VSP Choice Network.
- Paid Holidays: 11 paid federal holidays for full-time employees.
- Paid Time Off (PTO): Starts at 15 days per year.
- Training Benefit: Annual training allowance for job-related education.
- 401(k): Multiple fund choices through Fidelity with company match.