Identity Platform (IdP) Engineer
Capgemini Government Solutions (CGS) LLC seeks a highly skilled Identity Platform (IdP) Engineer to join our Zero Trust Architecture team. In this role, you will be the primary architect and administrator for identity services that form the "new perimeter" of our enterprise, bridging the gap between traditional networking and modern identity-centric security.
About the role
You will ensure that every access request is fully authenticated, authorized, and encrypted by designing and implementing identity-based access control policies that adhere to Zero Trust principles.
Responsibilities
- Design and implement identity-based access control policies that adhere to Zero Trust principles (Never Trust, Always Verify).
- Lead the deployment, configuration, and optimization of PingFederate and Ping Access to provide seamless SSO and attribute-based access control (ABAC).
- Manage the full lifecycle of Identity, Credential, and Access Management (ICAM), including automated provisioning and complex directory integrations.
- Collaborate with the SOC and Network teams to integrate identity signals into broader security monitoring and incident response workflows.
- Act as the subject matter expert for integrating PingFederate as the core Identity Provider (IdP) with third-party Zero Trust ecosystem components, including Privileged Access Manager (PAM), Master User Record (MUR), and Identity Governance and Administration (IGA).
- Create and maintain authentication policies, including Multi-Factor Authentication (MFA) and Risk-Based Authentication (RBA).
- Provide guidance and hands-on training for onboarding new applications into PingFederate using self-service templates, OIDC, and SAML to ensure consistent security standards across the enterprise.
Requirements
- Active Secret Government security clearance that requires U.S. citizenship.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related technical field.
- Minimum of 6 years of hands-on experience in ICAM (Identity, Credential, and Access Management) within enterprise or government environments.
- Deep proficiency with PingFederate (OIDC, SAML, OAuth protocols).
- Strong experience with Ping Access for protecting web applications and APIs at the gateway level.
- Active CompTIA Security+ (or equivalent IAT Level II certification) to meet compliance requirements.
- Knowledge of directory services (Active Directory, LDAP, Azure AD).
- Familiarity with NIST 800-207 Zero Trust Architecture standards.
- A security-first mindset with the ability to troubleshoot complex authentication handshakes.
About Capgemini
Capgemini is a global business and technology transformation partner, helping organizations accelerate their dual transition to a digital and sustainable world while creating tangible impact for enterprises and society. With a strong 55-year heritage, Capgemini is trusted by clients to unlock the value of technology to address their business needs. It delivers end-to-end services and solutions leveraging strengths in AI, generative AI, cloud, and data, combined with deep industry expertise and a partner ecosystem. The Group reported 2024 global revenues of €22.1 billion and employs 340,000 team members in more than 50 countries.
Pay
The base salary range for this role is $130K–$145K. This role may also be eligible for variable compensation, bonuses, or commissions. Full-time regular employees are eligible for paid time off and benefits including medical, dental, and vision insurance, as well as a 401(k).