Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer
KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise. We foster both personal and professional development, creating new pathways for growth in a collaborative, team-driven culture. Our people are our number one priority, with access to world-class training, leading market tools, and a strong team connection where you can be your whole self, have an impact, and expand your capabilities.
About the role
KPMG is seeking a Lead Specialist to join our Federal Advisory practice, focusing on Identity, Credentialing, and Access Management (ICAM) solutions.
Responsibilities
- Lead the architecture, deployment, and management of ICAM solutions using platforms such as Okta, SailPoint, and CyberArk
- Develop and enforce access control policies, standards, and procedures in alignment with Zero Trust principles and federal mandates (e.g., NIST, FICAM, HSPD-12)
- Engineer and manage the full lifecycle of digital identities, including provisioning, de-provisioning, and periodic access reviews
- Integrate ICAM solutions with a wide variety of applications and infrastructure, including cloud (IaaS, PaaS, SaaS) and on-premises environments
- Serve as technical lead for Privileged Access Management (PAM) initiatives, securing and monitoring access for high-risk accounts using tools like CyberArk
- Translate federal client unique mission requirements into technical ICAM strategies and roadmaps
- Troubleshoot and resolve complex issues related to identity federation, single sign-on (SSO), multi-factor authentication (MFA), and directory services
- Mentor and review work of junior engineers and act as a key technical advisor to senior leadership
Requirements
- A minimum of five years of experience in cybersecurity with a focus on Identity and Access Management; U.S. Federal government consulting experience preferred
- Bachelor's degree from an accredited college/university
- Demonstrated experience with federal ICAM programs and frameworks, such as Federal Identity, Credential, and Access Management (FICAM), HSPD-12, PIV/CAC, and NIST SP 800-53 (Digital Identity Guidelines)
- Hands-on implementation experience with one or more of the following platforms: Identity Governance and Administration (IGA), SailPoint (IdentityIQ or IdentityNOW), Access Management, SSO (Okta), PAM (CyberArk)
- Experience with identity services in major cloud providers (AWS, Azure, GCP)
- Excellent written and verbal communication skills with the ability to articulate complex technical concepts to both technical and non-technical stakeholders
- Ability to travel as required to support firm engagements
- Must possess a U.S. Government Secret clearance
Qualifications
- Preferred certifications: CISSP, GSEC, GCED
- Okta, SailPoint IdentityIQ Engineer, and/or CyberArk Delivery Engineer certifications strongly preferred
Benefits
KPMG offers a comprehensive, competitive benefits package, including:
- A variety of medical and dental plans, vision coverage, disability and life insurance
- 401(k) plans
- A robust suite of personal well-being benefits to support mental health
- Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service
- Two annual breaks where employees will not be required to use Personal Time Off: one at year-end and another around the July 4th holiday
Pay
Salary ranges are determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications, and market considerations. Ranges are displayed in compliance with local/state regulations for potential hires in the location(s) listed. For city-specific salary ranges outside of California, visit KPMG’s Pay Transparency page.