SME Systems Engineer (Azure AD)
GovCIO · Alexandria, VA · 4 wk ago
On-siteInformation Technology$135k/yrFull-time
About the Role
GovCIO is hiring a highly experienced SME Systems Engineer specializing in Federation & Interoperability (FI) with a focus on Customer Identity and Access Management (CIAM) via Azure AD B2C. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). The position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This is a hybrid position located in Alexandria, VA.
Responsibilities
- Lead modernization of legacy access controls into robust, secure ICAM solutions.
- Manage enterprise directories, federation, authentication, authorization, and SSO protocols.
- Architect identity lifecycles, user provisioning workflows, and privilege management controls.
- Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs.
- Configure and manage enterprise-grade PKI systems, credentials, and authenticators.
- Implement logical and physical access control systems, including MFA, SSO, and PAM.
- Build federated identity services to enable secure interoperability with mission partners.
- Conduct technical root cause analysis, privilege audits, and system performance tuning.
- Develop custom technical interfaces, architectures, data flows, and compliance documentation.
- Provide advanced engineering and architecture ownership for Azure AD B2C / CIAM (Federation & Interoperability). Own the technical lifecycle of the Customer Identity and Access Management (CIAM) platform, engineer custom policies and user flows, and architect integration of new external-facing applications.
Requirements
- High School diploma with 10+ years of relevant experience (or commensurate experience).
- DoD 8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).
- Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture.
- Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation.
- Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks.
- Active Secret clearance.
Preferred Qualifications
- Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
- Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls.
- Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
- Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards.
Pay
USD $135,000.00 - USD $172,000.00 / year.