Haystack
← Back to Jobs
Employee
Administrative

ICAM Engineer - Identity, Credential, and Access Management with Security Clearance

RMantrasArlington, VA🇺🇸United StatesPosted 4 Aug 2026

Quick Overview

Work Type
On Site
Schedule
Employee
Level
Mid Senior

Job Description

This position is 100% Onsite. This position is in Arlington, VA, with occasional/situational travel. Certificate N/A Location: 4800 Mark Center Drive, Alexandria, VA 22311 Schedule 100% onsite Clearance US Citizens with DOD Top Secret Responsibilities Qualifications * Engineering & Deployment: Engineer, deploy, secure, and maintain complex, mission-critical identity systems—specifically ForgeRock IdP/ICAM platforms—across Linux-based environments to meet DoD, DISA, and federal standards.
* Integration & Federation: Integrate enterprise applications and directories (LDAP, Active Directory) with ICAM platforms using robust federation protocols (SAML, OAuth2, APIs) across cross-domain workflows and secure enclaves.
* Lifecycle & Access Control: Manage the complete identity and credential lifecycle (issuing, renewing, revoking, and automating workflows) to enforce strict Zero Trust access controls.
* Security & Compliance: Conduct system hardening, log analysis, and vulnerability management to support compliance with the Risk Management Framework (RMF) and participate in architectural and risk reviews.
* Operations & Troubleshooting: Diagnose and resolve escalated ICAM and ForgeRock issues within defined SLAs, conducting root cause analysis, performance tuning, and active monitoring.
* Documentation & Metrics: Create and version-control key engineering artifacts (CONOPS, SOPs, API documentation, and workflow diagrams) while maintaining ICAM performance metrics and dashboards. Basic Qualifications * BS in Computer Science, IT, or related discipline and 8+ years of systems engineering experience (or equivalent experience in lieu of degree).
* Active TS clearance with SCI eligibility
* Ability to obtain and maintain a CI Poly and Special Program Access.
* IAT Level II certification or higher (e.g., Security+ CE, CySA+, SSCP, CISSP).
* Hands on experience with federation technologies (SAML, OAuth2) and ZeroTrust identity principles.
* Experience engineering or administering the ForgeRock platform (AM, IDM, DS).
* Strong understanding of ICAM concepts, identity lifecycle management, and enterprise access controls.
* Experience with Windows and Linux systems administration, shell scripting, and troubleshooting. Preferred Qualifications * Experience supporting DISA or DoD mission partners.
* Active TS/SCI with CI Poly preferred.
* Experience with any of the following:
– JISG Access Controls
– AWS cloud engineering, IAM, and security services
– Ansible playbooks and automated configuration management
– CI/CD pipelines (GitLab, Jenkins, etc.)

Similar jobs