Haystack
← Back to Jobs
Employee
Engineering
RM

ICAM Engineer - Identity, Credential, and Access Management with Security Clearance

RMantrasArlington, VA🇺🇸United StatesPosted Sep 16, 2026

Why This Role Stands Out

Leverage your expertise in Identity, Credential, and Access Management to engineer and deploy critical systems for a reputable organization, offering a path for significant professional growth. You will thrive in this role if you possess a strong technical foundation, a commitment to security, and enjoy solving complex challenges within a mission-focused environment. This on-site opportunity in Arlington, VA, is perfect for individuals seeking impactful work and career advancement.

Quick Overview

Seniority
Mid Senior
Employment type
Employee
Work mode
On Site
Location
Arlington, VA, United States
Posted
2 days ago

Job Description

This position is 100% Onsite. This position is in Arlington, VA, with occasional/situational travel.

Certificate N/A Location: 4800 Mark Center Drive, Alexandria, VA 22311 Schedule 100% onsite Clearance US Citizens with DOD Top Secret Responsibilities Qualifications

  • Engineering & Deployment: Engineer, deploy, secure, and maintain complex, mission-critical identity systems—specifically ForgeRock IdP/ICAM platforms—across Linux-based environments to meet DoD, DISA, and federal standards.
  • Integration & Federation: Integrate enterprise applications and directories (LDAP, Active Directory) with ICAM platforms using robust federation protocols (SAML, OAuth2, APIs) across cross-domain workflows and secure enclaves.
  • Lifecycle & Access Control: Manage the complete identity and credential lifecycle (issuing, renewing, revoking, and automating workflows) to enforce strict Zero Trust access controls.
  • Security & Compliance: Conduct system hardening, log analysis, and vulnerability management to support compliance with the Risk Management Framework (RMF) and participate in architectural and risk reviews.
  • Operations & Troubleshooting: Diagnose and resolve escalated ICAM and ForgeRock issues within defined SLAs, conducting root cause analysis, performance tuning, and active monitoring.
  • Documentation & Metrics: Create and version-control key engineering artifacts (CONOPS, SOPs, API documentation, and workflow diagrams) while maintaining ICAM performance metrics and dashboards.

Basic Qualifications

  • BS in Computer Science, IT, or related discipline and 8+ years of systems engineering experience (or equivalent experience in lieu of degree).
  • Active TS clearance with SCI eligibility
  • Ability to obtain and maintain a CI Poly and Special Program Access.
  • IAT Level II certification or higher (e.g., Security+ CE, CySA+, SSCP, CISSP).
  • Hands on experience with federation technologies (SAML, OAuth2) and ZeroTrust identity principles.
  • Experience engineering or administering the ForgeRock platform (AM, IDM, DS).
  • Strong understanding of ICAM concepts, identity lifecycle management, and enterprise access controls.
  • Experience with Windows and Linux systems administration, shell scripting, and troubleshooting.

Preferred Qualifications

  • Experience supporting DISA or DoD mission partners.
  • Active TS/SCI with CI Poly preferred.
  • Experience with any of the following:
– JISG Access Controls
– AWS cloud engineering, IAM, and security services
– Ansible playbooks and automated configuration management
– CI/CD pipelines (GitLab, Jenkins, etc.)

Similar jobs