Company: General Dynamics IT Location: Falls Church, Hom Employment Type: Full Time Date Posted: 08/07/2026 Job Categories:
Engineering, Information Technology
Job Description
ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by designing, developing, integrating, and maintaining enterprise Identity Provider (IdP) services that provide secure authentication and federation for more than 4 million enterprise identities across the Department of Defense. This is a fully remote position. MEANINGFUL WORK AND PERSONAL IMPACTThe ideal candidate is a senior hands-on identity engineer with expertise in Microsoft Active Directory Federation Services (ADFS), enterprise authentication, federation technologies, and modern identity protocols. This role focuses on delivering highly available authentication services, federation trust management, single sign-on (SSO), multi-factor authentication (MFA), and secure application integration across a large-scale enterprise environment..Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities.Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure supporting enterprise authentication and federation.Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.Support onboarding and integration of enterprise applications into the authentication and federation ecosystem.Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication capabilities.Collaborate with cybersecurity, Active Directory, cloud, infrastructure, and application teams to implement secure authentication services.Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.Monitor, troubleshoot, and resolve complex authentication, federation, trust, certificate, token, and identity assertion issues.Engineer highly available and resilient authentication services supporting mission-critical enterprise applications.Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.Participate in Agile development activities and continuous service improvement initiatives.Actively manage technical risks and contribute to enterprise identity modernization efforts.Basic Qualifications:Active Secret Clearance at minimum. Interim Secret Clearances are not allowed.Bachelors Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.DoD 8570/8140 IAT Level II certification (Security+ CE or higher)Required Skills/Knowledge:Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environmentsStrong experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS).Extensive experience implementing enterprise Identity Provider (IdP) services supporting large user populations.Strong understanding of authentication, authorization, federation, and identity assurance conceptsExperience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologiesExperience supporting PKI, certificate-based authentication, smart card authentication, and MFA solutionsExperience integrating applications, APIs, and enterprise services with federation platformsExperience with Active Directory, LDAP directories, and enterprise identity repositoriesExperience configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflowsExperience supporting Linux and/or Windows Server environmentsExperience deploying and supporting enterprise COTS products in secure customer environmentsExperience working in Agile development environments and utilizing associated toolsStrong written and verbal communication skillsSelf-starter capable of driving complex technical efforts to completion Desired Skills/Knowledge:Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP), load balancing, and disaster recovery architectures.Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar enterprise authentication platforms.Experience supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiativesExperience implementing federation solutions for coalition, partner, or cross-organizational environmentsExperience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL)Experience implementing phishing-resistant authentication technologies and passwordless authentication solutions.Experience supporting Zero Trust Architecture and identity-centric security initiatives.Familiarity with PowerShell scripting and automation for ADFS administration.Experience supporting enterprise monitoring, performance tuning, and capacity planning for authentication services supporting millions of identities.Experience with Active Directory Certificate Services (AD CS) and enterprise PKI.Familiarity with container technologies such as Docker and Kubernetes.Familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.Experience supporting highly available, mission-critical enterprise authentication environments.GDIT IS YOUR PLACEAt GDIT, the mission is our purpose, and our people are at the center of everything we do. Growth: AI-powered career tool that identifies career steps and learning opportunities Support: An internal mobility team focused on helping you achieve your career goals Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off Flexibility: Full-flex work week to own your priorities at work and at home Community: Award-winning culture of innovation and a military-friendly workplaceOWN YOUR OPPORTUNITYExplore an enterprise IT career at GDIT and youll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.