IAM (Identity & Access Management) Engineer
Peraton · Chantilly, VA, US
About this role
## IAM (Identity & Access Management) Engineer ### Responsibilities - Design, automate, operate, and sustain identity and access services across a complex, highly secure platform environment - Support identity federation, authentication, authorization, RBAC/ABAC, single sign-on (SSO), privileged access, and workload identity across shared platform services and tenant environments - Integrate enterprise identity and token services with applications, cloud platforms, Kubernetes, development environments, and operational services - Maintain the identity-to-entitlement layer that controls access across the environment **Identity Federation & Single Sign-On** - Integrate platform services with enterprise identity, token, and directory services - Design, operate, and integrate Keycloak (or equivalent) identity services - Implement and troubleshoot OAuth/OIDC, SAML, LDAP, and related identity-federation patterns - Maintain reliable SSO across approved platform services, applications, and environments - Troubleshoot federation and authentication flows across interconnected systems and identity providers **Authorization & Entitlements** - Design and maintain RBAC and ABAC patterns for users, tenant administrators, privileged users, and services - Integrate identity and authorization services with GitLab, Kubernetes, mission applications, ServiceNow, and federated AWS access - Design and support workload and service-identity patterns for pipelines, automation, APIs, and platform services - Support access reviews, access recertification, and separation-of-duties requirements - Ensure identity and entitlement models align with established security and access-control requirements **Automation & Identity Operations** - Automate user, group, role, and entitlement lifecycle activities where practical - Support privileged-access workflows and elevated-role approval processes - Troubleshoot authentication, authorization, token, and federation issues escalated from Tier 2 support - Maintain identity-service monitoring, documentation, recovery procedures, and operational support processes - Identify opportunities to improve identity lifecycle management and reduce manual access-management activities through automation **Platform & Security Integration** - Collaborate with cloud, Kubernetes, platform, application, infrastructure, and cybersecurity teams to integrate identity capabilities - Support identity requirements for shared services, tenant environments, applications, and automated workloads - Evaluate identity and access impacts of new services, platform changes, and evolving architecture - Support secure identity patterns across highly restricted and multi-domain environments ### Location - Fully onsite in **Chantilly, VA** ### Qualifications **Required** - **Active TS/SCI clearance with CI Polygraph** - ~**6–8 years** of experience in IAM, cybersecurity, directory services, security engineering, platform engineering, or related discipline - **6 years** with a BS/BA; **an additional 4 years** may be considered in lieu of a degree - Demonstrated experience with identity federation, SSO, OAuth/OIDC, SAML, RBAC, and enterprise identity systems - Experience integrating identity and access services with cloud, applications, or Kubernetes environments - Experience troubleshooting complex authentication, authorization, token, and federation issues - Working knowledge of privileged-access management and identity lifecycle controls - Strong scripting
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.