CronJobs

security jobs

IAM (Identity & Access Management) Engineer

Peraton · Chantilly, VA, US

onsitemid$112,000–$179,000Posted Oct 11, 2026KeycloakOAuthOIDCSAMLRBACABACKubernetesAWS IAM

Apply on the employer site

About this role

## IAM (Identity & Access Management) Engineer ### Responsibilities - Design, automate, operate, and sustain identity and access services across a complex, highly secure platform environment - Support identity federation, authentication, authorization, RBAC/ABAC, single sign-on (SSO), privileged access, and workload identity across shared platform services and tenant environments - Integrate enterprise identity and token services with applications, cloud platforms, Kubernetes, development environments, and operational services - Maintain the identity-to-entitlement layer that controls access across the environment **Identity Federation & Single Sign-On** - Integrate platform services with enterprise identity, token, and directory services - Design, operate, and integrate Keycloak (or equivalent) identity services - Implement and troubleshoot OAuth/OIDC, SAML, LDAP, and related identity-federation patterns - Maintain reliable SSO across approved platform services, applications, and environments - Troubleshoot federation and authentication flows across interconnected systems and identity providers **Authorization & Entitlements** - Design and maintain RBAC and ABAC patterns for users, tenant administrators, privileged users, and services - Integrate identity and authorization services with GitLab, Kubernetes, mission applications, ServiceNow, and federated AWS access - Design and support workload and service-identity patterns for pipelines, automation, APIs, and platform services - Support access reviews, access recertification, and separation-of-duties requirements - Ensure identity and entitlement models align with established security and access-control requirements **Automation & Identity Operations** - Automate user, group, role, and entitlement lifecycle activities where practical - Support privileged-access workflows and elevated-role approval processes - Troubleshoot authentication, authorization, token, and federation issues escalated from Tier 2 support - Maintain identity-service monitoring, documentation, recovery procedures, and operational support processes - Identify opportunities to improve identity lifecycle management and reduce manual access-management activities through automation **Platform & Security Integration** - Collaborate with cloud, Kubernetes, platform, application, infrastructure, and cybersecurity teams to integrate identity capabilities - Support identity requirements for shared services, tenant environments, applications, and automated workloads - Evaluate identity and access impacts of new services, platform changes, and evolving architecture - Support secure identity patterns across highly restricted and multi-domain environments ### Location - Fully onsite in **Chantilly, VA** ### Qualifications **Required** - **Active TS/SCI clearance with CI Polygraph** - ~**6–8 years** of experience in IAM, cybersecurity, directory services, security engineering, platform engineering, or related discipline - **6 years** with a BS/BA; **an additional 4 years** may be considered in lieu of a degree - Demonstrated experience with identity federation, SSO, OAuth/OIDC, SAML, RBAC, and enterprise identity systems - Experience integrating identity and access services with cloud, applications, or Kubernetes environments - Experience troubleshooting complex authentication, authorization, token, and federation issues - Working knowledge of privileged-access management and identity lifecycle controls - Strong scripting

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord