ICAM Security Engineer
Gaithersburg, MD - USA
Job Summary
Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical future-ready automation platform built on a hybrid cloud data mesh architecture enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset embracing emerging AI capabilities and modern development practices to accelerate delivery improve software quality and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.
This is a hybrid position requiring 3 days onsite and 2 days working from home if you are located within a commutable distance (Less than 1 hours drive one-way during normal traffic) from Gaithersburg MD; Eagan MN; or Egg Harbor Township NJ. However if you do not reside within a commutable distance you may be considered for a 100% remote role.
In this role you will implement the identity credential and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services enforce per-session authorization across distributed mission services and build the access control and audit foundations that operational and support users depend on.
- Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect including token issuance validation and claims mapping.
- Implement and maintain identity federation and user stores (Keycloak or equivalent) including role-based test account provisioning.
- Implement per-session authentication and authorization for user-to-service and service-to-service requests enforcing default-deny access regardless of network location.
- Implement mutual TLS (mTLS) service mesh/workload identity and certificate lifecycle management including issuance rotation expiration monitoring and revocation.
- Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
- Implement authentication and session management for operational users including sign-in/sign-out and time-on-position logging.
- Implement authentication and authorization audit logging including event capture storage and retrieval.
- Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
- Support security authorization and continuous monitoring by producing ICAM control evidence resolving identity integration issues across distributed services and leveraging AI-assisted development and automation to improve quality and delivery.
- Bachelors degree in Cybersecurity Computer Science Information Technology or related field with 4 years of relevant experience.(additional experience education and training may be considered in lieu of degree)
- Hands-on experience with OAuth 2.0 and OpenID Connect including token validation introspection and claims mapping.
- Experience with enterprise identity providers and federation such as Keycloak Okta Ping Microsoft Entra ID or equivalent.
- Experience implementing RBAC and/or ABAC within distributed applications.
- Working knowledge of PKI certificate lifecycle management mutual TLS (mTLS) and/or service mesh identity.
- Understanding of Zero Trust principles including per-session authorization and default-deny service communication.
- Experience implementing audit logging for access and authorization events.
- Proficiency in Java Python Go or a comparable programming/scripting language.
- Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
- Experience with Kubernetes and containerized service deployments.
- U.S. citizenship required with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
- Must meet FAA facility and information system access requirements including continuous U.S. residency for at least 3 of the previous 5 years.
- Security CE CySA or equivalent DoD 8570 IAT Level II certification.
- Federal ICAM/FICAM experience including PIV/CAC or agency ICAM integrations.
- Experience with SAML 2.0 and SCIM provisioning.
- Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).
- Experience with service mesh implementation (Istio Linkerd).
- Experience with API gateway authorization policy (Kong Apigee or equivalent).
- Familiarity with FIPS 140-3 validated cryptographic modules hardware security modules or enterprise key management.
- Knowledge of privileged access management practices.
- Experience in aviation FAA or other safety-critical environments.
- Experience with SAFe or large-scale Agile delivery.
Why Leidos
Youll work on systems where performance precision and reliability matter every second. This is not experimental AI for prototypes. This is disciplined responsible AI applied to mission-critical software that supports national infrastructure.
If youre excited by solving complex problems in regulated real-world environments and using AI as a force multiplier rather than a shortcut wed like to talk.
ATMC
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.