Identity & Access Management (IAM) Engineer – Keycloak/OIDC Specialist

00100 LEIDOS, INC.
Bethesda, MD
$122.2K-$220.9K a year
Full-time

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success.

We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Our Mission, Vision, and Values guide the way we do business. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers.

Your most important work is ahead.

If this sounds like the kind of environment where you can thrive, keep reading!

Leidos is seeking an Identity and Access Management (IdAM) Engineer to support the National Media Exploitation Center (NMEC).

The System Administrator will be responsible for maintaining existing enterprise identity management solutions, troubleshoot incidents, and assist with transitioning new capabilities to production.

Duties will include validating the health and status, operations, and maintenance of identity management systems such as Keycloak and OpenID Connect (OIDC) technologies.

This individual will work in a team environment supporting a large enterprise spanning multiple enclaves and sites.

This is a 100% on-site position. All work must be performed at the customer site in Bethesda at the Intelligence Community Campus.

Primary Responsibilities

Design and implement IAM solutions using Keycloak for secure authentication and authorization based on OIDC, OAuth2, and SAML protocols.

Integrate Keycloak with internal and external applications, APIs, and third-party services to enable secure access and identity federation.

Manage and maintain the Keycloak infrastructure, including clustering, performance tuning, and monitoring.

Implement custom authentication flows, policies, and user federation strategies using Keycloak.

Collaborate with DevOps and infrastructure teams to ensure the scalability, security, and high availability of Keycloak deployments.

Automate the management of identity and access workflows, including user provisioning, de-provisioning, and role-based access control (RBAC).

Provide technical expertise for OIDC / OAuth2 standards, keeping up with industry trends and ensuring compliance with evolving security requirements.

Troubleshoot issues related to authentication, authorization, and access control, ensuring a seamless user experience.

Document system configurations, processes, and troubleshooting procedures for internal teams and stakeholders.

Conduct regular security audits and recommend improvements for IAM practices and systems.

Participate in and contribute to cross-functional teams working on broader IAM, DevSecOps, and security initiatives.

Provide support for implementing, troubleshooting and maintaining of identity management systems.

Rapidly distinguish isolated user problems from enterprise-wide application / system problems and provide recommended solutions.

Provide follow-up reports (technical findings, feedback, resolution steps taken) for root cause analysis, engineering technical assessment and process improvement initiatives.

Update operations and maintenance documentation for 24 / 7 / 365 enterprise watch personnel.

Work with Operations, Engineering, and vendor support to develop solutions to complex technical issues.

Work independently as part of a virtual team

Provide mentorship and training for junior team members.

Basic Qualifications

Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent work experience.

3-5 years of experience working in Identity and Access Management (IAM) with a focus on Keycloak and OIDC / OAuth2 technologies.

Strong hands-on experience with configuring, deploying, and managing Keycloak in a production environment.

Deep understanding of authentication and authorization protocols including OIDC, OAuth2, SAML, and LDAP.

Proficiency in Java, Python, or other scripting languages used for extending and automating Keycloak.

Experience with user federation (LDAP, Active Directory, etc.) and social identity providers (Google, Facebook, etc.) using Keycloak.

Familiarity with DevOps practices, including CI / CD pipelines, and experience with Docker, Kubernetes, and infrastructure-as-code (IaC) tools such as Terraform.

Strong problem-solving and debugging skills, particularly in complex, distributed environments.

Ability to work in an Agile / Scrum environment, collaborating with cross-functional teams.

Strong communication skills, with the ability to articulate technical solutions to both technical and non-technical stakeholders.

Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements (currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification)

Education / Experience Requirements

Candidate must have a Bachelor's, with at least 12 years of relevant experience. Additional years of experience may be considered in lieu of degree.

Generally has 4+ years of experience supervising or leading teams or projects.

Clearance

Active TS / SCI clearance with Polygraph required OR active TS / SCI and willingness to get a Poly.

US Citizenship is required due to the nature of the government contracts we support.

Preferred Qualifications

  • 5+ years of experience in IAM or related security engineering roles.
  • Experience with cloud platforms (AWS, Azure, GCP) and securing cloud-native applications.
  • Experience with identity governance tools (e.g., SailPoint, Okta).
  • Familiarity with API security (e.g., JWT, mTLS) and best practices for securing microservices architectures.
  • Experience implementing MFA, SSO, and zero-trust architectures.

Original Posting Date :

2024-09-25

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $122,200.00 - $220,900.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

30+ days ago
Related jobs
00100 LEIDOS, INC.
Bethesda, Maryland

Identity and Access Management (IAM) with a focus on Keycloak and OIDC/OAuth2 technologies. Leidos is seeking an Identity and Access Management (IdAM) Engineer to support the National Media Exploitation Center (NMEC). Duties will include validating the health and status, operations, and maintenance ...

Promoted
VirtualVocations
Darnestown, Maryland

A company is looking for a Manager, Identity Access Management. ...

CVS Health
Work from home, MD, US
Remote

The Staff Security Engineer of IAM will be a product owner and lead engineer within Identity Access Management (IAM) space for CVS Health. Identity Access Management (IAM). This position will include leading multiple projects simultaneously and hands-on engineering of IAM solutions. Operating within...

GEICO
Chevy Chase, Maryland

You will lead and drive design, implementation, and maintenance of a robust workforce and workload identity management solutions and governance framework. Our Senior Engineer works with our Staff and Sr. Engineers to innovate and build new systems, improve, and enhance existing systems as well as id...

Disability Solutions
Rockville, Maryland

Westat is seeking a Senior Identity Access Management (IAM) Engineer who will be responsible for the design, implementation, and support for the organization IAM solutions. Experience with Okta or other identity and access management (IAM) platforms, and Single Sign-On technologies. Maintain and Enh...

Westat
Rockville, Maryland
Remote

Senior Identity Access Management Engineer (Remote-ET/CT time zone). Senior Identity Access Management Engineer (Remote-ET/CT time zone) | Westat. Westat is an Equal Opportunity Employer and does not discriminate on the basis of race, creed, color, religion, sex, national origin, age, veteran status...

MultiPlan
Rockville, Maryland
Remote

Lead the design and implementation of a robust and scalable IAM architecture, including identity lifecycle management, access governance, and privileged access management. The Director of Information Security - Identity and Access Management (IAM) provides leadership to architect and mature our IAM ...

Children’s National
Silver Spring, Maryland

Information Security Analyst II (Security / Identity Access Management (IAM) Analyst)-(240002LM). Understanding and some application of controls and practices associated with access management, active directory, privileged account management, and authentication. Bachelor's Degree Bachelor's degree i...

GEICO
Chevy Chase, Maryland

Our Engineer II will work independently and collaborate with management in our Identity Infrastructure, service, and processes. Create and maintain comprehensive documentation related to our identity directory, governance, and access management designs, configurations, and processes. GEICO is seekin...

GEICO
Chevy Chase, Maryland

GEICO is seeking an experienced Senior Staff Engineer to solve complex Identity and Access Management-related challenges. You will help drive our insurance business transformation as we redefine our Identity, Access Management, and Governance strategies. You will lead and drive design, implementatio...