General Dynamics Information Technology Logo

General Dynamics Information Technology

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

Posted 3 Hours Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
255K-345K Annually
Expert/Leader
In-Office or Remote
Hiring Remotely in United States
255K-345K Annually
Expert/Leader
Lead enterprise-scale IdP architecture and engineering for DoD-scale authentication and federation. Define standards, implement ADFS/modern IdP platforms, design federation/trust models, oversee MFA/PKI/passwordless solutions, mentor teams, and drive Zero Trust identity modernization for millions of users.
The summary above was generated by AI

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Microsoft Azure, Microsoft Cloud, Secure Authentication, Single Sign-On (SSO)

Certifications:

None

Experience:

15 + years of related experience

US Citizenship Required:

Yes

Job Description:

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

GDIT is seeking a highly experienced Principal ICAM Architect and Identity Provider Engineer to lead enterprise-scale authentication and federation strategy across the Department of Defense. This role serves as a senior technical authority responsible for defining architecture, guiding engineering teams, and delivering resilient Identity Provider (IdP) services that support secure authentication for more than 4 million DoD enterprise identities.

This position is fully remote.

MEANINGFUL WORK AND PERSONAL IMPACT

The ideal candidate brings 15+ years of deep experience in identity architecture, enterprise authentication platforms, federation engineering, and strategic ICAM modernization. As a Principal Engineer, you will define enterprise standards, drive Zero Trust–aligned identity strategies, and provide authoritative guidance across mission-critical authentication ecosystems. You will serve as a senior technical leader partnering with cybersecurity, infrastructure, and application teams to evolve enterprise identity capabilities.
  • • Serve as the enterprise technical lead and architect for Identity Provider services across DoD, driving long-term ICAM strategy, modernization, and architectural governance.
    • Architect, build, and evolve large-scale ADFS and modern IdP platforms to deliver secure, resilient authentication and federation for millions of identities.
    • Define enterprise trust architectures, federation models, and cross-boundary identity integration patterns with internal DoD components, mission partners, and external organizations.
    • Lead design and architecture of authentication solutions leveraging SAML, OAuth, OpenID Connect (OIDC), WS-Federation, JWT, and certificate-based technologies.
    • Set technical direction for onboarding applications, APIs, and enterprise services into the authentication ecosystem, ensuring alignment with Zero Trust and DoD ICAM standards.
    • Develop enterprise-wide policies, claims rule frameworks, token issuance patterns, identity assurance levels, and authorization logic.
    • Provide principal-level oversight for MFA, phishing-resistant authentication, Conditional Access, and passwordless identity technologies.
    • Act as the senior escalation point for the most complex trust, certificate, federation, and token issues impacting mission-critical workloads.
    • Architect highly available, fault-tolerant authentication platforms incorporating advanced load balancing, multi-region resiliency, failover, and operational continuity strategies.
    • Produce authoritative technical documentation including architecture roadmaps, engineering standards, reference architectures, integration guides, and operational frameworks.
    • Lead and mentor engineering teams, provide guidance during Agile development cycles, and champion continuous improvement across authentication services.
    • Identify enterprise risks, drive mitigation strategies, and advise senior leadership on authentication posture, ICAM modernization plans, and Zero Trust progress.

Basic Qualifications:

  • Active Secret Clearance at minimum. Interim Secret Clearances are not allowed. 
  • Bachelor’s Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher)

Required Skills/Knowledge:

  • 15+ years of experience in enterprise identity architecture, ICAM engineering, authentication platforms, or federation technologies.
  • Deep expertise designing and leading enterprise-scale ADFS and IdP solutions.
  • Proven leadership architecting identity systems for large regulated environments supporting millions of users.
  • Advanced understanding of authentication, authorization, identity assurance, federation protocols, and Zero Trust identity pillars.
  • Strong experience with SAML, OAuth, OIDC, WS-Federation, JWT, PKI, smart card authentication, and MFA architectures.
  • Architecture-level experience integrating mission applications and APIs with enterprise IdP and federation platforms.
  • Expert-level proficiency with Active Directory, LDAP directories, identity repositories, and claims-based identity systems.
  • Hands-on experience designing enterprise token rules, claims mappings, federation workflows, and trust policies.
  • Expertise with Windows and Linux server platforms in identity contexts.
  • Experience deploying identity COTS products in secure environments.
  • Excellent communication skills, with ability to provide guidance to engineers and influence leadership.
  • Proven success driving large-scale identity initiatives from architecture to implementation.

Desired Skills/Knowledge:

  • Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP), load balancing, and disaster recovery architectures.
  • Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar enterprise authentication platforms.
  • Experience supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives
  • Experience implementing federation solutions for coalition, partner, or cross-organizational environments
  • Experience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL)
  • Experience implementing phishing-resistant authentication technologies and passwordless authentication solutions.
  • Experience supporting Zero Trust Architecture and identity-centric security initiatives.
  • Familiarity with PowerShell scripting and automation for ADFS administration.
  • Experience supporting enterprise monitoring, performance tuning, and capacity planning for authentication services supporting millions of identities.
  • Experience with Active Directory Certificate Services (AD CS) and enterprise PKI.
  • Familiarity with container technologies such as Docker and Kubernetes.
  • Familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
  • Experience supporting highly available, mission-critical enterprise authentication environments.

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Flexibility: Full-flex work week to own your priorities at work and at home
● Community: Award-winning culture of innovation and a military-friendly workplace
 

The likely salary range for this position is $255,000 - $345,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Remote

Work Location:

USA VA Falls Church

Additional Work Locations:

Any Location / Remote

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 



Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Similar Jobs

3 Hours Ago
In-Office or Remote
United States
140K-190K Annually
Mid level
140K-190K Annually
Mid level
Aerospace • Information Technology • Professional Services • Security • Software
Support design, integration, operation, and sustainment of enterprise Identity Provider services for DoD-scale authentication. Administer ADFS, configure federation trusts, implement SAML/OAuth/OIDC/WS-Fed and certificate-based solutions, support SSO/MFA/conditional access, troubleshoot tokens/certificates, onboard applications, document designs, and contribute to Zero Trust and identity modernization efforts.
Top Skills: Active DirectoryCac/Smart CardCertificate-Based AuthenticationDockerDod IcamKeycloakKubernetesLdapLinuxLoad BalancersMfaMicrosoft Active Directory Federation Services (Adfs)Microsoft Entra IdNist 800-63Oauth 2.0OktaOpenid Connect (Oidc)PingaccessPingfederatePkiPowershellSAMLWeb Application Proxy (Wap)WindowsWs-FederationZero Trust
170K-230K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
Design, deploy, and maintain enterprise Identity Provider (IdP) and ADFS services for DoD-scale authentication. Implement and troubleshoot SAML/OAuth/OIDC federation, MFA, PKI/CAC authentication, claims/policy mappings, SSO, and high-availability architectures. Integrate applications, manage federation trusts, produce documentation, and collaborate with cybersecurity, AD, cloud, and application teams to support Zero Trust and identity modernization.
Top Skills: Active DirectoryActive Directory Certificate Services (Ad Cs)Active Directory Domain Services (Ad Ds)Active Directory Federation Services (Adfs)CacCertificate-Based AuthenticationDockerJwtKeycloakKubernetesLdapLinuxAzureMicrosoft Entra Id (Azure Ad)Multi-Factor Authentication (Mfa)Oauth 2.0OktaOpenid Connect (Oidc)PingaccessPingdirectoryPingfederatePkiPowershellSaml 2.0Web Application Proxy (Wap)Windows ServerWs-Federation
170K-230K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
Senior hands-on identity engineer responsible for designing, deploying, and maintaining enterprise Identity Provider (IdP) services and ADFS infrastructure for millions of users. Duties include configuring federation trusts, implementing SAML/OAuth/OIDC/WS-Fed, PKI/smart card/MFA integrations, onboarding applications, developing claims and token policies, ensuring high availability and zero trust alignment, troubleshooting complex authentication issues, and producing technical documentation while collaborating with cybersecurity, AD, cloud, and application teams.
Top Skills: Active DirectoryActive Directory Certificate Services (Ad Cs)Active Directory Domain Services (Ad Ds)Active Directory Federation Services (Adfs)CacCertificate-Based AuthenticationCots ProductsDockerJwtKeycloakKubernetesLdapLinuxMfaAzureMicrosoft Entra Id (Azure Ad)Oauth 2.0OktaOpenid Connect (Oidc)PingaccessPingdirectoryPingfederatePkiPowershellSaml 2.0Smart Card AuthenticationWindows ServerWs-Federation

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account