SME Systems Engineer (Governance Analytics)
Job ID: 113360
Location: Alexandria, Virginia [Hybrid]
Category: App/Dev
Employment Type: Contract
Date Added: 08/21/2026
Role Summary
This position is a senior-level Systems Engineer specialized in Access Governance (AG) with a focus on Governance, Reporting, and Data Analytics. The role involves supporting critical identity and access management modernization activities, primarily within enterprise architectures, to enhance security and compliance. The successful candidate will serve as a technical authority and lead design, implementation, and optimization of ICAM solutions across legacy and modern systems.
Responsibilities
- Lead the modernization of legacy access controls into secure, enterprise-grade ICAM solutions aligned with federal standards.
- Manage enterprise directories, federation services, authentication protocols, authorization mechanisms, and Single Sign-On (SSO) implementations.
- Architect identity lifecycle workflows, user provisioning processes, and privilege management controls to ensure security and compliance.
- Design, deploy, and enforce Zero Trust identity principles based on NIST SP 800-207 across network hubs and enterprise environments.
- Configure and oversee PKI systems, credentials, smart cards, and multi-factor authentication (MFA) tools.
- Develop and manage federated identity services to enable secure interoperability with government and mission partners.
- Perform root cause analysis, privilege audits, and system performance tuning to maintain optimal security posture.
- Create technical architectures, data flows, and compliance documentation supporting identity and access management initiatives.
- Build enterprise reporting solutions using Power BI and integrate data sources for analytics on service health, compliance, and access patterns.
- Develop advanced queries and analytics in Power BI and other tools to support audits, threat detection, and proactive security measures.
Qualifications
- High School diploma with 10+ years of relevant experience or equivalent technical experience.
- Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+, vendor-specific identity certifications).
- Strong technical understanding of federated identity protocols such as SAML, OAuth, and OIDC.
- Hands-on experience with Active Directory, LDAP, and managing Smart Card/CAC authentication systems.
- Proven expertise implementing federal Zero Trust security frameworks per NIST SP 800-207.
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required.
- Familiarity with enterprise identity management tools such as SailPoint, Okta, Microsoft Entra ID, or Power BI is preferred.
- Experience designing and deploying PKI, digital credentials, and privilege management solutions.
- Knowledge of RESTful APIs, secure gateways, and data security best practices.
Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, with time split between the office and remote work.
