SME Systems Engineer
Job ID: 113355
Location: Alexandria, Virginia [Hybrid]
Category: App/Dev
Employment Type: Contract
Date Added: 08/21/2026
Role Summary
A senior-level SME Systems Engineer specializing in Identity Management (IdM) and Automation is sought to support critical ICAM modernization initiatives. This position involves designing, engineering, and implementing secure, identity-centric access control solutions across enterprise environments. The role requires technical expertise in federated identity, Zero Trust principles, and cloud-native automation, with an emphasis on Power Platform applications.
Responsibilities
- Serve as the primary technical authority for enterprise identity management and access control frameworks.
- Lead the modernization of legacy access controls into secure ICAM solutions aligned with industry standards.
- Manage enterprise directories, federation, authentication, authorization, and single sign-on (SSO) protocols.
- Architect identity lifecycle processes, user provisioning workflows, and privilege management controls.
- Design and deploy Zero Trust security principles based on NIST SP 800-207 across network environments.
- Configure and oversee enterprise PKI systems, credentials, and authenticators, including smart cards and CACs.
- Implement logical and physical access control systems, such as MFA, SSO, and Privileged Access Management (PAM).
- Develop federated identity services enabling secure interoperability with external mission partners.
- Conduct root cause analysis, privilege audits, and system performance optimization.
- Oversee Power Platform solutions, migrating legacy automation to cloud-native technologies, managing architectures, and troubleshooting complex issues.
Qualifications
- High school diploma with 10+ years of relevant experience or equivalent technical expertise.
- Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+).
- Extensive knowledge of federated identity protocols including SAML, OAuth, OIDC, and directory services such as LDAP and Active Directory.
- Hands-on experience with smart card/CAC authentication and PKI certificate validation.
- Proven skills in designing and implementing federal Zero Trust identity frameworks following NIST SP 800-207.
- Ability to manage enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, and Ping Identity.
- Strong understanding of RESTful API security, secure gateways, and data schema protections.
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required. (Must possess an active Secret clearance).
- Availability to work in a hybrid environment.
Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, with time split between the office and remote work.
