SME Systems Engineer (Azure AD)
Job ID: 113356
Location: Alexandria, Virginia [Hybrid]
Category: App/Dev
Employment Type: Contract
Date Added: 08/21/2026
Role Summary
A highly specialized SME Systems Engineer with expertise in Federation and Interoperability (FI), focusing primarily on Customer Identity and Access Management (CIAM) via Azure AD B2C. This senior-level position involves designing and implementing secure identity management solutions to modernize enterprise ICAM infrastructure. The role demands technical leadership in integrating, architecting, and maintaining enterprise identity frameworks, ensuring alignment with federal security standards and best practices.
Responsibilities
- Lead the modernization of legacy access control systems into comprehensive, secure ICAM solutions.
- Manage enterprise directories, federation services, authentication protocols, authorization, and Single Sign-On (SSO) configurations.
- Architect lifecycle management for identities, including user provisioning workflows and privilege management controls.
- Design and deploy Zero Trust identity principles in accordance with NIST SP 800-207 across network hubs.
- Configure and oversee enterprise PKI systems, credentials, and authentication mechanisms.
- Implement logical and physical access controls, including Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and other security measures.
- Develop federated identity services to enable secure interoperability with external partners and mission-critical systems.
- Perform root cause analysis, privilege audits, and system performance tuning to ensure optimal operation.
- Create custom architecture, data flows, compliance documentation, and technical interfaces for identity solutions.
- Provide advanced engineering oversight for Azure AD B2C / CIAM platform, including custom policy development, user flow engineering, and integration of external applications.
Qualifications
- High School diploma or equivalent with 10+ years of related experience or equivalent technical expertise.
- Certifications such as DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or relevant vendor-specific identity certifications).
- Deep technical understanding of federated identity protocols, including SAML, OAuth, OIDC, and Active Directory/LDAP architecture.
- Hands-on experience managing Smart Card / CAC authentication systems and PKI certificate validation.
- Proven experience applying federal Zero Trust identity standards (NIST SP 800-207) in enterprise environments.
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required. (Active Secret clearance is required).
- Strong problem-solving skills with the ability to conduct root cause analysis and system performance tuning.
Preferred Skills & Experience
- Experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity programs.
- Knowledge of integrating data governance frameworks with ICAM solutions for data-level access control enforcement.
- Familiarity with enterprise identity management tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
- Advanced understanding of RESTful APIs, secure gateways, and data schema security standards.
Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, combining in-office work in Alexandria, VA with remote work flexibility.
