SME Systems Engineer (Cloud PKI)

Job ID: 113358
Location: Alexandria, Virginia  [Hybrid]
Category: App/Dev
Employment Type: Contract
Date Added: 08/21/2026

Apply Now

Fill out the form below to submit your information for this opportunity. Please upload your resume as a doc, pdf, rtf or txt file. Your information will be processed as soon as possible.


 
 
 
 
 
(Word, PDF, RTF, TXT)
Notice: Job application forms are locked until Analytics cookies are accepted for fraud prevention tracking. Please click the cookie settings banner to unlock.
* Required field.

Role Summary
This role requires an experienced Systems Engineer specializing in Credential Management, with a primary focus on cloud credentialing and Public Key Infrastructure (PKI). The position involves designing, engineering, and implementing secure identity and access management solutions to support modernization efforts for government agencies. The individual will serve as a technical authority within enterprise identity management frameworks, ensuring robust, scalable, and compliant systems.

Responsibilities

  • Lead the modernization of legacy access control systems into comprehensive ICAM solutions.
  • Manage enterprise directories, federation protocols, authentication, authorization, and Single Sign-On (SSO) configurations.
  • Architect identity lifecycle workflows, user provisioning, and privilege management processes.
  • Design and deploy Zero Trust identity principles, aligned with NIST SP 800-207 standards.
  • Configure and oversee PKI systems, including credential management and authentication devices.
  • Implement physical and logical access control systems, such as MFA, SSO, and Privileged Access Management (PAM).
  • Develop federated identity services to facilitate secure integration with mission partners.
  • Conduct root cause analysis, privilege audits, and system performance tuning.
  • Create technical architectures, data flows, compliance documents, and custom interfaces.
  • Lead the management and engineering of cloud credentialing platforms, including PKI hardware security modules (HSMs) and enterprise certificate templates.

Qualifications

  • High school diploma with 10+ years of relevant experience or equivalent technical background.
  • Certification: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or equivalent).
  • Extensive experience with federated identity protocols such as SAML, OAuth, and OIDC.
  • Hands-on experience managing CAC/PIV authentication and PKI certificate validation.
  • Proven track record implementing federal Zero Trust security principles within enterprise environments.
  • This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required. (Active Secret clearance is required).
  • Strong knowledge of enterprise identity management tools and systems.
  • Experience supporting U.S. Coast Guard or Department of Homeland Security identity programs is preferred.
  • Familiarity with data governance frameworks integrated with ICAM solutions.
  • Knowledge of REST APIs, secure gateways, and data security standards.

Publishing Pay Range: $60.00 – $65.00 hourly

This position offers a hybrid schedule, with time split between the office and remote work.