Senior Systems Engineer
Job ID: 113361
Location: Alexandria, Virginia [Hybrid]
Category: App/Dev
Employment Type: Contract
Date Added: 08/20/2026
Role Summary
A Senior Systems Engineer specializing in Cross-Cutting Support and ICAM Enterprise Architecture is sought to support critical identity, credential, and access management enhancement initiatives. This technical position involves designing, engineering, and implementing secure, identity-centric access control frameworks across diverse enterprise architectures. The role provides strategic technical leadership for enterprise identity management systems, ensuring alignment with federal security standards and best practices.
Responsibilities
- Serve as the primary technical authority for enterprise identity management and access control frameworks.
- Lead the modernization of legacy access controls into secure ICAM solutions.
- Manage enterprise directories, federation, authentication, authorization, and single sign-on (SSO) protocols.
- Architect identity lifecycles, user provisioning workflows, and privilege management controls.
- Design and deploy Zero Trust identity principles based on NIST SP 800-207 across network hubs.
- Configure and manage enterprise PKI systems, credentials, and authenticators.
- Implement logical and physical access control systems, including MFA, SSO, and privileged access management (PAM).
- Build federated identity services for secure interoperability with mission partners.
- Conduct root cause analysis, privilege audits, and system performance tuning to optimize security posture.
- Develop technical interfaces, architectures, data flows, and compliance documentation to support ICAM initiatives.
- Own the overarching hybrid identity strategy and ensure interoperability across enterprise identity systems.
Qualifications
- High school diploma with 10+ years of relevant experience or equivalent technical background.
- Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+).
- Extensive knowledge of federated identity protocols including SAML, OAuth, OIDC, and LDAP/Active Directory architecture.
- Hands-on experience managing Smart Card/CAC authentication and PKI certificate validation.
- Proven expertise implementing NIST SP 800-207 Zero Trust principles within enterprise networks.
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required.
- Strong understanding of enterprise identity tools and frameworks, including SailPoint, Okta, Microsoft Entra ID, or Ping Identity.
- Familiarity with integrating data governance with ICAM solutions to enforce data access controls.
- Experience with RESTful API authorization protocols, secure gateways, and data schema security standards.
Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, with time split between the office and remote work.
