A business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and in
AWS Cloud Security and ICAM Specialist
Location
Worldwide
Posted
10 days ago
Salary
$153K - $207K / year
Seniority
Senior
Job Description
AWS Cloud Security and ICAM Specialist
General Dynamics
Title: AWS Cloud Security and ICAM Specialist Job Description: Responsibilities for this Position Location: Any Location / Remote Full Part/Time: Full time Job Req: RQ220978 Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: BI Full 6C (T4) Job Family: IT Infrastructure and Operations Job Qualifications: Skills: Access Management, Identity Governance, Secure Authentication Certifications: None Experience: 10 + years of related experience US Citizenship Required: No Job Description: The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem. Key Responsibilities: - Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM - Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC) - Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs - Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak) - Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application - Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls - Develop and document identity lifecycle management processes-provisioning, deprovisioning, and access reviews - Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system - Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak - Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance - Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization - Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs - Design and implement storage level, microservice level Authentication and Authorization - Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams - Participate in design sessions and work closely with the security lead - Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates - Direct and lead Pen testing, Review architecture diagrams produced by different teams - Independently lead design and implement of vulnerability management - Heavily participate in ATO activity - Lead and direct engineering team Deliverable Alignment & Performance Outcomes: - Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems - Access Control Documentation: Policies, RBAC models, and credential management workflows - Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards - Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components - Performance Outcomes: - 100% of CMM applications integrated with SSO and MFA. - Zero unauthorized access incidents attributable to configuration error - 100% compliance with NIST and FedRAMP ICAM control requirements - Reduced account provisioning time by 30% through automation Tools & Technologies: - IAM & Federation: Key Cloak, Okta - Access & Compliance: SailPoint, CyberArk, HashiCorp Vault - Cloud: AWS IAM, KMS, CloudTrail, Lambda - Protocols: SAML, OAuth2.0, OIDC, SCIM - Monitoring & Audit: Splunk - Collaboration: Jira, Confluence, SharePoint, MS Teams Required Skills & Experience: - Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred - Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environmentsrequired; 12+ years of experience in information systems preferred - Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus) - Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows - Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement - Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks - Experience implementing ICAM solutions in Agile and DevSecOps environments - Working knowledge of PKI, digital certificates, and encryption technologies - Strong analytical and troubleshooting skills with ability to resolve identity integration issues - Experience with AWS Container Security and Network Security (preferred, not required) - Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system - Experience supporting federal digital modernization or judiciary IT programs. - Familiarity with Zero Trust Architecture and micro segmentation principles - Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway). - Experience integrating identity governance tools (SailPoint, Saviynt). - Excellent presentation and communication skills - Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship - Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies - Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement - Demonstrated ability to work effectively, independently, and as part of a team Certification(s): - Certified Information Systems Security Professional (CISSP) - preferred - AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred - Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial - SAFe Practitioner (SPC/SSM) - a plus Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts. Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen). Location: Remote GDIT IS YOUR PLACE At GDIT, the mission is our purpose, and our people are at the center of everything we do. - Growth: AI-powered career tool that identifies career steps and learning opportunities - Support: An internal mobility team focused on helping you achieve your career goals - Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off - Community: Award-winning culture of innovation and a military-friendly workplace OWN YOUR OPPORTUNITY Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward. The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Remote Work Location: Any Location / Remote Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Responsible for the review of background check reports, security clearance packets, and other security functions for prospective employees. • Sending and reviewing background checks. • Updates records as appropriate to include background check statuses, clearance statuses, and uploading clearances into internal database. • Answering GWFS main/security phone line. • Supporting security staff in badging and other HQ requirements. • Daily updates need to be conducted for reporting purposes and to control/manage candidate pipeline. • Upload all necessary documentation onto various portal websites for review/submission. • Check clearance status in DISS for potential candidates given from recruiting. • Coordinates with the recruiting team to ensure the accuracy of documents collected. • Administer and troubleshoot other databases, update websites/SharePoint sites; run reports; perform database clean up tasks. • Other administrative tasks as needed
Cybersecurity Engineer
Kentro.usKentro, formerly IT Concepts, Inc., is a mission-driven digital modernization and transformation firm founded in the early 2000s and headquartered in McLean, Virginia. Kentro speci
Title: Cybersecurity Engineer (TS Cleared) Location: Remote, United States Department: Information Technology Job Description: Category Information Technology Position Type Contingent Location Type Remote Location/Org Data : Name United States Overview Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities. By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones. Kentro is always interested in connecting with experienced Cybersecurity Engineers who hold an active Top Secret clearance and are passionate about protecting enterprise systems, supporting mission-critical operations, and advancing cybersecurity initiatives within complex environments. Ideal candidates bring strong technical expertise, collaboration skills, and experience supporting cybersecurity operations, compliance efforts, and secure infrastructure in government, defense, or highly regulated environments. This posting is intended for candidates who would like to be considered for future opportunities as hiring needs evolve. Our team regularly reviews resumes for both immediate and upcoming openings. If your background aligns with a current or future position, we’ll be in touch. Location: TBD Responsibilities You may be a great fit if you have experience with: - Implementing and maintaining cybersecurity tools, technologies, and security controls across enterprise environments. - Supporting security operations, incident response, threat detection, and vulnerability remediation activities. - Conducting system hardening, patch management, and secure configuration activities in accordance with security standards. - Monitoring and analyzing security events, logs, and alerts to identify and mitigate potential threats. - Supporting RMF, NIST, STIG, ICD 503, or other compliance and accreditation requirements. - Performing vulnerability assessments, risk analysis, and security impact evaluations. - Collaborating with system administrators, network engineers, developers, and leadership to improve overall security posture. - Supporting cloud security initiatives within AWS, Azure, or hybrid environments. - Developing and maintaining cybersecurity documentation, procedures, diagrams, and reports. - Assisting with audits, assessments, POA&M management, and continuous monitoring activities. - Managing multiple competing priorities while supporting mission-critical operations and timelines. Qualifications - Active Top Secret (TS) security clearance or higher. - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience. - 5+ years of experience in cybersecurity, information assurance, or security engineering roles. - Experience supporting enterprise cybersecurity operations in government, defense, or regulated environments. - Strong understanding of cybersecurity principles, network security, system hardening, and risk management frameworks. - Experience with security tools such as SIEM platforms, vulnerability scanners, endpoint protection, or monitoring solutions. - Highly polished communication, presentation, and stakeholder engagement skills. - Ability to work independently and collaboratively in fast-paced environments. Nice to Haves - Security certifications such as Security+, CISSP, CASP+, CEH, or GIAC certifications. - Experience supporting RMF accreditation and authorization processes. - Familiarity with Splunk, Tenable, CrowdStrike, Microsoft Defender, ACAS, or similar tools. - Experience supporting Windows, Linux, and/or cloud-based environments. - Knowledge of scripting or automation using PowerShell, Python, or Bash. - Experience supporting DevSecOps or cloud modernization initiatives. Benefits The Company We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let’s solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence. We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015), two CMMI ML 3 ratings (DEV and SVC) and CMMC Level 2 Certification. Industry Recognition Growth | Inc 5000’s Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C. Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner – Mid-Size Companies, Companies Owned by People of Color; Department of Labor’s HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award Benefits We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. We invest in our employees – Every employee is eligible for education reimbursement for certifications, degrees, or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development. We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities – virtual and in-person – e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy. Commitment Equal Opportunity Employment & VEVRAA Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law. Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements. As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness. We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility. Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.. #LI-PR1
Senior Director Analyst – Network Security
GartnerWe deliver actionable, objective insight that drives smarter decisions and stronger performance.
• Create innovative and thought-provoking insights • Develop new insights and offer actionable approaches to clients • Research, analyze, and predict market trends and shifts • Provide clients with actionable advice via virtual or face-to-face interactions • Deliver high-value presentation materials at various events • Actively participate in innovation discussions and collaborate with peers
Senior Information Security Engineer
JobandtalentThe world-leading digital job platform connecting great people with endless opportunities
• Improve and take ownership of incident management • Improve detection capabilities and reduce noise for the SIEM. Create and improve playbooks. Improve email security. • Developing security guides along with defining, implementing, and monitoring security measures to protect Job&talent. • Improving security tooling, processes, and standards to provide security assurances across the business. • Mentoring and guiding more junior engineers • Use our CSPM tool to monitor cloud security configurations across AWS, Azure, and Google Cloud Platform. • Working closely with DevOps teams to integrate security into the cloud deployment environment and pipeline. • Performing risk assessments, threat modeling, and security reviews. • Improve logging, visibility, and evidence collection across corporate and production systems.



