AWS Cloud Infrastructure Engineer (Keycloak Specialty)
$153k - $207kGdit
Req ID: RQ222522
Type of Requisition: Regular
Clearance Level Must Be Able to Obtain: None
Public Trust/Other Required: BI Full 6C (T4)
Job Family: Software Engineering
Skills:
Authentication,Cloud Computing,Identity Access Management (IAM)
Certifications:
AWS Certified Solutions Architect - Professional | Amazon Web Services (AWS) - Amazon Web Services (AWS), AWS Certified Solutions Architect - Associate | Amazon Web Services (AWS) - Amazon Web Services (AWS), Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2)
Experience:
10 + years of related experience
Job Description:
The AWS Cloud Infrastructure Engineer (Keycloak Specialty) supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The Engineer collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.
Key Responsibilities:
Design and maintain the identity architecture utilizing Keycloak
Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , KeyCloak)
Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
Design identity solutions and support compliance assessments , ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
Develop and document identity lifecycle management processes -provisioning, deprovisioning, and access reviews
Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and KeyCloak
Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
Provide subject matter expertise in identity federation, PKI, certificate management , and secure API authorization
Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
Design and implement storage level, microservice level Authentication and Authorization
Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
Participate in design sessions and work closely with the security lead
Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
Direct and lead Pen testing, Review architecture diagrams produced by different teams
Independently lead design and implement of vulnerability management
Lead and direct engineering team
Deliverable Alignment & Performance Outcomes:
Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
Access Control Documentation: Policies, RBAC models, and credential management workflows
Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
Performance Outcomes:
100% of CMM applications integrated with SSO and MFA.
Zero unauthorized access incidents attributable to configuration error
100% compliance with NIST and FedRAMP ICAM control requirements
Reduced account provisioning time by =30% through automation
Tools & Technologies:
IAM & Federation: KeyCloak , Okta
Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
Cloud: AWS IAM, KMS, CloudTrail, Lambda
Protocols: SAML, OAuth2.0, OIDC, SCIM
Monitoring & Audit: Splunk
Collaboration: Jira, Confluence, SharePoint, MS Teams
Required Skills & Experience:
Education: Bachelor's Degree in Cybersecurity, Information Systems, or equivalent experience required; Master's Degree preferred
Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based environmentsrequired ; 12+ years of experience in information systems preferred
Hands-on experience with KeyCloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus)
Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
Experience implementing ICAM solutions in Agile and DevSecOps environments
Working knowledge of PKI, digital certificates, and encryption technologies
Strong analytical and troubleshooting skills with ability to resolve identity integration issues
Experience with AWS Container Security and Network Security (preferred, not required)
Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
Experience supporting digital modernization or judiciary IT programs
Familiarity with Zero Trust Architecture and micro segmentation principles
Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).
Experience integrating identity governance tools (SailPoint, Saviynt)
Excellent presentation and communication skills
Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship
Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
Demonstrated ability to work effectively, independently, and as part of a team
Certification(s):
AWS Certified Solutions Architect - Associate or Professional - preferred
Certified Information Systems Security Professional (CISSP) - preferred
AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred
Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial
SAFe Practitioner (SPC/SSM) - a plus
Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts.
Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen).
Location: Remote
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.
The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
Join our Talent Community to stay up to date on our career opportunities and events at
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
- ...Cloud Infrastructure Engineer The hiring manager is seeking a Cloud Infrastructure Engineer with strong experience enabling Generative AI (GenAI) solutions in AWS. This role is focused on designing, enabling, and supporting GenAI infrastructure capabilities, with hands...Amazon Web ServiceWork experience placement
- ...Job Description: ~ Cloud Infrastructure Engineer ~5 plus years of Knowledge and Handson experience in designing and supporting AWS platform infrastructure solutions. ~ In depth understanding of AWS Networking Private Link, Security Group, Route53, VPC,...Amazon Web ServiceWork experience placement
$131.3k - $177.6k
...team at Amazon Web Services (AWS). In this role, you'll work closely... ...success through their cloud journey, providing technical... ...requirements, assess current infrastructure, and propose effective migration... ...guidance through our global specialty practices, which cover a variety...Amazon Web ServiceWork at officeFlexible hours1 day per week$229.9k - $262.4k
Senior Lead AI Engineer (GenAI Platform, Agentic Infrastructure) Overview: At Capital One, we are creating responsible... ...Source and SaaS AI technologies such as AWS Ultraclusters, Huggingface,... ...scalable and responsible AI solutions on cloud platforms (e.g. AWS, Google Cloud,...Amazon Web ServiceFull timePart timeLocal area- ...Cloud Network Engineer Everforth ECS is seeking a Cloud Network Engineer to... ...sustains the cloud networking infrastructure underpinning WDP operations... ...cloud enclaves spanning AWS GovCloud, the SC2S AWS Secret... ...Certified Advanced Networking – Specialty or AWS Certified Solutions...Amazon Web ServiceContract workLocal area
- ...greater success. We are seeking a Cloud Platform Engineer to support cloud modernization... ...reusable cloud platform capabilities using AWS, Infrastructure as Code, CI/CD pipelines, automation... ...AWS Associate, Specialty, or Professional-level certification...Amazon Web ServiceWork experience placementRemote work
- ...At Rune, we are building the infrastructure that powers logistics operations across cloud and edge environments - from centralized... ...conditions. As a Cloud DevOps Engineer, you will be responsible for... ...operate cloud infrastructure across AWS and multi-cloud environments,...Amazon Web ServiceFull timeFor contractorsWork at office
$69.4k - $158k
Azure Cloud Infrastructure Architect Everyone is trying to “harness the cloud”, but not everyone knows... ...with fellow cloud architects and engineers specializing in cloud IT to define and... ...troubleshooting networking issues within AWS cloud Top Secret clearance HS diploma...Amazon Web ServiceLocal area- ...Lead Cloud Engineer Why choose between doing meaningful work and having... ...Summary The Cloud and Infrastructure Engineering Center is seeking... ...to work in several specialty fields with information technology... ...commercial cloud platforms (e.g., AWS, Azure, or Google Cloud)...Amazon Web ServiceInternshipLocal area
$300 per month
...learners. About the Role: The Senior Engineer, Cloud is responsible for designing, implementing,... ...maintaining secure, reliable, and scalable cloud infrastructure. This role focuses on migrating on-premise applications to AWS and other cloud platforms, optimizing...Amazon Web ServiceFull timeFor contractorsWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours- ...Job Title: Cloud Engineer Professional Location: Mclean, VA - Onsite Contract: 11 Months Contract... ...Ideal candidate will have 3+ years of strong infrastructure-focused experience. Must have hands on AWS experience and strong knowledge of AWS native...Amazon Web ServiceContract workWork experience placement
$115.2k - $164.57k
...network architecture, reverse engineering, software and hardware... ...seeking an Intermediate-level Cloud Security Engineer to work... ..., containerized services, Infrastructure as Code modules, and... ...experience. Amazon Web Services AWS Security‑Specialty certified Must be Top...Amazon Web ServiceFull timeContract workWork at officeLocal areaRemote workWorldwide- ...Job Description SENIOR CLOUD INFRASTRUCTURE CONSULTANT Location: 10... ...Infinity is expanding our AWS Professional Services delivery... ...automation. This is a hands-on engineering role: you will write... ...Certified Advanced Networking - Specialty ~ AWS Certified Security...Amazon Web Service
$100k - $175k
...Overview As a Cloud Engineer, you will work within our growing DevSecOps practice delivering... ...services and DevOps practices such as infrastructure as code and confirmation management... ...designing and implementing cloud solutions in AWS ~3+ years of experience with Git SCM...Amazon Web Service- ...Cloud Engineer Role: Cloud Engineer Location: Must sit on site in McLean, VA (hybrid,... ...onsite) Must haves: Jenkins AWS Scripting UNIX (Shell), CI/CD... .... Role: Team is maintaining infrastructure. Providing support. Running scripting...Amazon Web ServiceLocal areaRemote work
- ...are seeking a Geospatial Platform Engineer to support geospatial, imagery,... ...hybrid environments, including cloud, on-premises, virtualized, and classified infrastructure. This person should be comfortable... ...with Rancher, RKE2, OpenShift, AWS, Azure, VMware vSphere,...Amazon Web ServiceFull timeRemote work
- A leading defense contractor is seeking a Senior Cloud Engineer in Fairfax, VA to develop and maintain cloud infrastructures for DoD operations. Candidates must have significant experience with AWS, relevant certifications, and a strong background in incident response...Amazon Web ServiceFor contractors
$115.2k - $164.57k
...defense technology company is seeking an Intermediate-level Cloud Security Engineer based in Fairfax, VA. The role involves... ...Candidates should have 5 years of relevant experience, AWS Security-Specialty certification, and must be US citizens and SC/TS eligible...Amazon Web Service- ...VA is seeking a Senior-level IaC Engineer. In this role, you'll develop infrastructure solutions using Infrastructure as... ...methodologies and design automated cloud architectures. Candidates should have... ...with a Bachelor's degree. Must be AWS certified and eligible for TS/SCI...Amazon Web ServiceFor contractors
$140k - $155k
...Management Services, LLC is seeking a Senior Platform Engineer to develop scalable infrastructure for mission-critical applications. This remote role requires... ...proficiency in infrastructure tools like Terraform and AWS. A salary range of $140k-$155k is offered for this role...Amazon Web ServiceRemote job- ECS in Fairfax, Virginia is seeking a Cloud Network Engineer to design and sustain cloud networking infrastructure for the War Data Platform operations. This role requires experience in network engineering and current security clearance. The ideal candidate will have strong...Amazon Web Service
- TryApplyNow is looking for an entry-level Azure Cloud Engineer to support cloud solutions at their... ...strong understanding of both Azure and AWS technologies. The successful candidate... ...along with experience in Python, Cloud infrastructure, and DevOps practices. Join a team that...Amazon Web ServiceFull time
- ...Senior Cloud Network Engineer Everforth ECS is seeking a Senior Cloud Network Engineer to work... ...environments across IL2/NIPRNet, IL5/AWS GovCloud, IL6/AWS Secret Region, and... ...administering advanced cloud network infrastructures supporting Department of War missions...Amazon Web ServiceContract work
- Everforth ECS is seeking a mid-level Cloud Systems Engineer to work remotely in Fairfax, Virginia.... ...position involves implementing cloud infrastructure, monitoring system performance, and collaborating... ...will have extensive experience with AWS, coding languages, and container...Amazon Web ServiceRemote job
$115k - $130k
...Cloud ServicesOverland Park,KansasTroy,MichiganYarmouth... ...to hire a Cloud Engineer to work a hybrid schedule... ...Design and develop infrastructure solutions to support business... ...Implement and manage AWS infrastructure using... ..., in area of specialty 6-8 years’ experience...Amazon Web ServiceCurrently hiring- ...Senior Level Cloud Engineer We are seeking a senior level cloud engineer capable of working... ...on the customer network within the AWS Platform. At the expert level the candidate... ...identifying, analyzing, and resolving infrastructure vulnerabilities and application deployment...Amazon Web ServiceWork experience placement
- ...Splunk Engineer Hybrid The candidate selected for this role will... .... Rowe Price. The Sr. Splunk Infrastructure Engineer will be responsible... ...Splunk from Windows, Linux and cloud-based sources Support... ...cloud-based solutions using AWS ~ Experience in onboarding...Amazon Web Service
- ...Overview Cloud Software Engineer McLean, VA TS/SCI with Poly At Bcore, our strength comes from how... ...developing software that runs within the AWS cloud 3 years experience with the AWS... ...Service (EKS). Experience deploying Infrastructure as Code (IaC) in an AWS ecosystems...Amazon Web Service
$140k - $155k
...Sr. Platform Engineer (remote) - $140k-$155k Immediate need for a Sr. Platform Engineer... ...of scalable, high-performance infrastructure to support mission-critical applications... ...hands-on experience designing and managing AWS cloud infrastructure. ~ Demonstrated expertise...Amazon Web ServiceLive inImmediate startRemote work$135k - $150k
...specializing in cybersecurity, cloud computing, and risk... ...in. Our world‑class team of engineers, consultants, and subject matter... ...role As a Splunk Engineer with AWS expertise, you will play a critical... ..., and maintain Splunk infrastructure within AWS environments, including...Amazon Web ServiceLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AWS Cloud Infrastructure Engineer (Keycloak Specialty). Be the first to apply!
- cloud developer Fairfax, VA
- senior principal cloud computing engineer Fairfax, VA
- aws cloud infrastructure engineer Fairfax, VA
- informatica cloud developer Fairfax, VA
- software engineer - cloud services Fairfax, VA
- cloud architect Fairfax, VA
- big data cloud engineer Fairfax, VA
- aws cloud architect Fairfax, VA
- senior cloud network engineer Fairfax, VA
- senior aws cloud engineer Fairfax, VA


