Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AWS Cloud Security and ICAM Specialist

General Dynamics

AWS Cloud Security And ICAM Specialist

The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.

Key Responsibilities:

  • Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM
  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify, Key Cloak)
  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
  • Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
  • Develop and document identity lifecycle management processes -provisioning, deprovisioning, and access reviews
  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak
  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
  • Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
  • Design and implement storage level, microservice level Authentication and Authorization
  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
  • Participate in design sessions and work closely with the security lead
  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
  • Direct and lead Pen testing, Review architecture diagrams produced by different teams
  • Independently lead design and implement of vulnerability management
  • Heavily participate in ATO activity
  • Lead and direct engineering team

Deliverable Alignment & Performance Outcomes:

  • Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
  • Access Control Documentation: Policies, RBAC models, and credential management workflows
  • Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
  • Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
  • Performance Outcomes:
    • 100% of CMM applications integrated with SSO and MFA.
    • Zero unauthorized access incidents attributable to configuration error
    • 100% compliance with NIST and FedRAMP ICAM control requirements
    • Reduced account provisioning time by 30% through automation

Tools & Technologies:

  • IAM & Federation: Key Cloak, Okta
  • Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
  • Cloud: AWS IAM, KMS, CloudTrail, Lambda
  • Protocols: SAML, OAuth2.0, OIDC, SCIM
  • Monitoring & Audit: Splunk
  • Collaboration: Jira, Confluence, SharePoint, MS Teams

Required Skills & Experience:

  • Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred
  • Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required; 12+ years of experience in information systems preferred
  • Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus)
  • Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
  • Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
  • Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
  • Experience implementing ICAM solutions in Agile and DevSecOps environments
  • Working knowledge of PKI, digital certificates, and encryption technologies
  • Strong analytical and troubleshooting skills with ability to resolve identity integration issues
  • Experience with AWS Container Security and Network Security (preferred, not required)
  • Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
  • Experience supporting federal digital modernization or judiciary IT programs.
  • Familiarity with Zero Trust Architecture and micro segmentation principles
  • Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).
  • Experience integrating identity governance tools (SailPoint, Saviynt).
  • Excellent presentation and communication skills
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
  • Demonstrated ability to work effectively, independently, and as part of a team

Certification(s):

  • Certified Information Systems Security Professional (CISSP) - preferred
  • AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred
  • Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial
  • SAFe Practitioner (SPC/SSM) - a plus

Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts. Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen). Location: Remote

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the AWS Cloud Security and ICAM Specialist in United States vacancy
  •  ...Identity, Credential, and Access Management (ICAM) Security Engineer Location: Washington, DC...  ...methods for enterprise platforms on the cloud, as well as for those hosted on-premises...  ...management within Azure AD, Okta, and AWS, including integrations for containers,... 
    Amazon Web Service
    Cloud
    Work at office

    Ampcus

    Washington DC
    3 days ago
  •  ...Caesars is seeking a Specialist Analyst to join our cybersecurity team and play a critical role in managing and enhancing our Security Operations Center (SOC) with a focus on AWS cloud environment. In this position, you will apply your expertise in cloud security, threat... 
    Amazon Web Service
    Cloud

    Caesars Entertainment

    Las Vegas, NV
    2 days ago
  •  ...To support a growing multi-cloud environment, the remote contract Lead IAM Specialist will architect and operationalize an enterprise...  ...program, focusing on zero trust security architecture and policy-as-code implementation across AWS, Azure, and GCP. Key Responsibilities... 
    Amazon Web Service
    Cloud
    Contract work
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...IAM KeyCloak / Redhat SSO Specialist Location: 100% Remote Duration...  ...customization of login modules and security solutions for Single Sign On...  ...in Identity Management -AWS DevOps Engineer – Professional...  ...SSO -2 years' experience with Cloud Native & AWS -2 years' experience... 
    Amazon Web Service
    Cloud
    Remote work

    ShiftCode Analytics

    United States
    1 day ago
  •  ...Edge Connectivity Specialist 2 Independently support enterprise connectivity...  ..., firewall operations, and cloud-connected edge environments....  ...private connectivity, network security controls, and hybrid...  ...environments. Exposure to Azure and/or AWS networking services.... 
    Amazon Web Service
    Cloud
    Work at office
    Monday to Friday
    Shift work

    HDR

    Orlando, FL
    4 days ago
  •  ...Job Title Design implement and manage AWS Cloud Infrastructure to ensure high availability scalability and security Develop and maintain CICD pipelines to automate the deployment process and ensure smooth and efficient software delivery Monitor system performance... 
    Amazon Web Service
    Cloud

    Futran Tech Solutions Pvt. Ltd.

    Irvine, CA
    2 days ago
  •  ...Specialist Analyst, Cybersecurity/h2pCaesars is seeking a Specialist Analyst to join our cybersecurity team and play a critical role in managing and enhancing our Security Operations Center (SOC) with a focus on AWS cloud environment. In this position, you will apply your... 
    Amazon Web Service
    Cloud
    Full time
    Remote work

    Caesars Entertainment

    Las Vegas, NV
    4 days ago
  • $86.8k - $198k

     ...Job Number: R0239449 ICAM Security Engineer The Opportunity: The user is the last frontier...  ...technical security controls across multi-cloud and multi-vendor ecosystems...  ...supporting IAM in a Cloud environment, including AWS or Azure Knowledge of cybersecurity... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $91.87k - $137.81k

     ...currently seeking a ESRI/ArcGIS Specialist to join our team in Arlington,...  ...FedRAMP and other government security standards. Additional...  ...data management • Knowledge of AWS GovCloud architecture • Familiarity...  ...in enterprise-scale AI, cloud, security, connectivity, data... 
    Amazon Web Service
    Cloud
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT America

    Arlington, VA
    2 days ago
  • $153.6k - $207.8k

     ...5, 2026 This position is part of the AWS Specialist and Partner Organization (ASP). Specialists...  ...domain-specific expertise in critical security domains. As part of the AWS sales...  ...architectures, including hybrid, multi-cloud, and post-quantum cryptography migration... 
    Amazon Web Service
    Cloud
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  • $110.4k - $148.9k

     ...TALENT NETWORK Cyber Defense Specialist Apply now Date:...  ...technical problems in cyber security, develop new technologies, and...  ...intelligence, machine learning, and cloud security ~ Represent MIT...  ...cybersecurity solutions (e.g. AWS, Azure, Google Cloud)... 
    Amazon Web Service
    Cloud

    MIT Lincoln Laboratory

    Maryland
    2 days ago
  • $81.6k - $142.8k

     ...Description At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Assurance team is responsible for demonstrating...  ...to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical... 
    Amazon Web Service
    Cloud
    Flexible hours

    Amazon

    Arlington, VA
    5 days ago
  • $93.37k - $153.4k

     ...Job Title: InfoSec Specialist - SOC Role Overview: We are seeking...  ...complex, cross-functional security initiatives. We are looking for...  ...capabilities in security automation and cloud security across modern...  ...- detection and response (AWS, GCP and Azure) ~ Application... 
    Amazon Web Service
    Cloud
    Temporary work
    Relocation package
    Flexible hours
    Weekend work

    McAfee

    San Jose, CA
    2 days ago
  • $162.7k - $220.2k

     ...desktops toward intelligent, cloud-native workspaces that adapt to...  ...actually work—powered by AI, secured by design, and delivered anywhere...  ...workflows and tasks. AWS serves millions of customers in...  ...seeking a Worldwide (WW) GTM Specialist to drive the next chapter of growth... 
    Amazon Web Service
    Cloud
    Local area
    Worldwide
    Flexible hours

    Amazon

    Santa Clara, CA
    4 days ago
  • $74.2k - $129.8k

     ...enable business? Amazon Web Services (AWS) Security is looking for an experienced,...  ...and results-oriented Security Industry Specialist to join the AWS Security Assurance team...  ...experience in a wide variety of areas including cloud, devices, retail, entertainment,... 
    Amazon Web Service
    Cloud
    Flexible hours

    Amazon

    Herndon, VA
    1 day ago
  • $86.8k - $198k

     ...Share Cybersecurity Specialist The Opportunity: Everyone knows security needs to be "baked in" to a system...  ...like accreditation of mobile and cloud-based security capabilities, while...  ...with cloud environments such as AWS, Azure, M365, and SaaS applications... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    4 days ago
  • $58.14k - $83.05k

     ...Edge Connectivity Specialist 1 At HDR, our employee-owners are fully...  ...datacenter. Assist with basic public cloud networking tasks such as reviewing route tables, security groups, NSGs, or connectivity...  ...networking in Azure and/or AWS. Familiarity with firewall administration... 
    Amazon Web Service
    Cloud
    Full time
    Temporary work
    Part time
    Work at office
    Remote work
    Monday to Friday
    Shift work

    HDR

    Denver, CO
    4 days ago
  • $115k

     ...Systems Specialist ECI is the leading global provider of managed services...  ..., ECI provides stability, security and improved business...  ...technology programs, including Cloud implementation and support, desktop...  ...5/Azure, Amazon Web Services (AWS) Provide escalation support... 
    Amazon Web Service
    Cloud
    Remote work
    Worldwide
    Flexible hours

    ECI

    Boston, MA
    2 days ago
  •  ...most mission-critical facilities, secure environments, complex infrastructure...  ...industries. We are seeking a Tech Specialist 2 to join our Security and...  ...intercom systems Manage and maintain cloud-based infrastructure (e.g., AWS EC2 instances), including provisioning... 
    Amazon Web Service
    Cloud
    Work at office
    Local area
    Remote work
    Flexible hours
    Night shift

    M.C. Dean, Inc.

    McLean, VA
    4 days ago
  • $131.3k - $237.35k

     ...environment where you can thrive, keep reading! TheIntel Security Sectordelivers technology-enabled services and...  ...compliance standards. ~ Experience supporting cloud security monitoring and compliance within AWS, Azure, Oracle (OCI)or Google Cloud environments.... 
    Amazon Web Service
    Cloud
    Local area
    Immediate start
    Flexible hours

    Leidos

    Reston, VA
    1 day ago
  • $165k - $195k

     ...organizations rely on when speed and security matter most. The Department of...  .... As a Senior DevOps Specialist, you will join VIA’s DevOps...  ...build, and maintenance of the cloud infrastructure, CI/CD pipelines...  ...) ~ In-depth experience with AWS; Azure, or GCP cloud service providers... 
    Amazon Web Service
    Cloud
    Summer work
    Remote work
    Work from home
    Flexible hours

    VIA

    Somerville, MA
    1 day ago
  • $176.6k - $239k

     ...Description Amazon Web Services (AWS) Specialist Solutions Architects (SSAs) are technologists...  ...application or designing entirely new cloud-based systems. Do you enjoy solving...  ...you will share recommendations around security, cost, performance, reliability and operational... 
    Amazon Web Service
    Cloud
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Amazon

    San Francisco, CA
    2 days ago
  • $100.5k - $185k

     ...and cyber domains in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer Job Code: 36904...  ...OpenFlow, Cisco ACI, Etc.) Familiarity with Cloud Networking services and architectures (AWS, Azure, or Google Cloud networking, Etc.)... 
    Amazon Web Service
    Cloud
    Local area
    Flexible hours

    L3Harris

    Colorado Springs, CO
    2 days ago
  •  ...business. By weaving together advances in cloud infrastructure, automation and analytics,...  ...perspectives at AHEAD. The AHEAD Security Specialty Solutions Engineer (SSE) will be...  ...development. ~ FamiliarwithPublicCloudproviders: AWS, Azure, GCP ~ Ability to grasp new... 
    Amazon Web Service
    Cloud
    Work at office

    AHEAD

    Indianapolis, IN
    3 days ago
  •  ...Cybersecurity Expert (ICSE) and play a pivotal role in delivering secure and resilient industrial solutions. You will leverage...  ...How You'll Make an Impact Administer and support AWS (Amazon Web Services) Gov Cloud compliant with NIST 800-171 SP2 for Controlled... 
    Amazon Web Service
    Cloud
    Local area
    Visa sponsorship

    Siemens Energy

    Houston, TX
    5 days ago
  •  ...Deployment Network Specialist 4 M.C. Dean is Building Intelligence®. We design...  ...most mission-critical facilities, secure environments, complex infrastructure...  ...of the network. Experience with cloud provider environments such as AWS and Azure, with IL-2 or higher experience... 
    Amazon Web Service
    Cloud
    Work experience placement
    Work at office
    Local area

    M.C. Dean, Inc.

    Springfield, VA
    16 hours ago
  • $86.8k - $198k

     ...requisition id: R0240633Cybersecurity Specialist**The Opportunity:**Everyone knows security needs to be “baked in” to a system...  ...like accreditation of mobile and cloud-based security capabilities, while...  ...with cloud environments such as AWS, Azure, M365, and SaaS... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Remote work

    Booz Allen Hamilton

    Lorton, VA
    4 days ago
  •  ...sea and cyber domains in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer Job Code: 38215 Job...  ...Experience working with classified and unclassfied cloud connectivity such as AWS or other government facilities. Experience in... 
    Amazon Web Service
    Cloud
    Temporary work
    Work at office
    Local area

    L3Harris Technologies

    Palm Bay, FL
    10 hours ago
  •  ...land, sea and cyber domains in the interest of national security. Job Title: Specialist Systems Engineer – DMS Engineer Job Code: 35225...  ...TensorFlow, PyTorch, scikit-learn, Keras). Knowledge of cloud platforms (AWS, Azure, Google Cloud) and their AI/ML services.... 
    Amazon Web Service
    Cloud
    Local area

    L3Harris

    Salt Lake City, UT
    4 days ago
  •  ...and solutions in: ~National Security Programs ~Professional, Administrative...  ..., and Access Management (ICAM) Subject Matter Expert (SME)...  ...meetings, works with CLOUD SME to ensure that Identity Management...  ...SailPoint, OKTA, CyberArk, Azure/AWS, Active Directory, LDAP, SSO,... 
    Amazon Web Service
    Cloud
    Full time
    For contractors
    Remote work

    gTANGIBLE Corporation

    Arlington, VA
    7 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AWS Cloud Security and ICAM Specialist. Be the first to apply!