AWS Cloud Security and ICAM Specialist
General Dynamics
AWS Cloud Security And ICAM Specialist
The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.
Key Responsibilities:
- Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM
- Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
- Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
- Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify, Key Cloak)
- Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
- Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
- Develop and document identity lifecycle management processes -provisioning, deprovisioning, and access reviews
- Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
- Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak
- Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
- Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
- Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
- Design and implement storage level, microservice level Authentication and Authorization
- Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
- Participate in design sessions and work closely with the security lead
- Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
- Direct and lead Pen testing, Review architecture diagrams produced by different teams
- Independently lead design and implement of vulnerability management
- Heavily participate in ATO activity
- Lead and direct engineering team
Deliverable Alignment & Performance Outcomes:
- Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
- Access Control Documentation: Policies, RBAC models, and credential management workflows
- Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
- Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
- Performance Outcomes:
- 100% of CMM applications integrated with SSO and MFA.
- Zero unauthorized access incidents attributable to configuration error
- 100% compliance with NIST and FedRAMP ICAM control requirements
- Reduced account provisioning time by 30% through automation
Tools & Technologies:
- IAM & Federation: Key Cloak, Okta
- Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
- Cloud: AWS IAM, KMS, CloudTrail, Lambda
- Protocols: SAML, OAuth2.0, OIDC, SCIM
- Monitoring & Audit: Splunk
- Collaboration: Jira, Confluence, SharePoint, MS Teams
Required Skills & Experience:
- Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred
- Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required; 12+ years of experience in information systems preferred
- Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus)
- Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
- Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
- Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
- Experience implementing ICAM solutions in Agile and DevSecOps environments
- Working knowledge of PKI, digital certificates, and encryption technologies
- Strong analytical and troubleshooting skills with ability to resolve identity integration issues
- Experience with AWS Container Security and Network Security (preferred, not required)
- Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
- Experience supporting federal digital modernization or judiciary IT programs.
- Familiarity with Zero Trust Architecture and micro segmentation principles
- Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).
- Experience integrating identity governance tools (SailPoint, Saviynt).
- Excellent presentation and communication skills
- Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship
- Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
- Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
- Demonstrated ability to work effectively, independently, and as part of a team
Certification(s):
- Certified Information Systems Security Professional (CISSP) - preferred
- AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred
- Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial
- SAFe Practitioner (SPC/SSM) - a plus
Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts. Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen). Location: Remote
- ...Identity, Credential, and Access Management (ICAM) Security Engineer Location: Washington, DC... ...methods for enterprise platforms on the cloud, as well as for those hosted on-premises... ...management within Azure AD, Okta, and AWS, including integrations for containers,...Amazon Web ServiceCloudWork at office
- ...Caesars is seeking a Specialist Analyst to join our cybersecurity team and play a critical role in managing and enhancing our Security Operations Center (SOC) with a focus on AWS cloud environment. In this position, you will apply your expertise in cloud security, threat...Amazon Web ServiceCloud
- ...To support a growing multi-cloud environment, the remote contract Lead IAM Specialist will architect and operationalize an enterprise... ...program, focusing on zero trust security architecture and policy-as-code implementation across AWS, Azure, and GCP. Key Responsibilities...Amazon Web ServiceCloudContract workRemote work
- ...IAM KeyCloak / Redhat SSO Specialist Location: 100% Remote Duration... ...customization of login modules and security solutions for Single Sign On... ...in Identity Management -AWS DevOps Engineer – Professional... ...SSO -2 years' experience with Cloud Native & AWS -2 years' experience...Amazon Web ServiceCloudRemote work
- ...Edge Connectivity Specialist 2 Independently support enterprise connectivity... ..., firewall operations, and cloud-connected edge environments.... ...private connectivity, network security controls, and hybrid... ...environments. Exposure to Azure and/or AWS networking services....Amazon Web ServiceCloudWork at officeMonday to FridayShift work
- ...Job Title Design implement and manage AWS Cloud Infrastructure to ensure high availability scalability and security Develop and maintain CICD pipelines to automate the deployment process and ensure smooth and efficient software delivery Monitor system performance...Amazon Web ServiceCloud
- ...Specialist Analyst, Cybersecurity/h2pCaesars is seeking a Specialist Analyst to join our cybersecurity team and play a critical role in managing and enhancing our Security Operations Center (SOC) with a focus on AWS cloud environment. In this position, you will apply your...Amazon Web ServiceCloudFull timeRemote work
$86.8k - $198k
...Job Number: R0239449 ICAM Security Engineer The Opportunity: The user is the last frontier... ...technical security controls across multi-cloud and multi-vendor ecosystems... ...supporting IAM in a Cloud environment, including AWS or Azure Knowledge of cybersecurity...Amazon Web ServiceCloudFull timeContract workPart timeWork at officeLocal areaRemote work$91.87k - $137.81k
...currently seeking a ESRI/ArcGIS Specialist to join our team in Arlington,... ...FedRAMP and other government security standards. Additional... ...data management • Knowledge of AWS GovCloud architecture • Familiarity... ...in enterprise-scale AI, cloud, security, connectivity, data...Amazon Web ServiceCloudTemporary workWork at officeRemote workFlexible hours$153.6k - $207.8k
...5, 2026 This position is part of the AWS Specialist and Partner Organization (ASP). Specialists... ...domain-specific expertise in critical security domains. As part of the AWS sales... ...architectures, including hybrid, multi-cloud, and post-quantum cryptography migration...Amazon Web ServiceCloudFlexible hours$110.4k - $148.9k
...TALENT NETWORK Cyber Defense Specialist Apply now Date:... ...technical problems in cyber security, develop new technologies, and... ...intelligence, machine learning, and cloud security ~ Represent MIT... ...cybersecurity solutions (e.g. AWS, Azure, Google Cloud)...Amazon Web ServiceCloud$81.6k - $142.8k
...Description At Amazon Web Services (AWS), Security is our highest priority. The AWS Security Assurance team is responsible for demonstrating... ...to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical...Amazon Web ServiceCloudFlexible hours$93.37k - $153.4k
...Job Title: InfoSec Specialist - SOC Role Overview: We are seeking... ...complex, cross-functional security initiatives. We are looking for... ...capabilities in security automation and cloud security across modern... ...- detection and response (AWS, GCP and Azure) ~ Application...Amazon Web ServiceCloudTemporary workRelocation packageFlexible hoursWeekend work$162.7k - $220.2k
...desktops toward intelligent, cloud-native workspaces that adapt to... ...actually work—powered by AI, secured by design, and delivered anywhere... ...workflows and tasks. AWS serves millions of customers in... ...seeking a Worldwide (WW) GTM Specialist to drive the next chapter of growth...Amazon Web ServiceCloudLocal areaWorldwideFlexible hours$74.2k - $129.8k
...enable business? Amazon Web Services (AWS) Security is looking for an experienced,... ...and results-oriented Security Industry Specialist to join the AWS Security Assurance team... ...experience in a wide variety of areas including cloud, devices, retail, entertainment,...Amazon Web ServiceCloudFlexible hours$86.8k - $198k
...Share Cybersecurity Specialist The Opportunity: Everyone knows security needs to be "baked in" to a system... ...like accreditation of mobile and cloud-based security capabilities, while... ...with cloud environments such as AWS, Azure, M365, and SaaS applications...Amazon Web ServiceCloudFull timeContract workPart timeWork at officeLocal areaRemote work$58.14k - $83.05k
...Edge Connectivity Specialist 1 At HDR, our employee-owners are fully... ...datacenter. Assist with basic public cloud networking tasks such as reviewing route tables, security groups, NSGs, or connectivity... ...networking in Azure and/or AWS. Familiarity with firewall administration...Amazon Web ServiceCloudFull timeTemporary workPart timeWork at officeRemote workMonday to FridayShift work$115k
...Systems Specialist ECI is the leading global provider of managed services... ..., ECI provides stability, security and improved business... ...technology programs, including Cloud implementation and support, desktop... ...5/Azure, Amazon Web Services (AWS) Provide escalation support...Amazon Web ServiceCloudRemote workWorldwideFlexible hours- ...most mission-critical facilities, secure environments, complex infrastructure... ...industries. We are seeking a Tech Specialist 2 to join our Security and... ...intercom systems Manage and maintain cloud-based infrastructure (e.g., AWS EC2 instances), including provisioning...Amazon Web ServiceCloudWork at officeLocal areaRemote workFlexible hoursNight shift
$131.3k - $237.35k
...environment where you can thrive, keep reading! TheIntel Security Sectordelivers technology-enabled services and... ...compliance standards. ~ Experience supporting cloud security monitoring and compliance within AWS, Azure, Oracle (OCI)or Google Cloud environments....Amazon Web ServiceCloudLocal areaImmediate startFlexible hours$165k - $195k
...organizations rely on when speed and security matter most. The Department of... .... As a Senior DevOps Specialist, you will join VIA’s DevOps... ...build, and maintenance of the cloud infrastructure, CI/CD pipelines... ...) ~ In-depth experience with AWS; Azure, or GCP cloud service providers...Amazon Web ServiceCloudSummer workRemote workWork from homeFlexible hours$176.6k - $239k
...Description Amazon Web Services (AWS) Specialist Solutions Architects (SSAs) are technologists... ...application or designing entirely new cloud-based systems. Do you enjoy solving... ...you will share recommendations around security, cost, performance, reliability and operational...Amazon Web ServiceCloudWork experience placementLocal areaWorldwideFlexible hours$100.5k - $185k
...and cyber domains in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer Job Code: 36904... ...OpenFlow, Cisco ACI, Etc.) Familiarity with Cloud Networking services and architectures (AWS, Azure, or Google Cloud networking, Etc.)...Amazon Web ServiceCloudLocal areaFlexible hours- ...business. By weaving together advances in cloud infrastructure, automation and analytics,... ...perspectives at AHEAD. The AHEAD Security Specialty Solutions Engineer (SSE) will be... ...development. ~ FamiliarwithPublicCloudproviders: AWS, Azure, GCP ~ Ability to grasp new...Amazon Web ServiceCloudWork at office
- ...Cybersecurity Expert (ICSE) and play a pivotal role in delivering secure and resilient industrial solutions. You will leverage... ...How You'll Make an Impact Administer and support AWS (Amazon Web Services) Gov Cloud compliant with NIST 800-171 SP2 for Controlled...Amazon Web ServiceCloudLocal areaVisa sponsorship
- ...Deployment Network Specialist 4 M.C. Dean is Building Intelligence®. We design... ...most mission-critical facilities, secure environments, complex infrastructure... ...of the network. Experience with cloud provider environments such as AWS and Azure, with IL-2 or higher experience...Amazon Web ServiceCloudWork experience placementWork at officeLocal area
$86.8k - $198k
...requisition id: R0240633Cybersecurity Specialist**The Opportunity:**Everyone knows security needs to be “baked in” to a system... ...like accreditation of mobile and cloud-based security capabilities, while... ...with cloud environments such as AWS, Azure, M365, and SaaS...Amazon Web ServiceCloudFull timeContract workPart timeWork at officeRemote work- ...sea and cyber domains in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer Job Code: 38215 Job... ...Experience working with classified and unclassfied cloud connectivity such as AWS or other government facilities. Experience in...Amazon Web ServiceCloudTemporary workWork at officeLocal area
- ...land, sea and cyber domains in the interest of national security. Job Title: Specialist Systems Engineer – DMS Engineer Job Code: 35225... ...TensorFlow, PyTorch, scikit-learn, Keras). Knowledge of cloud platforms (AWS, Azure, Google Cloud) and their AI/ML services....Amazon Web ServiceCloudLocal area
- ...and solutions in: ~National Security Programs ~Professional, Administrative... ..., and Access Management (ICAM) Subject Matter Expert (SME)... ...meetings, works with CLOUD SME to ensure that Identity Management... ...SailPoint, OKTA, CyberArk, Azure/AWS, Active Directory, LDAP, SSO,...Amazon Web ServiceCloudFull timeFor contractorsRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AWS Cloud Security and ICAM Specialist. Be the first to apply!
- cloud security consultant United States
- cloud consultant United States
- cloud computing analyst United States
- salesforce marketing cloud consultant United States
- salesforce service cloud consultant United States
- cloud operations specialist United States
- cloud solution specialist United States
- salesforce marketing cloud specialist United States
- cloud security analyst United States
- oracle cloud financials consultant United States

