Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AWS Cloud Security and ICAM Specialist (Keycloak required)

LED FastStart

AWS Cloud Security And ICAM Specialist

The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.

Key Responsibilities:
  • Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM
  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify, Key Cloak)
  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
  • Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
  • Develop and document identity lifecycle management processes—provisioning, deprovisioning, and access reviews
  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak
  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
  • Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
  • Design and implement storage level, microservice level Authentication and Authorization
  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
  • Participate in design sessions and work closely with the security lead
  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
  • Direct and lead Pen testing, Review architecture diagrams produced by different teams
  • Independently lead design and implement of vulnerability management
  • Heavily participate in ATO activity
  • Lead and direct engineering team
Deliverable Alignment & Performance Outcomes:
  • Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
  • Access Control Documentation: Policies, RBAC models, and credential management workflows
  • Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
  • Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
  • Performance Outcomes:
    • 100% of CMM applications integrated with SSO and MFA.
    • Zero unauthorized access incidents attributable to configuration error
    • 100% compliance with NIST and FedRAMP ICAM control requirements
    • Reduced account provisioning time by ≥30% through automation
Tools & Technologies:
  • IAM & Federation: Key Cloak, Okta
  • Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
  • Cloud: AWS IAM, KMS, CloudTrail, Lambda
  • Protocols: SAML, OAuth2.0, OIDC, SCIM
  • Monitoring & Audit: Splunk
  • Collaboration: Jira, Confluence, SharePoint, MS Teams
Required Skills & Experience:
  • Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred
  • Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required; 12+ years of experience in information systems preferred
  • Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus)
  • Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
  • Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
  • Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
  • Experience implementing ICAM solutions in Agile and DevSecOps environments
  • Working knowledge of PKI, digital certificates, and encryption technologies
  • Strong analytical and troubleshooting skills with ability to resolve identity integration issues
  • Experience with AWS Container Security and Network Security (preferred, not required)
  • Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
  • Experience supporting federal digital modernization or judiciary IT programs.
  • Familiarity with Zero Trust Architecture and micro segmentation principles
  • Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).
  • Experience integrating identity governance tools (SailPoint, Saviynt).
  • Excellent presentation and communication skills
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
  • Demonstrated ability to work effectively, independently, and as part of a team
Certification(s):
  • Certified Information Systems Security Professional (CISSP) - preferred
  • AWS Certified Security – Specialty or Azure Identity & Access Administrator – preferred
  • Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) – beneficial
  • SAFe Practitioner (SPC/SSM) – a plus

Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts.

Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen).

Location: Remote

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

Explore an enterprise IT career at GDIT and

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the AWS Cloud Security and ICAM Specialist (Keycloak required) in United States vacancy
  • $153k - $207k

    LED FastStart is seeking an AWS Cloud Security and ICAM Specialist to support the Case Management Modernization Program. This role involves designing, implementing, and managing secure authentication frameworks within cloud-based applications while ensuring compliance... 
    Amazon Web Service
    Cloud
    Remote job

    LED FastStart

    Louisiana, MO
    2 days ago
  • Vivsoft-Technologies is seeking a Cyber Security Specialist to support a critical program for the Defense Counterintelligence...  ...involves ensuring compliance with DoD cybersecurity requirements in a secure AWS IL5 cloud environment. The ideal candidate has over 10 years... 
    Amazon Web Service
    Cloud
    Remote job
    Flexible hours

    Vivsoft-Technologies

    New York, NY
    4 days ago
  • $110.4k - $148.9k

     ...NETWORK Cyber Defense Specialist Apply now...  ...technical problems in cyber security, develop new...  ...machine learning, and cloud security ~ Represent...  ...areas is desired but not required: Experience working...  ...cybersecurity solutions (e.g. AWS, Azure, Google Cloud)... 
    Amazon Web Service
    Cloud

    MIT Lincoln Laboratory

    Maryland
    1 day ago
  • $93.37k - $153.4k

     ...Infosec Specialist - SOC We are seeking a senior-level...  ...complex, cross-functional security initiatives. We are...  ...security automation and cloud security across modern...  ...Frisco, TX. You will be required to be onsite on an as-needed...  ...and response (AWS, GCP and Azure) ~ Application... 
    Amazon Web Service
    Cloud
    Temporary work
    Relocation package
    Flexible hours
    Weekend work

    McAfee

    Frisco, TX
    1 day ago
  • $115k

     ...Systems Specialist ECI is the leading global provider of managed services...  ..., ECI provides stability, security and improved business...  ...technology programs, including Cloud implementation and support, desktop...  ...5/Azure, Amazon Web Services (AWS) Provide escalation support... 
    Amazon Web Service
    Cloud
    Remote work
    Worldwide
    Flexible hours

    ECI

    Boston, MA
    11 days ago
  • $165k - $195k

     ...rely on when speed and security matter most. The...  ...As a Senior DevOps Specialist, you will join VIA’s DevOps...  ...meets rigorous security requirements. In this role, you...  ...and maintenance of the cloud infrastructure, CI/CD...  ...depth experience with AWS; Azure, or GCP cloud service... 
    Amazon Web Service
    Cloud
    Summer work
    Remote work
    Work from home
    Flexible hours

    VIA

    Somerville, MA
    10 days ago
  •  ...mission-critical facilities, secure environments, complex...  ...We are seeking a Tech Specialist 2 to join our Security and...  ...systems Manage and maintain cloud-based infrastructure (e.g., AWS EC2 instances), including...  ...and may meet eligibility requirements, including U.S.... 
    Amazon Web Service
    Cloud
    Work at office
    Local area
    Remote work
    Flexible hours
    Night shift

    M.C. Dean, Inc.

    McLean, VA
    3 days ago
  • $86.8k - $198k

     ...The Opportunity Everyone knows security needs to be "baked in" to a...  ...accreditation of mobile and cloud-based security capabilities,...  ...with cloud environments such as AWS, Azure, M365, and SaaS...  ...may need to meet eligibility requirements for access to classified information... 
    Amazon Web Service
    Cloud
    Full time
    Part time
    Local area

    Phase2 Technology

    Lorton, VA
    2 days ago
  • $96k - $178k

     ...domains in the interest of national security. Job Title: Senior Specialist, Data Governance Job Code: 3...  ...objectives and regulatory requirements. As a Senior Specialist in Data...  ...lineage analysis Understanding of cloud data platforms (AWS, Azure, GCP) and modern data... 
    Amazon Web Service
    Cloud
    Local area
    Flexible hours

    L3Harris

    Melbourne, FL
    16 hours ago
  •  ...we've redefined modern security with the world's most...  ...innovation as our new Specialist Sales Engineer! What...  ...plus Experience with cloud security via one or more...  ...hyperscalers such as AWS, GCP or Azure a huge plus...  ...--on valid job requirements. If you need assistance... 
    Amazon Web Service
    Cloud
    Remote job
    Full time
    Work at office
    Local area
    Flexible hours

    CrowdStrike, Inc.

    Sunnyvale, CA
    6 hours ago
  •  ...play a pivotal role in delivering secure and resilient industrial solutions....  ...Impact Administer and support AWS (Amazon Web Services) Gov Cloud compliant with NIST 800-171 SP2 for...  ...ICS activities and ensure security requirements are met. Liaise with project execution... 
    Amazon Web Service
    Cloud
    Local area
    Visa sponsorship

    Siemens Energy

    Alpharetta, GA
    4 days ago
  • $100.5k - $185k

     ...in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer...  ...architectures that meet customer requirements. Analyzes, plans, and...  ..., Etc.) Familiarity with Cloud Networking services and architectures (AWS, Azure, or Google Cloud networking... 
    Amazon Web Service
    Cloud
    Local area
    Flexible hours

    L3Harris

    Colorado Springs, CO
    6 days ago
  •  ...mission-critical facilities, secure environments, complex...  ...a Deployment Network Specialist 4 to join our Security...  ...network. Experience with cloud provider environments such as AWS and Azure, with IL-2 or...  ...may meet eligibility requirements, including U.S. Citizenship... 
    Amazon Web Service
    Cloud
    Work experience placement
    Work at office
    Local area

    M.C. Dean, Inc.

    Springfield, VA
    5 days ago
  •  ...domains in the interest of national security. Job Title: Senior Specialist, Network Plan Engineer Job...  ...by translating customer requirements and objectives into final product...  ...classified and unclassfied cloud connectivity such as AWS or other government facilities... 
    Amazon Web Service
    Cloud
    Temporary work
    Work at office
    Local area

    L3Harris Technologies

    Palm Bay, FL
    4 days ago
  •  ...Technical Services Support Specialist The Technical Services...  ...issues which may require some research, thought,...  ...day-to-day work of the security operation center (SOC)....  ...complex technical problems. Cloud Security Engineer Tyler...  ...HTML5, SQL, and Cloud/AWS building scalable... 
    Amazon Web Service
    Cloud
    Contract work
    Temporary work
    Summer work
    Internship
    Summer internship
    Work at office
    Local area

    Tyler Technologies, Inc.

    Plano, TX
    3 days ago
  • $270k - $300k

     ...together advances in cloud infrastructure, automation...  ...at AHEAD. Our cloud security practice has grown 193...  ...AHEAD Cloud Security Specialist Solutions Engineer (SSE...  ...necessary to meet OEM requirements. Roles and...  ...least one hyperscaler (AWS, Azure, or GCP) including... 
    Amazon Web Service
    Cloud

    Medium

    Chicago, IL
    2 days ago
  •  ...solutions in: ~National Security Programs ~Professional...  ...and Access Management (ICAM) Subject Matter Expert...  ...appropriate security requirements.Duties include the following...  ...meetings, works with CLOUD SME to ensure that...  ...OKTA, CyberArk, Azure/AWS, Active Directory, LDAP... 
    Amazon Web Service
    Cloud
    Full time
    For contractors
    Remote work

    gTANGIBLE Corporation

    Arlington, VA
    16 days ago
  • $180k - $247.5k

    FEQ127R316 As a Specialist Solutions Architect (SSA) - Cloud Infrastructure & Platform, you will...  ...the administration and security of their Databricks deployments...  ...Architects, which requires hands-on production experience...  ...with public cloud - AWS, Azure, and GCP. SSAs help... 
    Amazon Web Service
    Cloud
    Full time
    Work experience placement
    Local area
    Remote work
    Worldwide

    Databricks

    California
    8 hours ago
  •  ...seeking a Cybersecurity Specialist with expertise in...  ...This role focuses on securing enterprise systems, ensuring...  ...modernization. Requirements : U.S....  ...Familiarity with cloud security in AWS (GovCloud preferred)...  ...access management (IAM/ICAM) solutions Enforce... 
    Amazon Web Service
    Cloud
    For contractors
    Remote work

    Network Designs

    Washington DC
    8 days ago
  • $86.8k - $198k

     ...Number: R0239948 ICAM Solutions Engineer...  ...perimeter is drawn, and securing identities is...  ...access requirements and defining enterprise...  ...with tools such as AWS IAM, Microsoft Entra...  ...Experience with Keycloak or Cognito Experience...  ...solutions within secure cloud and on-premises... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Mc Lean, VA
    2 days ago
  • $86.8k - $198k

     ...Number: R0238565 ICAM Architect The...  ...perimeter is drawn, and securing identities is...  ...(IAM) specialist, you have the skills...  ...articulating access requirements and defining...  ...solutions Knowledge of cloud identity platforms such as AWS Cognito, Azure AD B2C, KeyCLoak, or Google Cloud... 
    Amazon Web Service
    Cloud
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Mc Lean, VA
    1 day ago
  •  ...Cybersecurity and Infrastructure Security Agency (CISA). This...  ..., and Access Management (ICAM), Zero Trust architecture, cloud services, and enterprise...  ...with all contract requirements, government regulations,...  ...certifications (e.g., CISSP, AWS, Azure, etc.) are a plus.... 
    Amazon Web Service
    Cloud
    Contract work
    Remote work

    Sev1Tech

    United States
    3 days ago
  • $70 - $95 per hour

     ...role focuses on enhancing security operations through the...  ...As a SOC Investigation Specialist, you will engage in...  ...including SIEM, endpoint, cloud, and identity...  ...security investigations when required, including log analysis...  ...logs and signals from AWS (CloudTrail, GuardDuty)... 
    Amazon Web Service
    Cloud
    Remote job
    Hourly pay

    SaidGig

    Remote
    more than 2 months ago
  • $204k - $310k

     ...looking for a Principal Security Architect to lead the...  ...security architecture for cloud applications operating...  ...and access management (ICAM) Network segmentation...  ...translating complex requirements into scalable architecture...  ...experience in AWS GovCloud Experience... 
    Amazon Web Service
    Cloud

    Lila Sciences

    San Francisco, CA
    3 days ago
  •  ...: SOC & IR Specialist The Company: Varonis (Nasdaq...  ...VRNS) is a leader in data security, fighting a different...  ...cybersecurity companies. Our cloud-native Data Security...  ...team. This role requires a deep understanding of...  ...Proficient in Azure and AWS Cloud platforms ~ Strong... 
    Amazon Web Service
    Cloud
    Full time
    Worldwide

    Varonis

    United States
    1 day ago
  •  ...Keycloak Expert Atos Group is a global leader in digital...  ...one in cybersecurity, cloud and high performance...  ...Group is committed to a secure and decarbonized future...  ...directories Required Skills and Experience:...  ...certifications e.g. Google Cloud, AWS, ITIL Conferences and... 
    Amazon Web Service
    Cloud
    Remote work

    World Grid

    United States
    1 day ago
  •  ...Systems Integration Senior Specialist to join our team in...  ...•    Knowledge of Pivotal Cloud Foundry (PCF), AWS, GCP, or Azure" About NTT...  ...enterprise-scale AI, cloud, security, connectivity, data centers...  ...to change based on client requirements. For employees near an NTT... 
    Amazon Web Service
    Cloud
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Indiana
    10 hours ago
  •  ...interest of national security. Job Title: Senior Specialist, Software Engineering...  ...infrastructure team leverages Cloud Service Providers (AWS, Microsoft Azure,...  ...(IAM) solutions using Keycloak Assist in migrating...  ...many of our positions require the ability to obtain... 
    Amazon Web Service
    Cloud
    Local area

    L3Harris

    Palm Bay, FL
    5 days ago
  • $86.8k - $198k

    ICAM Architect**The Opportunity****:*...  ...perimeter is drawn, and securing identities is...  ...(IAM) specialist, you have the skills...  ...articulating access requirements and defining...  ...solutions* Knowledge of cloud identity platforms such as AWS Cognito, Azure AD B2C, KeyCLoak, or Google Cloud... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Mc Lean, VA
    1 day ago
  •  ...currently seeking a Network Security Sr. Specialist Advisor to join our team in...  ...operational processes. The role requires the ability to work...  ...switching, F5, SD-WAN, and AWS networking Strong expertise...  ...capabilities in enterprise-scale AI, cloud, security, connectivity,... 
    Amazon Web Service
    Cloud
    Work at office
    Immediate start
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Indiana
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AWS Cloud Security and ICAM Specialist (Keycloak required). Be the first to apply!