Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AWS Cloud Security and ICAM Specialist (Keycloak required)

$153k - $207k

Gdit

Req ID: RQ220978

Type of Requisition: Regular

Clearance Level Must Be Able to Obtain: None

Public Trust/Other Required: BI Full 6C (T4)

Job Family: IT Infrastructure and Operations

Skills:

Access Management,Identity Governance,Secure Authentication

Certifications:

Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2)

Experience:

10 + years of related experience

Job Description:

The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.

Key Responsibilities:

  • Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM

  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)

  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs

  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak)

  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application

  • Design ICAM brokerage solutions and support compliance assessments , ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls

  • Develop and document identity lifecycle management processes -provisioning, deprovisioning, and access reviews

  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system

  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak

  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance

  • Provide subject matter expertise in identity federation, PKI, certificate management , and secure API authorization

  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs

  • Design and implement storage level, microservice level Authentication and Authorization

  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams

  • Participate in design sessions and work closely with the security lead

  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates

  • Direct and lead Pen testing, Review architecture diagrams produced by different teams

  • Independently lead design and implement of vulnerability management

  • Heavily participate in ATO activity

  • Lead and direct engineering team

Deliverable Alignment & Performance Outcomes:

  • Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems

  • Access Control Documentation: Policies, RBAC models, and credential management workflows

  • Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards

  • Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components

  • Performance Outcomes:

  • 100% of CMM applications integrated with SSO and MFA.

  • Zero unauthorized access incidents attributable to configuration error

  • 100% compliance with NIST and FedRAMP ICAM control requirements

  • Reduced account provisioning time by =30% through automation

Tools & Technologies:

  • IAM & Federation: Key Cloak , Okta

  • Access & Compliance: SailPoint, CyberArk, HashiCorp Vault

  • Cloud: AWS IAM, KMS, CloudTrail, Lambda

  • Protocols: SAML, OAuth2.0, OIDC, SCIM

  • Monitoring & Audit: Splunk

  • Collaboration: Jira, Confluence, SharePoint, MS Teams

Required Skills & Experience:

  • Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred

  • Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environmentsrequired ; 12+ years of experience in information systems preferred

  • Hands-on experience with Key Cloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus)

  • Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows

  • Expertise with RBAC/ABAC frameworks , policy-based access control, and least-privilege enforcement

  • Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks

  • Experience implementing ICAM solutions in Agile and DevSecOps environments

  • Working knowledge of PKI, digital certificates, and encryption technologies

  • Strong analytical and troubleshooting skills with ability to resolve identity integration issues

  • Experience with AWS Container Security and Network Security (preferred, not required)

  • Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system

  • Experience supporting federal digital modernization or judiciary IT programs.

  • Familiarity with Zero Trust Architecture and micro segmentation principles

  • Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).

  • Experience integrating identity governance tools (SailPoint, Saviynt).

  • Excellent presentation and communication skills

  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship

  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies

  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement

  • Demonstrated ability to work effectively, independently, and as part of a team

Certification(s):

  • Certified Information Systems Security Professional (CISSP) - preferred

  • AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred

  • Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial

  • SAFe Practitioner (SPC/SSM) - a plus

Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts.

Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen).

Location: Remote

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities

  • Support: An internal mobility team focused on helping you achieve your career goals

  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

  • Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY

Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the AWS Cloud Security and ICAM Specialist (Keycloak required) in Fairfax, VA vacancy
  •  ...Edge Connectivity Specialist 2 Independently support...  ...firewall operations, and cloud-connected edge...  ...connectivity, network security controls, and hybrid interconnects...  ..., and change control requirements. Create and maintain...  ...to Azure and/or AWS networking services. Experience... 
    Amazon Web Service
    Cloud
    Work at office
    Monday to Friday
    Shift work

    HDR

    Vienna, VA
    2 days ago
  • $86.8k - $198k

     ...Job Number: R0239449 ICAM Security Engineer The Opportunity: The...  ...lifecycle, articulate access requirements, and define enterprise identity...  ...controls across multi-cloud and multi-vendor ecosystems...  ...Cloud environment, including AWS or Azure Knowledge of cybersecurity... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  •  ...mission-critical facilities, secure environments, complex...  ...We are seeking a Tech Specialist 2 to join our Security and...  ...systems Manage and maintain cloud-based infrastructure (e.g., AWS EC2 instances), including...  ...and may meet eligibility requirements, including U.S.... 
    Amazon Web Service
    Cloud
    Work at office
    Local area
    Remote work
    Flexible hours
    Night shift

    M.C. Dean, Inc.

    Vienna, VA
    6 days ago
  • $58.14k - $83.05k

     ...Edge Connectivity Specialist 1 At HDR, our employee-owners...  ...with basic public cloud networking tasks such as...  ...reviewing route tables, security groups, NSGs, or...  ...Additionally, this position requires scheduled on-call flexibility...  ...in Azure and/or AWS. Familiarity with firewall... 
    Amazon Web Service
    Cloud
    Full time
    Temporary work
    Part time
    Work at office
    Remote work
    Monday to Friday
    Shift work

    HDR

    Vienna, VA
    2 days ago
  • $91.87k - $137.81k

     ...seeking a ESRI/ArcGIS Specialist to join our team in Arlington...  ...and other government security standards. Additional...  ...• Knowledge of AWS GovCloud architecture...  ...additional voluntary or legally-required benefits. About NTT...  ...in enterprise-scale AI, cloud, security, connectivity... 
    Amazon Web Service
    Cloud
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT America

    Arlington, VA
    4 days ago
  • $93.37k - $153.4k

     ...Job Title: InfoSec Specialist - SOC Role Overview:...  ...complex, cross-functional security initiatives. We are...  ...security automation and cloud security across modern...  ...Frisco, TX. You will be required to be onsite on an as-needed...  ...and response (AWS, GCP and Azure) ~ Application... 
    Amazon Web Service
    Cloud
    Temporary work
    Relocation package
    Flexible hours
    Weekend work

    McAfee

    Reston, VA
    4 days ago
  • $81.6k - $142.8k

     ...Description At Amazon Web Services (AWS), Security is our highest priority. The AWS Security...  ...Independently assess and satisfy compliance requirements Develop reusable artifacts, propose...  ...in a wide variety of areas including cloud, devices, retail, entertainment,... 
    Amazon Web Service
    Cloud
    Flexible hours

    Amazon

    Herndon, VA
    7 days ago
  • $74.2k - $129.8k

     ...have a passion for analyzing requirements, partnering with legal,...  ...business? Amazon Web Services (AWS) Security is looking for an...  ...-oriented Security Industry Specialist to join the AWS Security Assurance...  ...variety of areas including cloud, devices, retail, entertainment... 
    Amazon Web Service
    Cloud
    Flexible hours

    Amazon

    Herndon, VA
    3 days ago
  • $86.8k - $198k

     ...ICAM Architect The Opportunity :...  ...perimeter is drawn, and securing identities is...  ...(IAM) specialist, you have the skills...  ...articulating access requirements and defining...  ...Knowledge of cloud identity platforms such as AWS Cognito, Azure AD B2C, KeyCLoak, or Google Cloud... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    5 days ago
  • $131.3k - $237.35k

     ...thrive, keep reading! TheIntel Security Sectordelivers technology-...  ...organizational and federal cybersecurity requirements. Are you ready for your next...  .... ~ Experience supporting cloud security monitoring and compliance within AWS, Azure, Oracle (OCI)or Google... 
    Amazon Web Service
    Cloud
    Local area
    Immediate start
    Flexible hours

    Leidos

    Reston, VA
    3 days ago
  • $86.8k - $198k

     ...The Opportunity Everyone knows security needs to be "baked in" to a...  ...accreditation of mobile and cloud-based security capabilities,...  ...with cloud environments such as AWS, Azure, M365, and SaaS...  ...may need to meet eligibility requirements for access to classified information... 
    Amazon Web Service
    Cloud
    Full time
    Part time
    Local area

    Phase2 Technology

    Lorton, VA
    5 days ago
  • $176.6k - $239k

     ...Amazon Web Services (AWS) Specialist Solutions Architects (SSAs) are technologists...  ...complex challenges that require expert-level knowledge to...  ...or designing entirely new cloud-based systems. Do you enjoy...  ...share recommendations around security, cost, performance,... 
    Amazon Web Service
    Cloud
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Amazon

    Arlington, VA
    6 hours ago
  •  ...Senior Technical Lead For ICAM We are seeking a Senior Technical Lead for ICAM...  ...customer in Tysons VA Responsibilities & Requirements: An AWS Solution Architect certification is mandatory...  ...IBM Products, Oracle Products, and Cloud Base Products. 7+ years of experience... 
    Amazon Web Service
    Cloud

    Navstar

    McLean, VA
    4 days ago
  • $86.8k - $198k

     ...: R0240633Cybersecurity Specialist**The Opportunity:**Everyone knows security needs to be “baked in” to...  ...of mobile and cloud-based security capabilities...  ...cloud environments such as AWS, Azure, M365, and SaaS applications...  ...to meet eligibility requirements for access to classified... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Remote work

    Booz Allen Hamilton

    Lorton, VA
    1 day ago
  •  ...mission-critical facilities, secure environments, complex...  ...a Deployment Network Specialist 4 to join our Security...  ...network. Experience with cloud provider environments such as AWS and Azure, with IL-2 or...  ...may meet eligibility requirements, including U.S. Citizenship... 
    Amazon Web Service
    Cloud
    Work experience placement
    Work at office
    Local area

    M.C. Dean, Inc.

    Springfield, VA
    3 days ago
  •  ...configuration, etc. Oracle database SQL Queries – to extract data from Oracle database Python scripting PREFERRED AWS Desired Kubernetes Docker Any cloud Certifications Python scripting DevOps - Terraform/Ansible/Jenkins/etc.... 
    Amazon Web Service
    Cloud

    Samprasoft

    McLean, VA
    6 hours ago
  •  ...candidate from working on the proposed assignment for the duration of the assignment period. Must Haves DPM, Unix, ETL, and AWS cloud (preferred) Nice To Have Experience with BigID tool, Kubernetes and dockers Hands-on experience upgrading within Linus environment... 
    Amazon Web Service
    Cloud

    Samprasoft

    McLean, VA
    5 days ago
  •  ...solutions in: ~National Security Programs ~Professional...  ...and Access Management (ICAM) Subject Matter Expert...  ...appropriate security requirements.Duties include the following...  ...meetings, works with CLOUD SME to ensure that...  ...OKTA, CyberArk, Azure/AWS, Active Directory, LDAP... 
    Amazon Web Service
    Cloud
    Full time
    For contractors
    Remote work

    gTANGIBLE Corporation

    Arlington, VA
    8 days ago
  •  ...Database Engineer Specialist Database Engineer Specialist responsibilities...  ..., performance tuning, security, auditing, metadata...  ...replacement of EC2 nodes in AWS. Includes Cloud Formation Template creation...  ...minimal supervision Basic Requirements: More than 7 years of... 
    Amazon Web Service
    Cloud

    Software Technology Inc

    McLean, VA
    4 days ago
  •  ...Senior Edge Connectivity Specialist At HDR, our...  ...firewalls, and public/private cloud integration. Design...  ...cloud integration, and secure interconnection...  ...security and governance requirements. Review and improve firewall...  ...Azure networking, AWS networking, ExpressRoute... 
    Amazon Web Service
    Cloud
    Permanent employment
    Work at office
    Monday to Friday
    Shift work

    HDR

    Vienna, VA
    2 days ago
  •  ...Job Title: Developer - Full Stack Specialist Location: McLean, VA...  ...for production deployment. Required Qualifications ~ Bachelor's or...  ...architecture. ~ Proven experience with cloud-native development, particularly AWS services. ~ Strong programming... 
    Amazon Web Service
    Cloud
    Contract work

    HonorVet Technologies

    McLean, VA
    3 days ago
  • $131.3k - $237.35k

     ...technical engineer for ICAM federation,...  ...across DoD enterprise, cloud, mission, and legacy...  ...owners, security teams, mission partners...  ...Microsoft Entra ID,Keycloak, ForgeRock, SailPoint...  ...integration. ​ ​ Required Qualifications ​Active...  ...integration, and AWS or comparable cloud... 
    Amazon Web Service
    Cloud
    Local area
    Immediate start

    Leidos

    Reston, VA
    2 days ago
  •  ...leaders, and operational analysts. The cloud security lead sme is a senior subject matter...  ...of war mission systems operating within aws govcloud, azure government, and approved...  ...to the dow cloud computing security requirements guide, zero trust architecture, and risk... 
    Amazon Web Service
    Cloud
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  • $131.3k - $237.35k

     ...technical lead for ICAM engineering, integration...  ...across enterprise, cloud, coalition, and...  .... The role requires hands-on engineering...  ...application owners, security teams, mission partners...  ...,HashiCorp, Corsha,Keycloak, Microsoft Entra ID...  ...environments including AWS, GovCloud, IL5/IL6,... 
    Amazon Web Service
    Cloud
    Local area
    Immediate start

    Leidos

    Reston, VA
    3 days ago
  •  ...Lead (Business Applications & AWS) Location: Must eventually...  ...familiarity with AWS and cloud migrations. An ideal candidate...  ...customers, and top management on requirements pertinent to the technical...  ...understanding of application security, mobile, databases, enterprise... 
    Amazon Web Service
    Cloud
    Contract work

    Samprasoft

    McLean, VA
    5 days ago
  •  ...seeking an experienced Infrastructure & Security Engineer to join our Platform team, which...  ...you will design, build, and scale secure cloud infrastructure that powers Antithesis'...  ...~ Deep experience with cloud providers (AWS, GCP, or Azure) ~ Strong knowledge of cloud... 
    Amazon Web Service
    Cloud
    Work at office

    Antithesis Operations LLC

    Vienna, VA
    3 days ago
  •  ...Apogee Global RMS is seeking a Cloud Security Architect / FedRAMP Advisor to support federal...  ...will serve as a trusted advisor across AWS, Azure, and hybrid environments,...  ...cloud platforms meet stringent federal requirements. What You Will Lead Architect secure... 
    Amazon Web Service
    Cloud

    Apogee Global RMS

    McLean, VA
    5 days ago
  •  ...transformation services across all security levels. • Directs...  ...Databricks, Apache Airflow, AWS Glue, Kafka, and federated data...  ...partners to synthesize operational requirements, define data product roadmaps...  ...multi-security-environment cloud platforms. • Strong ability... 
    Amazon Web Service
    Cloud
    Contract work

    ECS

    Fairfax, VA
    2 days ago
  •  ..., and Access Management (ICAM) implementation effort, as...  ...design, modeling, security, integration, and formal...  ...stakeholders to gather project requirements and develop complex solutions...  ...with supporting IAM in a Cloud environment, including Azure or AWS ⦁ Experience with... 
    Amazon Web Service
    Cloud
    Temporary work
    Relocation package
    Flexible hours

    ENS Solutions, LLC

    McLean, VA
    5 days ago
  • $86.8k - $198k

     ...Number: R0239948 ICAM Solutions Engineer...  ...perimeter is drawn, and securing identities is...  ...access requirements and defining enterprise...  ...with tools such as AWS IAM, Microsoft Entra...  ...Experience with Keycloak or Cognito Experience...  ...solutions within secure cloud and on-premises... 
    Amazon Web Service
    Cloud
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Mc Lean, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AWS Cloud Security and ICAM Specialist (Keycloak required). Be the first to apply!