About this role
Position Title: Senior IdAM Engineer
Location: Schriever Space Force Base, Colorado Springs, CO, Redstone Arsenal, Huntsville, AL or Fort Belvoir, VA
Relocation Assistance: None available at this time
Remote/Telework: NO - Not available for this position
Clearance Type: DoW Secret
Shift: Day shift
Travel Required: Up to 10% of the time
Description of Duties:
As a Senior IdAM Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, deploying, automating, securing, and sustaining the Identity, Credential, and Access Management (IdAM / ICAM) ecosystem underpinning the Missile Defense Agency’s (MDA) unified digital environment.
In this role, you will help advance NGE’s hybrid and multi-cloud identity modernization strategy by implementing robust Identity Governance and Administration (IGA) workflows, federation and Single Sign-On (SSO) services, enterprise directory integrations, and DoD/NSS Public Key Infrastructure (PKI) aligned with the Zero Trust Security Model. You will work across engineering, cybersecurity, hybrid cloud, infrastructure, contract consortium performers, and Government stakeholder teams to deliver resilient identity services across on-premises and cloud-hosted mission environments.
You will play a key role in standardizing identity lifecycle automation, enhancing authentication security, eliminating credential risks, strengthening access controls, and ensuring continuous compliance with DoD, DISA, and MDA security requirements.
Description of Duties
Identity Governance & Administration (IGA):
· Implement, deploy, configure, and sustain SailPoint IdentityIQ (IIQ) solutions, including Operations & Maintenance (O&M), platform upgrades, capability enhancements, and enterprise application onboarding.
· Design and customize identity lifecycle management workflows (joiner, mover, leaver), certification campaigns, role-based/attribute-based access controls (RBAC/ABAC), custom Java rules, and compliance reporting.
Federation & Single Sign-On (SSO):
· Engineer, deploy, and maintain PingIdentity PingFederate services to enable secure, federated Single Sign-On (SSO) across enterprise and mission partner applications.
· Lead application onboarding and integration utilizing modern authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and phishing-resistant Multi-Factor Authentication (MFA).
Hybrid Cloud Identity Integration:
· Implement and sustain secure identity and access architectures across hybrid multi-cloud environments, including Microsoft Entra ID (Azure AD) and Amazon Web Services (AWS IAM and AWS IAM Identity Center) operating within DoD IL5/IL6 boundaries.
· Ensure secure synchronization, conditional access policy enforcement, and seamless identity interoperability between on-premises domains and cloud service providers.
Directory Services & Authentication:
· Configure, optimize, and administer Microsoft Directory Services, including Active Directory Domain Services (AD DS) and Active Directory Federation Services (AD FS), maintaining high availability and schema integrity.
· Maintain Kerberos, LDAP/S, and federated trust configurations across complex multi-forest and segmented enterprise environments.
DoD & NSS Public Key Infrastructure (PKI):
· Deploy, maintain, and support DoD and National Security Systems (NSS) Public Key Infrastructure (PKI) components, including Certificate Authorities (CAs), hardware tokens (CAC/PIV/SIPR tokens), Certificate Validation services (OCSP/CRL), and certificate lifecycle management.
· Ensure cryptographic enforcement and certificate-based authentication across all network boundaries, endpoints, and server infrastructure.
Zero Trust Architecture & Security Compliance:
· Implement dynamic, identity-centric security policies and controls supporting the DoD Zero Trust Strategy and NIST SP 800-207.
· Harden identity platforms and services in accordance with DISA STIGs, Risk Management Framework (RMF), and MDA cybersecurity requirements to support continuous Authorization to Operate (cATO).
Consortium & Cross-Functional Engineering Collaboration:
· Collaborate with multi-contractor consortium performers, systems engineers, network architects, DevSecOps teams, and Government personnel to standardize identity interfaces and integration protocols.
· Serve as an identity integration focal point during Joint Interoperability Test events, cross-domain coordination, and enterprise cutovers.
Automation & Scripting:
· Develop and maintain automated provisioning scripts, API integrations (SCIM, REST), and administrative routines utilizing PowerShell, Bash, Python, or Java to streamline identity operations and eliminate manual configuration drift.
Documentation & Engineering Governance:
· Author and maintain comprehensive engineering deliverables, including Low-Level Designs (LLDs), Interface Control Documents (ICDs), standard operating procedures (SOPs), deployment runbooks, and test/validation plans.
Technology Evaluation & Continuous Improvement:
· Research and assess emerging IdAM/ICAM technologies, cloud identity features, and PAM/IGA enhancements to optimize security posture, scalability, and user experience across NGE.
Stakeholder Reporting & Technical Communication:
· Provide technical status, risk analysis, and engineering recommendations to program leadership and Government stakeholders.
· Translate complex identity, PKI, and federation requirements into actionable engineering plans and mission outcomes.
Resumes, in month and year format, must be submitted with application in order to be considered for the position. The selected candidate may be assigned as an employee for one of our teammate companies.
Basic Requirements:
· Must have 12 , or more, years of general (full-time) work experience
o May be reduced with completion of advanced education
· Must have 6, or more, years of dedicated Identity, Credential, and Access Management (IdAM / ICAM) experience.
· Must have 1, or more, years of experience in technical leadership, mentoring, or engineering management roles.
· Must have direct experience supporting the IRES contract or previous technical experience supporting the Missile Defense Agency (MDA).
· Must have demonstrated, hands-on, engineering proficiency across enterprise identity solutions, specifically:
· Must have a combination of experience, or familiarity, with the following:
o SailPoint IdentityIQ (IIQ) (deployments, lifecycle workflows, rules, and connectors).
o PingIdentity PingFederate (SAML, OAuth2, OIDC, MFA federation).
o Microsoft Directory Services (AD DS, AD FS).
o Cloud Identity Management (Microsoft Entra ID, AWS IAM).
o DoD / NSS Public Key Infrastructure (PKI) (Certificate Authorities, validation, and token integration).
· Must hold a current DoW 8140/8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+ CE, CISSP).
· Must have an active DoW Secret security clearance with the ability to obtain a Top Secret clearance (or active Top Secret).
· Must have an active DoW Secret Security Clearance
Desired Requirements:
· Have an active DoW Top Secret clearance.
· Have a Bachelor’s degree, or higher, in Computer Science, Information Technology, or Cybersecurity.
· Professional certifications in core tools:
o SailPoint Certified IdentityIQ Engineer / Architect
o Ping Identity Certified Professional
o Microsoft Certified: Identity and Access Administrator Associate (SC-300)
o AWS Certified Security – Specialty
· Have experience integrating identity solutions with Privileged Access Management (PAM) platforms (e.g., CyberArk) and enterprise ITSM systems (e.g., ServiceNow).
· Have experience with Model-Based Systems Engineering (MBSE) concepts and Agile/SAFe methodologies within DoD/MDA environments.
This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.
Compensation Details:
$175,000 – $220,000
The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.
Benefits Overview:
Our health and welfare benefits are designed to support you and your priorities. Offerings include:
- Health, dental, and vision insurance
- Paid time off and holidays
- Retirement benefits (including 401(k) matching)
- Educational reimbursement
- Parental leave
- Employee stock purchase plan
- Tax-saving options
- Disability and life insurance
- Pet insurance
Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.
Original Posting:
09/28/2026 - 10/02/2026
Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.
Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters .