About this role
We are seeking a highly experienced and technically exceptional Identity Architect & Technical Lead (Engineer 4 / Analyst 4) to serve as a trusted technical advisor in a Systems Engineering and Technical Assistance (SETA) capacity directly supporting the Government Chief Technology Officer (CTO) and Next Generation Environment (NGE) leadership in the Missile Defense Agency.
Note, this position is in Colorado Springs, Colorado and 100% onsite.
About the Program: Join a mission-critical, high-visibility program to architect, build, and secure the Agency’s Next Generation Environment (NGE). This initiative establishes a secure, resilient, and flexible hybrid, multi-cloud ecosystem designed to support national security objectives for years to come.
Within the NGE, Identity, Credential, and Access Management (ICAM) serves as the foundational trust fabric and critical enforcement pillar of the Agency’s Zero Trust Architecture (ZTA). As the Identity Architect and Technical Lead for the NGE Identity Design Area, you will guide technical decisions, shape identity roadmaps, and oversee multi-vendor integration efforts across commercial cloud providers (AWS, Azure) and enterprise on-premises platforms.
Position Summary In this role, you will serve as the senior technical authority for all capabilities within the NGE Identity Design Area. You will ensure that identity components—spanning identity lifecycle management, federation, credentialing, privileged access, and fine-grained authorization—are engineered into a unified, interoperable, and accredited system. You will act as the key technical bridge between senior Government leadership requirements, mission partner needs, and the complex engineering deliverables produced by the integration contractor and vendor community.
Key Responsibilities
- Serve as the primary technical authority for the Identity Design Area on Architecture Review Boards (ARBs). Evaluate, validate, and adjudicate vendor-proposed ICAM designs against the NGE Master Architecture and DoD Zero Trust reference mandates.
- Lead the technical direction of the NGE Identity working group. Translate high-level operational concepts and security policies into concrete engineering specifications, interface control documents (ICDs), and baseline standards
- Architect end-to-end integration across enterprise identity services, including Identity Providers (IdP), Identity Governance and Administration (IGA), Privileged Access Management (PAM), and Public Key Infrastructure (PKI).
- Design dynamic, Attribute-Based Access Control (ABAC) and Policy Decision/Enforcement Point (PDP/PEP) frameworks to enable continuous risk-based authentication and authorization across hybrid multi-cloud enclaves.
- Advise the Government CTO and program leadership on complex identity challenges, vendor roadmap evaluations, and emerging federal standards (NIST SP 800-207, OMB M-22-09, DoD ZT Capability execution).
- Lead technical exchange meetings (TEMs) with integration contractors and software vendors (e.g., Microsoft, AWS, SailPoint, CyberArk, Ping, Broadcom). Act as the final technical escalation authority for resolving cross-stack identity integration deadlocks.
Required Qualifications
Experience & Education Education & Years of Experience: Bachelor of Science degree in Systems Engineering, Computer Science, Cybersecurity, Information Systems, or a related technical discipline with 12 years of progressive engineering and architectural experience (or Master's degree with 10 years of experience).
- Identity Architecture Track Record: Minimum of 6 years dedicated to architecting, deploying, or managing enterprise-scale ICAM, directory, or authentication solutions.
- Classified Environment Experience: Demonstrated hands-on experience designing, integrating, or accrediting identity solutions within classified DoD or Intelligence Community enclaves.
- Multi-Cloud ICAM Delivery: Demonstrated expertise engineering enterprise identity services across both AWS and Microsoft Azure.
Security Clearance & Compliance
- Clearance: Must possess an active Top Secret security clearance with current SCI eligibility (TS/SCI).
- DoD Compliance: Must meet DoD 8140 / 8570.01-M requirements for IAM Level III or IASAE Level II/III. An active (ISC)² CISSP certification is required.
Desired Qualifications (Highly Valued)
- Direct experience designing identity solutions according to JSIG PL-3/PL-4, CSfC Capability Packages, and the DoD Zero Trust Strategy (Target and Advanced levels).
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- AWS Certified Security - Specialty
- CyberArk Certified Delivery Engineer (CDE) or Sentry
- SailPoint Certified IdentityIQ Architect / Engineer
- Experience deploying and managing ICAM components via Terraform, Ansible, GitOps pipelines, and Helm/Kubernetes manifests.
The pay range for this position in Colorado is $130,000/year to $190,000/year; however, base pay offered may vary depending on established government contract ranges, job-related knowledge, skills, and experience, and other factors. MTSI also offers a full range of medical, financial, and other benefits, dependent on the position offered. Base pay information is based on market location. Applications will be accepted on an ongoing basis. This posting will be renewed periodically until the position is filled.
#LI-AT1