Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Leidos

ICAM Security Engineer

Leidos

. Implement the identity, credential, and access management layer governing user and service interactions with L-CAP .

Posted 9/21/2026full-timeUnited StatesMid-LevelSenior💰 $87,100 - $157,450 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Identity, Credential, and Access Management (ICAM) with a focus on OAuth 2.0, OpenID Connect, and role-based access controls. Proficient in implementing security measures such as mutual TLS, audit logging, and API gateway authorization within a Zero Trust framework.

Highest-signal resume keywords
OAuth 2.0OpenID ConnectRBACABACKubernetes

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
JavaPythonGoIdentity FederationCertificate Lifecycle ManagementAudit LoggingAPI Gateway AuthorizationService Mesh ImplementationToken ValidationClaims Mapping
Tools & Technologies
KeycloakOktaPingMicrosoft Entra IDKongApigeeIstioLinkerd
Certifications & Qualifications
Security+ CECySA+DoD 8570 IAT Level II
Industry Keywords
Zero TrustNIST SP 800-53FIPS 140-3Public TrustFAASAFeAgile

Tech Stack

Tools & technologies
Cyber SecurityJavaKubernetesPythonGo

About the role

Key responsibilities & impact
  • Implement the identity, credential, and access management layer governing user and service interactions with L-CAP
  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect
  • Implement and maintain identity federation and user stores, including role-based test account provisioning
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests
  • Implement mutual TLS, service mesh/workload identity, and certificate lifecycle management
  • Design and implement role-based and attribute-based access controls
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging
  • Implement authentication and authorization audit logging, including event capture, storage, and retrieval
  • Implement API gateway authorization and protect external-facing endpoints through the API management layer
  • Produce ICAM control evidence and resolve identity integration issues across distributed services
  • Leverage AI-assisted development and automation to improve quality and delivery within a SAFe/Agile framework

Requirements

What you’ll need
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience
  • Additional experience, education and training may be considered in lieu of degree
  • Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent
  • Experience implementing RBAC and/or ABAC within distributed applications
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity
  • Understanding of Zero Trust principles, including per-session authorization and default-deny service communication
  • Experience implementing audit logging for access and authorization events
  • Proficiency in Java, Python, Go, or a comparable programming/scripting language
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls
  • Experience with Kubernetes and containerized service deployments
  • U.S. citizenship required
  • Ability to obtain and maintain a favorable Public Trust investigation and successfully complete required government background investigations
  • Must meet FAA facility and information system access requirements
  • Continuous U.S. residency for at least 3 of the previous 5 years
  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification preferred
  • Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations preferred
  • Experience with SAML 2.0 and SCIM provisioning preferred
  • Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE) preferred
  • Experience with service mesh implementation (Istio, Linkerd) preferred
  • Experience with API gateway authorization policy (Kong, Apigee, or equivalent) preferred
  • Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management preferred
  • Knowledge of privileged access management practices preferred
  • Experience in aviation, FAA, or other safety-critical environments preferred
  • Experience with SAFe or large-scale Agile delivery preferred

Benefits

Comp & perks
  • Hybrid work arrangement: 3 days onsite and 2 days working from home for employees within commuting distance
  • 100% remote work may be considered for employees outside commuting distance
  • Mission-critical work supporting national infrastructure
  • AI-assisted development and automation opportunities