FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Identity, Credential, and Access Management (ICAM) with a focus on OAuth 2.0, OpenID Connect, and role-based access controls. Proficient in implementing security measures such as mutual TLS, audit logging, and API gateway authorization within a Zero Trust framework.
Highest-signal resume keywords
OAuth 2.0OpenID ConnectRBACABACKubernetes
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
JavaPythonGoIdentity FederationCertificate Lifecycle ManagementAudit LoggingAPI Gateway AuthorizationService Mesh ImplementationToken ValidationClaims Mapping
Tools & Technologies
KeycloakOktaPingMicrosoft Entra IDKongApigeeIstioLinkerd
Certifications & Qualifications
Security+ CECySA+DoD 8570 IAT Level II
Industry Keywords
Zero TrustNIST SP 800-53FIPS 140-3Public TrustFAASAFeAgile
Tech Stack
Tools & technologiesCyber SecurityJavaKubernetesPythonGo
About the role
Key responsibilities & impact- Implement the identity, credential, and access management layer governing user and service interactions with L-CAP
- Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect
- Implement and maintain identity federation and user stores, including role-based test account provisioning
- Implement per-session authentication and authorization for user-to-service and service-to-service requests
- Implement mutual TLS, service mesh/workload identity, and certificate lifecycle management
- Design and implement role-based and attribute-based access controls
- Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging
- Implement authentication and authorization audit logging, including event capture, storage, and retrieval
- Implement API gateway authorization and protect external-facing endpoints through the API management layer
- Produce ICAM control evidence and resolve identity integration issues across distributed services
- Leverage AI-assisted development and automation to improve quality and delivery within a SAFe/Agile framework
Requirements
What you’ll need- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience
- Additional experience, education and training may be considered in lieu of degree
- Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping
- Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent
- Experience implementing RBAC and/or ABAC within distributed applications
- Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity
- Understanding of Zero Trust principles, including per-session authorization and default-deny service communication
- Experience implementing audit logging for access and authorization events
- Proficiency in Java, Python, Go, or a comparable programming/scripting language
- Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls
- Experience with Kubernetes and containerized service deployments
- U.S. citizenship required
- Ability to obtain and maintain a favorable Public Trust investigation and successfully complete required government background investigations
- Must meet FAA facility and information system access requirements
- Continuous U.S. residency for at least 3 of the previous 5 years
- Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification preferred
- Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations preferred
- Experience with SAML 2.0 and SCIM provisioning preferred
- Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE) preferred
- Experience with service mesh implementation (Istio, Linkerd) preferred
- Experience with API gateway authorization policy (Kong, Apigee, or equivalent) preferred
- Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management preferred
- Knowledge of privileged access management practices preferred
- Experience in aviation, FAA, or other safety-critical environments preferred
- Experience with SAFe or large-scale Agile delivery preferred
Benefits
Comp & perks- Hybrid work arrangement: 3 days onsite and 2 days working from home for employees within commuting distance
- 100% remote work may be considered for employees outside commuting distance
- Mission-critical work supporting national infrastructure
- AI-assisted development and automation opportunities
