1 day ago
Arlington, VA, USASenior
Base Salary
$175k - $220k/yr
Responsibilities
- Deploy, configure, upgrade, enhance, and sustain SailPoint IdentityIQ solutions, including lifecycle workflows, certification campaigns, RBAC/ABAC, custom Java rules, and compliance reporting.
- Engineer and maintain PingFederate SSO and federation services using SAML 2.0, OAuth 2.0, OpenID Connect, and phishing-resistant MFA.
- Implement hybrid and multi-cloud identity architectures using Microsoft Entra ID, AWS IAM, and AWS IAM Identity Center across DoD IL5/IL6 environments.
- Administer Active Directory Domain Services and Active Directory Federation Services, including Kerberos, LDAP/S, federated trusts, schema integrity, and multi-forest environments.
- Deploy and support DoD/NSS PKI components, certificate authorities, hardware tokens, certificate validation services, and certificate lifecycle management.
- Implement Zero Trust identity controls and harden platforms against DISA STIGs, RMF, NIST SP 800-207, and MDA cybersecurity requirements.
- Develop provisioning scripts, SCIM and REST API integrations, and administrative automation using PowerShell, Bash, Python, or Java.
- Collaborate with contractors, systems engineers, network architects, DevSecOps teams, and Government stakeholders on integrations, testing, cutovers, and interoperability events.
- Produce engineering designs, interface documents, standard operating procedures, runbooks, test plans, risk analyses, and technical recommendations.
Requirements
- At least 12 years of general full-time work experience, potentially reduced with advanced education.
- At least six years of dedicated Identity, Credential, and Access Management or Identity, Credential, and Access Management experience.
- At least one year of technical leadership, mentoring, or engineering management experience.
- Direct experience supporting the IRES contract or previous technical experience supporting the Missile Defense Agency.
- Hands-on engineering experience with SailPoint IdentityIQ, PingFederate, Microsoft Directory Services, cloud identity management, and DoD/NSS PKI.
- Current DoW 8140/8570 IAT Level II or higher certification, such as Security+ CE, CySA+, CASP+ CE, or CISSP.
- Active DoW Secret clearance and ability to obtain Top Secret clearance, or an active Top Secret clearance.
- Preferred qualifications include a bachelor's degree or higher in Computer Science, Information Technology, or Cybersecurity.
- Preferred qualifications include SailPoint, Ping Identity, Microsoft SC-300, or AWS Certified Security – Specialty certifications.
- Preferred experience includes CyberArk, ServiceNow, MBSE, and Agile/SAFe methodologies in DoD/MDA environments.
Benefits
- Health, dental, and vision insurance.
- Paid time off and holidays.
- Retirement benefits including 401(k) matching.
- Educational reimbursement, parental leave, employee stock purchase plan, tax-saving options, disability and life insurance, and pet insurance.
- Onsite position with no remote or telework availability, locations in Colorado, Alabama, or Virginia, day shift, and up to 10% travel.
- No relocation assistance is available; the selected candidate may be employed by a teammate company.
About Amentum
Amentum provides engineering, operations and maintenance, logistics, and mission support services to U.S. federal agencies and allied governments, including defense and energy programs. Its business centers on large, long-term government contracts spanning defense, space, nuclear cleanup, and infrastructure, with program management and technical services at the core. Headquartered in Chantilly, Virginia, it was formed in 2020 from the spinoff of AECOM’s Management Services division.
