Identity, Credential, & Access Management (ICAM) Engineer

Chantilly, Virginia
Closing date
Dec 13, 2023

View more

Job Details

Responsibilities & Qualifications

The Identity, Credential, and Access Management (ICAM) Engineer will be responsible for implementing access control modules and policies across multiple systems, applications, data stores and environments for an intelligence analyst modelling workbench on multiple customer security domains (unclassified, secret, top secret). While these systems and applications will be deployed to and reside primarily in the cloud (AWS, C2S), there will also be on-prem, remote and edge node deployments. Deployments will leverage the customer ICAM systems ad capabilities (GeoAXIS, e.g.) when required.

Deployments may constitute Mandatory Access Control (MAC), Role-Based Access Control (RBAC), Discretionary Access Control (DAC), Rule-Based Access Control (RBAC or RB-RBAC), and/or Policy-Based Access Control (PBAC), with an emphasis on RBAC/PBAC.

The ICAM Engineer will be responsible for:
  • RBAC and PBAC Implementation: Develop, deploy, and maintain RBAC and PBAC modules for access control, ensuring that users and entities have the appropriate permissions and privileges.
  • Access Control Policies: Collaborate with stakeholders to define and enforce access control policies based on RBAC and PBAC principles.
  • Identity Management: Design and manage the identity lifecycle, including provisioning, de-provisioning, and authentication processes.
  • Access Governance: Monitor and audit access permissions to ensure compliance with security policies, industry standards, and regulatory requirements.
  • Single Sign-On (SSO) Solutions: Integrate with existing (GeoAXIS, e.g.) and/or implement and maintain SSO solutions for streamlined user authentication and access management, if permitted.
  • Integration: Integrate ICAM solutions with various systems, applications, and services, ensuring seamless functionality.
  • Troubleshooting and Incident Response: Investigate and resolve access-related issues and participate in incident response activities as needed.
  • Documentation: Maintain detailed documentation of ICAM configurations, policies, and procedures.
  • Security Awareness: Stay current with emerging ICAM technologies and best practices in access management and security.
  • Collaboration: Work closely with cross-functional teams, including IT, security, compliance, and application development teams, on a Scaled Agile Framework (SAFe)-based program, to implement and maintain ICAM solutions effectively.
  • User Training: Provide training and support to end-users and administrators on ICAM tools and procedures.

    • Proficiency in ICAM technologies, including IAM, SSO, and access control solutions.
    • Strong knowledge of RBAC and PBAC principles and their practical implementation.
    • Experience with IAM tools such as Okta, Ping Identity, or Azure AD.
    • BA/BS with 5+ years'; MS with 3+ years'; PhD with 0+ years' experience
    • Familiarity with identity federation protocols (SAML, OAuth, OpenID Connect).
    • Scripting and programming skills (e.g., Python, PowerShell) for automation.
    • Security Awareness: Understanding of cybersecurity principles, threat landscape, and the ability to apply security best practices to ICAM solutions.
    • Experience in the intelligence community or DoD a plus
    • Experience with customer IdAM solutions (GeoAXIS, e.g.) is highly desirable
    • Active Top Secret/SCI government clearance


    We are seeking an Identity, Credential, and Access Management (ICAM) Engineer to join our team supporting our NGA customer on a new program in Reston, VA. This once-in-a- generation program will put a 21 st century analytic workbench in the hands of intelligence and GEOINT analysts.

    Successful applicants will help to facilitate widespread application of machine augmentation and automation and contribute to deployment of an intuitive user-focused set of services to capture, manage, and automate analytic mission and workflow expertise.

    ICAM is important as it will allow our customers and analyst end users to securely access resources across existing systems and our emerging platforms. With ICAM, agencies can ensure that the right person with the right privileges can access the right information at the right time.

    TekSynap, a "Fast 50" technology company in the Washington DC area that offers technology solutions to federal, state and local government agencies. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.

    Visit us at .

    Apply now to explore jobs with us!

    Additional Job Information

    • Establish Focus
    • Change Management
    • Oral Communication
    • Written Communication
    • Interpersonal Awareness
    • Build Relationships
    • Analytical Thinking
    • Technical Expertise
    • Initiative
    • Foster Innovation
    • Results Oriented
    • Teamwork
    • Customer Service


    The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
    • Location: Chantilly, VA
    • Type of environment: Office and Remote
    • Noise level: Medium
    • Work schedule: Schedule is day shift Monday - Friday, with the ability to flex (9/80 schedule, e.g.).
    • Amount of Travel: Less than 10%


    The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

    While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.


    Citizenship: U.S. Citizenship

    Clearance requirement: TS/SCI, eligible for CI Poly


    Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.


    In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.


    TekSynap understands both the pace of technology today and the need to have a comprehensive well planned information management environment. Technology moving at the speed of thought®embodies these principles – the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.

    The TekSynap founders have worked together for over a decade, supporting customers ranging from small departmental operations & maintenance efforts to leading broad nationwide deployment efforts for agencies such as the U.S. Department of Veterans Affairs. This core management team has operated in leading companies such as SIGNAL Corporation and managed business sectors of over 100M in annual revenue in industry leading companies such as General Dynamics.

    At each level this team has absorbed what “works” – for the company, our customers and our employees. We synthesize the best at each level resulting in a unique service provider that combines the infrastructure and process models of larger organizations with an agile ability to cost effectively meet our customer’s requirements.

    Get job alerts

    Create a job alert and receive personalized job recommendations straight to your inbox.

    Create alert