View all jobs

Top Secret - Senior ICAM Engineer - Technician LEVEL 4

  • Chantilly, VA
  • Information Technology

Bailey Information Technology, LLC

Position: Senior ICAM Engineer - Technician Level 4
(PDP, PEP/PIP, EMS & RPMS Modernization)

Location: Chantilly, VA

Clearance: TS, SCI/Poly eligible

Certifications: Ability to obtain Security+ within 90 days of hire.

Job Description:
GEOAxIS is currently modernizing legacy ICAM components including Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS) using on-prem and cloud-native patterns, modern vendor open-source technologies, improved deployment automation, and microservices-based designs.

The Senior ICAM Engineer (Technician Level 4) plays a critical role in implementing the Architect’s designs and fulfilling the Technical Lead’s engineering direction. This position will design, develop, integrate, test, and troubleshoot modernized ICAM capabilities, serving as a senior hands-on contributor across multiple modernization workstreams. This position is a short‑term assignment with an expected duration of 7 months.

Responsibilities:

  • Implement ICAM modernization designs for PEP/PIP/EMS and RPMS components, ensuring alignment with architectural patterns and modernization goals. Transition from the legacy PDP to JBlocks.
  • Develop and integrate microservices supporting identity, attributes, authorization, resource registration, and policy distribution.
  • Work closely with the Architect to translate high-level designs into detailed engineering tasks, technical artifacts, and system interfaces.
  • Support the Technical Lead by providing technical input during Program Increment (PI) planning, backlog refinement, work estimation, and risk identification.
  • Develop new PEP/PIP patterns including enforcement endpoints, policy decision integrations, and attribute retrieval mechanisms.
  • Enhance EMS and RPMS services by implementing automation for resource/role lifecycle management, attribute orchestration, and policy ingestion workflows.
  • Collaborate closely with Development and Operations (DevOps) engineers on Continuous Integration and Continuous Delivery (CI/CD), containerization, infrastructure automation, and deployment to Kubernetes or the governments currently installed application platform.
  • Troubleshoot complex identity, authentication, authorization, and policy-related issues across legacy and modernized components.
  • Contribute to engineering documentation including design specifications, data flow diagrams, configuration standards, and interface definitions.
  • Ensure modernization activities reduce operational overhead and improve system reliability, maintainability, and observability.
  • Participate in integration testing, operational readiness testing, and deployment validation across multiple environments and security domains.
  • Mentor junior engineers and promote best practices in secure coding, microservices development, and ICAM integration.

Requirements/Qualifications:

  • Bachelor’s degree in a Science, Technology, Engineering, and Mathematics (STEM) field and 8+ years of relevant experience, or equivalent experience.
  • Hands-on experience developing or integrating systems related to identity, authentication, authorization, or enterprise security.
  • Experience implementing distributed systems or microservices architectures on modern platforms.
  • Experience supporting Agile teams and contributing to iterative delivery of new capabilities.
  • Ability to interpret architectural guidance and convert designs into high‑quality, maintainable engineering solutions.
  • Ability to obtain Security+ within 90 days of hire.

Preferred Qualifications:

  • Experience with Kubernetes or OpenShift for deployment and container orchestration.
  • Programming experience with Java and/or Python.
  • Familiarity with GitOps tools.
  • Experience with Amazon Web Services (AWS), Linux, or containerization technologies.
  • Knowledge of identity and access standards: X.509, SAML, OAuth2, OIDC, LDAP.
  • Experience with Oracle products or similar ICAM vendor technologies.
  • Experience implementing ABAC/RBAC models, policy-based access controls, and ZT aligned authorization patterns.
  • Experience supporting Intelligence Community (IC) or Department of War (DoW) systems, particularly authorization and identity-centric services.

Clearance Requirements*
Requires an active Top Secret security clearance upon hire and must meet SCI eligibility. Must be willing and able to obtain a polygraph within the customer’s timeline after hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.