EngineerJobs.io
← Back to all jobs

Job Description

Leidos is seeking an ICAM Security Engineer to implement and integrate identity, credential, and access management for the Leidos Common Automation Platform (L-CAP). The position operates in a SAFe/Agile environment supporting government air traffic programs, with a focus on secure authorization, auditability, and certificate lifecycle controls.

Core Responsibilities

  • Implement the identity, credential, and access management (ICAM) layer that governs all user and service interactions with L-CAP.
  • Integrate L-CAP with government-provided ICAM services and enforce per-session authorization across distributed mission services.
  • Establish access control and audit foundations used by operational and support users.
  • Integrate L-CAP services with government ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping.
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation.
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
  • Implement authentication and authorization audit logging, including event capture, storage, and retrieval.
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
  • Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience. Additional experience, education, and training may be considered in lieu of degree.
  • Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.
  • Experience implementing RBAC and/or ABAC within distributed applications.
  • Working knowledge of PKI, certificate lifecycle management, mTLS, and/or service mesh identity.
  • Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.
  • Experience implementing audit logging for access and authorization events.
  • Proficiency in Java, Python, Go, or a comparable programming/scripting language.
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
  • Experience with Kubernetes and containerized service deployments.
  • U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.

Technologies

  • OAuth 2.0, OpenID Connect
  • Keycloak, Okta, Ping, Microsoft Entra ID
  • RBAC, ABAC
  • mutual TLS (mTLS), service mesh/workload identity, certificate lifecycle management, PKI
  • Java, Python, Go
  • Kubernetes, containerized service deployments
  • NIST SP 800-53 Access Control (AC), NIST SP 800-53 Audit and Accountability (AU)
  • API gateway authorization, API management layer

Preferred / Desired Qualifications

  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.
  • Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.
  • Experience with SAML 2.0 and SCIM provisioning.
  • Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).
  • Experience with service mesh implementation (Istio, Linkerd).
  • Experience with API gateway authorization policy (Kong, Apigee, or equivalent).
  • Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.
  • Knowledge of privileged access management practices.
  • Experience in aviation, FAA, or other safety-critical environments.
  • Experience with SAFe or large-scale Agile delivery.

Benefits

  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement
  • Competitive compensation

Compensation, Location, and Posting

  • Location: Eagan, MN (hybrid)
  • Pay Range: USD 87,100 - 157,450 per year
  • Original Posting: September 21, 2026

Similar Jobs