Description
You will design, implement, and maintain identity, PKI, and secrets management systems in classified and high-assurance environments.
This role is hybrid.
Responsibilities
- Engineer secure authentication and authorization patterns using OIDC, OAuth 2.0, SAML, LDAP/LDAPS, Kerberos, mTLS, RBAC, and ABAC.
- Design and modernize identity platforms including Entra ID, Keycloak, Active Directory, and certificate authorities.
- Manage the full certificate lifecycle, including issuance, renewal, rotation, revocation, trust store management, and service identity dependencies.
- Implement Zero Trust-aligned access controls, least privilege principles, and secure service-to-service communication.
- Support RMF, ATO, STIG, and cybersecurity compliance activities for identity services, producing detailed technical documentation and diagrams.
Required Skills
- 5+ years of senior-level experience implementing enterprise identity, PKI, SSO, or secrets management capabilities.
- Hands-on expertise with Entra ID, Keycloak, Active Directory, LDAP/LDAPS, OIDC, OAuth 2.0, SAML, and PKI.
- Strong practical knowledge of certificate lifecycle management, trust chains, mTLS, token-based authentication, and secrets rotation.
- Experience supporting classified, TS/SCI, multi-enclave, internet-connected, or air-gapped environments.
- Ability to coordinate technical dependencies across cybersecurity, application, platform, network, and operations teams.
- Proven ability to produce clear technical documentation, implementation guides, test procedures, and operational support materials.
- Bachelor's degree in a related field.
Preferred Skills
- Experience with secrets platforms such as HashiCorp Vault, Azure Key Vault, CyberArk, or Kubernetes secrets.
- Familiarity with Aqua Security or container/cloud-native security tooling for certificate and workload identity integrations.
- Experience with HSMs, private CAs, offline roots, cross-certification, or high-assurance PKI operations.