Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.
This is a hybrid position requiring 3 days onsite and 2 days working from home, i f you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.
In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.
What You’ll Do:
- Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect , including token issuance, validation, and claims mapping.
- Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
- Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
- Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management , including issuance, rotation, expiration monitoring, and revocation.
- Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
- Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
- Implement authentication and authorization audit logging , including event capture, storage, and retrieval.
- Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
- Support security authorization and continuous monitoring by producing ICAM control evidence , resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.
Core Technical Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology , or related field with 4+ years of relevant experience . (additional experience, education and training may be considered in lieu of degree)
- Hands-on experience with OAuth 2.0 and OpenID Connect , including token validation, introspection, and claims mapping.
- Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft En
ICAM Security Engineer in nj at Unknown Company
This position is listed as full time and able to be worked remotely.