Unknown Company

ICAM Security Engineer

nj • Posted 2 days ago
Remote Full Time IT & Technology

Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.


This is a hybrid position requiring 3 days onsite and 2 days working from home, i f you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.


In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.


What You’ll Do:

  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect , including token issuance, validation, and claims mapping.
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management , including issuance, rotation, expiration monitoring, and revocation.
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
  • Implement authentication and authorization audit logging , including event capture, storage, and retrieval.
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
  • Support security authorization and continuous monitoring by producing ICAM control evidence , resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.

Core Technical Qualifications:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology , or related field with 4+ years of relevant experience . (additional experience, education and training may be considered in lieu of degree)
  • Hands-on experience with OAuth 2.0 and OpenID Connect , including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft En

#J-18808-Ljbffr

ICAM Security Engineer in nj at Unknown Company

This position is listed as full time and able to be worked remotely.

Back to Job Search