ICAM Security Engineer
Job Description
Leidos is seeking an ICAM Security Engineer to help build identity, credential, and access management for the Leidos Common Automation Platform (L-CAP). This hybrid role in Eagan, MN supports government air traffic programs in a SAFe/Agile environment, with an emphasis on integrating modern authentication and authorization capabilities, strong auditability, and certificate lifecycle controls.
On this team, you will implement an ICAM layer that governs how users and services securely interact with L-CAP. You will connect L-CAP to government-provided ICAM capabilities using industry-standard protocols, enforce per-session authorization, and deliver control evidence to support security authorization and continuous monitoring across distributed mission services.
Responsibilities
- Implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP.
- Integrate L-CAP with government-provided ICAM services and enforce per-session authorization across distributed mission services.
- Implement OAuth 2.0 and OpenID Connect integrations, including token issuance, token validation, and claims mapping.
- Build and maintain identity federation and user stores (for example, Keycloak or equivalent), including role-based test account provisioning.
- Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
- Deliver mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management including issuance, rotation, expiration monitoring, and revocation.
- Design and implement RBAC and ABAC access controls aligned to operational and support roles.
- Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
- Implement authentication and authorization audit logging, including event capture, storage, and retrieval.
- Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
- Support security authorization and continuous monitoring by resolving identity integration issues across distributed services and leveraging AI-assisted development and automation to improve quality and delivery.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience. Additional experience, education, and training may be considered in lieu of degree.
- Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.
- Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.
- Experience implementing RBAC and/or ABAC within distributed applications.
- Working knowledge of PKI, certificate lifecycle management, mTLS, and/or service mesh identity.
- Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.
- Experience implementing audit logging for access and authorization events.
- Proficiency in Java, Python, Go, or a comparable programming or scripting language.
- Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
- Experience with Kubernetes and containerized service deployments.
- U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
- Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.
Technologies
- OAuth 2.0, OpenID Connect
- Keycloak, Okta, Ping, Microsoft Entra ID
- RBAC, ABAC
- Mutual TLS (mTLS), service mesh/workload identity
- Certificate lifecycle management, PKI
- Java, Python, Go
- Kubernetes, containerized service deployments
- NIST SP 800-53 Access Control (AC), NIST SP 800-53 Audit and Accountability (AU)
- API gateway authorization, API management layer
Benefits
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement
- Competitive compensation
Pay Range: $87,100.00 - $157,450.00 per year
Original posting: September 21, 2026