Lead Identity and Access Management (ICAM) Engineer

leidos· 00100 LEIDOS, INC.
Apply Now ↗
📍 Rockville, MDFull time💰 USD 131K–237K

About this role

Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers. advanced enterprise-level identity solutions.


Candidate MUST:

Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance
 

Primary Responsibilities:

  • Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services.
  • Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms.
  • Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles.
  • Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations.
  • Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping Identity, CyberArk).
  • Provide technical leadership, mentoring, and peer review for IAM engineering staff.
  • Support incident response and forensic investigations involving identity-related events.
  • Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies.
  • Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap.
     

Required Qualifications:

  • Bachelor’s degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor’s degree. With a Master’s degree, 10 years of general experience is required.
  • 8+ years of progressive experience focusing on identity and access management.
  • 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture.
  • Hands-on experience with at least two of the following IAM platform categories:

  - IGA: Microsoft Identity Manager

  - PAM: CyberArk, Beyond Trust

  - SSO/Federation: Okta, Microsoft Entra ID, Ping Identity

  - Directory Services: Active Directory, Azure AD/Entra ID, LDAP

  • Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles).
  • Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM).
  • Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos.
  • Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM).
  • Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures.
  • Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA).
  • Strong experience with Entra B2B and B2C for external identity management.
  • Experience with Entra AD Connect, including custom synchronization rules.
  • Strong proficiency in PowerShell and Graph API for identity management automation.
  • Familiarity with Zero Trust architecture and identity-related security best practices.

Preferred Qualifications:

  • Relevant certifications, hold at least one or two of the following, aligned to seniority:
    • CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
    • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
    • CyberArk Defender/Sentry/Guardian
    • Okta Certified Professional/Consultant/Administrator
    • Ping Identity Certified Professional
    • CompTIA Security+
  • Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp).
  • Experience with Azure AD Verifiable Credentials and decentralized identity concepts.
  • Understanding of biometric authentication methods and their Azure AD integration.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

August 5, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Frequently Asked Questions

What is the salary for the Lead Identity and Access Management (ICAM) Engineer role at leidos?
The listed salary for this Lead Identity and Access Management (ICAM) Engineer position at leidos is USD 131K–237K. This is an Full time role.
Where is the Lead Identity and Access Management (ICAM) Engineer position at leidos located?
This Lead Identity and Access Management (ICAM) Engineer role at leidos is based in Rockville, MD. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Lead Identity and Access Management (ICAM) Engineer role at leidos full-time or part-time?
This is listed as a Full time position. It is posted as a Lead Identity and Access Management (ICAM) Engineer role in the 00100 LEIDOS, INC. department at leidos.
Which team or department does the Lead Identity and Access Management (ICAM) Engineer at leidos belong to?
This Lead Identity and Access Management (ICAM) Engineer position is part of the 00100 LEIDOS, INC. department at leidos. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Lead Identity and Access Management (ICAM) Engineer position at leidos?
Click the "Apply Now" button on this page. You will be redirected to leidos's official application portal hosted on workday where you can submit your application directly.
When was the Lead Identity and Access Management (ICAM) Engineer job at leidos posted?
This Lead Identity and Access Management (ICAM) Engineer position at leidos was posted on Aug 5, 2026. Apply as soon as possible — early applications are often reviewed first.
Lead Identity and Access Management (ICAM) Engineer
leidos · 💰 USD 131K–237K
Apply for this role ↗

You'll be redirected to leidos's official application page on Workday.