General Dynamics Information Technology Logo

General Dynamics Information Technology

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

Posted 5 Hours Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
140K-190K Annually
Mid level
In-Office or Remote
Hiring Remotely in United States
140K-190K Annually
Mid level
Support design, integration, operation, and sustainment of enterprise Identity Provider services for DoD-scale authentication. Administer ADFS, configure federation trusts, implement SAML/OAuth/OIDC/WS-Fed and certificate-based solutions, support SSO/MFA/conditional access, troubleshoot tokens/certificates, onboard applications, document designs, and contribute to Zero Trust and identity modernization efforts.
The summary above was generated by AI

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Authentication Protocols, Secure Authentication, Single Sign-On (SSO)

Certifications:

None

Experience:

3 + years of related experience

US Citizenship Required:

Yes

Job Description:

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

GDIT has an opportunity for an Identity Provider (IdP) Engineer supporting a large line of business delivering enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by helping design, integrate, operate, and maintain enterprise Identity Provider services that provide secure authentication and federation for more than 4 million DoD enterprise identities.

This is a fully remote position.

MEANINGFUL WORK AND PERSONAL IMPACT
The ideal candidate has at least 3 years of hands-on experience supporting authentication or identity systems and is eager to grow deeper into enterprise ICAM technologies. Strong foundational skills in Microsoft Active Directory Federation Services (ADFS), authentication protocols, and troubleshooting are essential. This role provides opportunities to work with senior engineers, contribute to mission-critical authentication services, and expand your technical skillset across large-scale identity platforms.

Key Responsibilities

  • Support the design, configuration, and sustainment of enterprise Identity Provider (IdP) services used by millions of DoD users.
  • Assist in administering and maintaining Microsoft Active Directory Federation Services (ADFS) infrastructure supporting authentication and federation.
  • Help configure federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.
  • Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
  • Collaborate in onboarding and integrating applications into the authentication and federation ecosystem.
  • Help develop and maintain authentication policies, claims rules, attribute mappings, and token issuance configurations.
  • Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication mechanisms.
  • Work with cybersecurity, Active Directory, cloud, infrastructure, and application teams to deliver secure authentication services.
  • Contribute to Zero Trust Architecture objectives through modern authentication and federation capabilities.
  • Assist in monitoring, troubleshooting, and resolving authentication, federation, trust, certificate, and token issues.
  • Support the development of resilient, highly available authentication services for mission-critical workloads.
  • Help create technical documentation including architecture diagrams, SOPs, integration guides, and operational procedures.
  • Participate in Agile development activities and continuous improvement efforts.
  • Identify technical risks and contribute to identity modernization initiatives.

Basic Qualifications

  • Active Secret Clearance (Interim Secret not allowed).
  • Bachelor’s degree in a related technical field, or equivalent combination of education, certifications, and experience.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher).

Required Skills & Knowledge

  • Minimum 3 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM-related technologies.
  • Experience supporting or implementing Microsoft ADFS in enterprise environments.
  • Strong understanding of authentication, authorization, and federation concepts.
  • Familiarity with SAML, OAuth, OIDC, WS-Federation, and related identity technologies.
  • Experience with PKI, certificate-based authentication, smart cards, or MFA.
  • Experience supporting application or API integrations with identity/federation platforms.
  • Familiarity with Active Directory, LDAP, and enterprise identity repositories.
  • Ability to configure or support claims rules, attribute mappings, or token policies.
  • Experience working with Windows or Linux server environments.
  • Ability to document technical findings and communicate effectively.
  • Self-starter with a desire to learn and grow in enterprise identity operations.

Desired Skills & Knowledge

  • Experience with ADFS farms, Web Application Proxy (WAP), load balancers, or disaster recovery setups.
  • Exposure to modern identity platforms such as Microsoft Entra ID, PingFederate, PingAccess, Okta, or Keycloak.
  • Familiarity with DoD ICAM or federation initiatives.
  • Understanding of NIST 800-63 Identity Assurance models.
  • Exposure to phishing-resistant authentication or passwordless technologies.
  • Experience supporting Zero Trust concepts.
  • Basic PowerShell scripting for ADFS or identity operations.
  • Experience with monitoring, performance tuning, or troubleshooting authentication issues at scale.
  • Familiarity with PKI/certificate services, CAC authentication, or DoD credentialing.
  • Awareness of container technologies (Docker, Kubernetes).

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Flexibility: Full-flex work week to own your priorities at work and at home
● Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

The likely salary range for this position is $140,250 - $189,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Remote

Work Location:

USA VA Falls Church

Additional Work Locations:

Any Location / Remote

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 



Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Similar Jobs

5 Hours Ago
In-Office or Remote
United States
255K-345K Annually
Expert/Leader
255K-345K Annually
Expert/Leader
Aerospace • Information Technology • Professional Services • Security • Software
Lead enterprise-scale IdP architecture and engineering for DoD-scale authentication and federation. Define standards, implement ADFS/modern IdP platforms, design federation/trust models, oversee MFA/PKI/passwordless solutions, mentor teams, and drive Zero Trust identity modernization for millions of users.
Top Skills: Active DirectoryActive Directory Certificate Services (Ad Cs)AdfsCacConditional AccessDockerJwtKeycloakKubernetesLdapLinuxMfaAzureMicrosoft CloudMicrosoft Entra Id (Azure Ad)OauthOktaOpenid Connect (Oidc)Passwordless AuthenticationPingaccessPingdirectoryPingfederatePkiPowershellSAMLSmart Card AuthenticationWeb Application Proxy (Wap)WindowsWs-FederationZero Trust
170K-230K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
Design, deploy, and maintain enterprise Identity Provider (IdP) and ADFS services for DoD-scale authentication. Implement and troubleshoot SAML/OAuth/OIDC federation, MFA, PKI/CAC authentication, claims/policy mappings, SSO, and high-availability architectures. Integrate applications, manage federation trusts, produce documentation, and collaborate with cybersecurity, AD, cloud, and application teams to support Zero Trust and identity modernization.
Top Skills: Active DirectoryActive Directory Certificate Services (Ad Cs)Active Directory Domain Services (Ad Ds)Active Directory Federation Services (Adfs)CacCertificate-Based AuthenticationDockerJwtKeycloakKubernetesLdapLinuxAzureMicrosoft Entra Id (Azure Ad)Multi-Factor Authentication (Mfa)Oauth 2.0OktaOpenid Connect (Oidc)PingaccessPingdirectoryPingfederatePkiPowershellSaml 2.0Web Application Proxy (Wap)Windows ServerWs-Federation
170K-230K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
Senior hands-on identity engineer responsible for designing, deploying, and maintaining enterprise Identity Provider (IdP) services and ADFS infrastructure for millions of users. Duties include configuring federation trusts, implementing SAML/OAuth/OIDC/WS-Fed, PKI/smart card/MFA integrations, onboarding applications, developing claims and token policies, ensuring high availability and zero trust alignment, troubleshooting complex authentication issues, and producing technical documentation while collaborating with cybersecurity, AD, cloud, and application teams.
Top Skills: Active DirectoryActive Directory Certificate Services (Ad Cs)Active Directory Domain Services (Ad Ds)Active Directory Federation Services (Adfs)CacCertificate-Based AuthenticationCots ProductsDockerJwtKeycloakKubernetesLdapLinuxMfaAzureMicrosoft Entra Id (Azure Ad)Oauth 2.0OktaOpenid Connect (Oidc)PingaccessPingdirectoryPingfederatePkiPowershellSaml 2.0Smart Card AuthenticationWindows ServerWs-Federation

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account