ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
Falls Church, VA
Salary
$170,000–$230,000 / yr
Posted
35 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $173k
This role $200k
$116k most similar roles pay here $242k

This role pays more than 75% of similar roles. Most pay $145,000–$200,625 — the shaded band above. At the midpoint, this role pays about $200k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About General Dynamics

General Dynamics is a global aerospace and defense company offering a broad portfolio of products and services in business aviation, ship construction, land combat vehicles, and information technology. It serves customers in the U.S. government, allied governments, and a diverse array of commercial markets.

General Dynamics currently has 1123 open roles on FindRole.

Listed pay typically runs $124,093–$150,385 across 984 roles with salary data.

Most-posted roles

View all roles at General Dynamics

At a glance

TL;DR · ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services serves on a team providing enterprise-scale Identity, Credential, and Access Management capabilities for the Department of Defense. This role involves designing, developing, and maintaining identity provider services to provide secure authentication and federation for over four million identities. The engineer will build and manage Microsoft Active Directory Federation Services infrastructure, configure federation trust relationships, and develop authentication policies including claims rules and attribute mappings. Day-to-day tasks include troubleshooting complex certificate and token issues while supporting Single Sign-On, Multi-Factor Authentication, and Zero Trust Architecture. Key technologies include Active Directory Domain Services, Microsoft Azure, SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and JWT. The role addresses the critical challenge of providing highly available, resilient authentication services for mission-critical applications within a large-scale government environment.

What you'll do

  • Design, develop, and maintain enterprise Identity Provider (IdP) services for over 4 million identities.
  • Engineer and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure for authentication and federation.
  • Manage federation trust relationships with internal and external identity providers and service providers.
  • Implement authentication solutions using SAML 2.0, OAuth 2.0, OpenID Connect, and certificate-based protocols.
  • Develop authentication policies, claims rules, attribute mappings, and authorization workflows.
  • Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), and phishing-resistant capabilities.
  • Resolve complex issues related to certificates, tokens, identity assertions, and federation trust.
  • Create technical documentation including architecture diagrams, integration guides, and standard operating procedures.

What we're looking for

  • Must be a U.S. citizen.
  • Must possess an active Secret clearance (interim clearances are not accepted).
  • Must hold a DoD 8570/8140 IAT Level II certification, such as Security+ CE or higher.
  • Must have a Bachelor's degree in a related technical discipline or equivalent experience and training.
  • Must have at least 8 years of experience supporting IAM, authentication, federation, or ICAM solutions in government or regulated environments.
  • Must have extensive experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS) and enterprise Identity Provider services.
  • Must be proficient in SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies.
  • Experience with advanced identity features like MFA, PKI, certificate-based authentication, and Zero Trust Architecture is preferred.

More like this

Similar roles

Identity Provider Operations Engineer

Booz Allen Hamilton

McLean, VA +1 9 days ago $86,800$198,000
PingFederate Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Python Java JavaScript PowerShell Groovy RESTful APIs Active Directory LDAP SCIM Zero Trust MFA AWS Cognito Azure AD B2C Google Cloud Identity CI/CD

Identity Provider Operations Engineer

Booz Allen Hamilton

Riverdale, MD +3 14 days ago $86,800$198,000
PingFederate Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Python Java JavaScript PowerShell Groovy RESTful APIs Active Directory LDAP SCIM Zero Trust MFA AWS Cognito Azure AD B2C Google Cloud Identity CI/CD

Senior Authentication Services Engineer

3M

Maplewood, MN +1 53 days ago $145,676$178,049
Microsoft Entra ID Active Directory SAML OIDC OAuth 2.0 FIDO2 PowerShell Microsoft Graph API Zero Trust CyberArk AWS IAM SIEM
6+ yrs exp Hybrid