ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Fort Meade, MD
Salary
$140,250–$189,750 / yr
Posted
7 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $173k
This role $165k
$117k most similar roles pay here $226k

This role pays more than 51% of similar roles. Most pay $145,099–$200,625 — the shaded band above. At the midpoint, this role pays about $165k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About General Dynamics

General Dynamics is a global aerospace and defense company offering a broad portfolio of products and services in business aviation, ship construction, land combat vehicles, and information technology. It serves customers in the U.S. government, allied governments, and a diverse array of commercial markets.

General Dynamics currently has 1123 open roles on FindRole.

Listed pay typically runs $124,093–$150,385 across 984 roles with salary data.

Most-posted roles

View all roles at General Dynamics

At a glance

TL;DR · ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services joins a team delivering enterprise-scale Identity, Credential, and Access Management capabilities. This role involves designing, integrating, operating, and maintaining identity provider services to provide secure authentication and federation for millions of users. The engineer will manage Microsoft Active Directory Federation Services infrastructure, configure federation trust relationships with internal and external partners, and implement solutions using SAML, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication. Daily tasks include managing Single Sign-On, Multi-Factor Authentication, and Conditional Access while developing policies, claims rules, and attribute mappings. The role requires expertise in Active Directory, LDAP, PKI, and PowerShell scripting within Windows or Linux environments. This position addresses the critical business problem of providing secure, resilient, and high-availability authentication services to support Zero Trust Architecture objectives for mission-critical workloads.

What you'll do

  • Manage and maintain Microsoft Active Directory Federation Services (ADFS) infrastructure for enterprise authentication.
  • Configure federation trust relationships with internal and external Identity Providers and Service Providers.
  • Implement and troubleshoot authentication protocols including SAML, OAuth 2.0, OpenID Connect, and WS-Federation.
  • Develop and maintain authentication policies, claims rules, attribute mappings, and token issuance configurations.
  • Support Single Sign-On (SSO), Multi-Factor Authentication (MFA), and phishing-resistant authentication mechanisms.
  • Resolve technical issues related to certificates, tokens, and federation trust at scale.
  • Create technical documentation including architecture diagrams, standard operating procedures, and integration guides.
  • Contribute to Zero Trust Architecture objectives through modern identity and federation capabilities.

What we're looking for

  • Must be a United States citizen.
  • Must possess an active Secret clearance (interim not allowed).
  • Must hold a DoW 8570/8140 IAT Level II certification, such as Security+ CE or higher.
  • Must have a Bachelor's degree in a related technical field or an equivalent combination of education, certifications, and experience.
  • Must have at least 3 years of experience supporting IAM, authentication, federation, or ICAM technologies.
  • Must have experience supporting or implementing Microsoft ADFS in enterprise environments.
  • Must possess knowledge of protocols including SAML, OAuth 2.0, OpenID Connect (OIDC), and WS-Federation.
  • US Citizenship.

More like this

Similar roles

Identity Provider Operations Engineer

Booz Allen Hamilton

McLean, VA +1 9 days ago $86,800$198,000
PingFederate Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Python Java JavaScript PowerShell Groovy RESTful APIs Active Directory LDAP SCIM Zero Trust MFA AWS Cognito Azure AD B2C Google Cloud Identity CI/CD

Identity Provider Operations Engineer

Booz Allen Hamilton

Riverdale, MD +3 14 days ago $86,800$198,000
PingFederate Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Python Java JavaScript PowerShell Groovy RESTful APIs Active Directory LDAP SCIM Zero Trust MFA AWS Cognito Azure AD B2C Google Cloud Identity CI/CD

Senior Authentication Services Engineer

3M

Maplewood, MN +1 53 days ago $145,676$178,049
Microsoft Entra ID Active Directory SAML OIDC OAuth 2.0 FIDO2 PowerShell Microsoft Graph API Zero Trust CyberArk AWS IAM SIEM
6+ yrs exp Hybrid