Skip to content

Open nowPosted 39 days ago

Senior ICAM Engineer, Remote, United States

Workable (global search)107,990 open roles

Where
United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior ICAM Engineer, Remote, United StatesWorkable (global search) · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 6 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 39 days ago

Workable (global search) median: 6 days open

The posting

Mount Airey Group (MAG), a wholly owned subsidiary of Technologist Inc., is seeking a Senior Identity, Credential and Access Management (ICAM) Engineer to join our team. This is a full-time telework opportunity offering a competitive salary coupled with a stellar benefits package effective your first day of employment.

The Senior ICAM Engineer is responsible for the engineering, implementation, automation, administration, and operational support of enterprise Identity, Credential, and Access Management (ICAM) services. This role designs and implements secure identity solutions supporting authentication, authorization, identity lifecycle management, and Zero Trust initiatives. The engineer develops automation using PowerShell and the Okta REST APIs to improve operational efficiency, reduce manual administration, and support enterprise identity operations across cloud and on-premises environments. The engineer will also evaluate and adopt emerging automation technologies, including Python, to enhance future automation capabilities.

Primary Responsibilities

  • Administer, configure, and maintain enterprise Okta Identity Cloud environments supporting workforce identity and access management.
  • Design, implement, and troubleshoot Single Sign-On (SSO) integrations using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
  • Configure and maintain authentication policies, adaptive Multi-Factor Authentication (MFA), phishing-resistant authentication, and application sign-on policies.
  • Develop and maintain user lifecycle automation, including provisioning, deprovisioning, profile mappings, attribute transformations, group rules, and application assignments.
  • Design, configure, and support inbound and outbound identity federation with internal and external Identity Providers (IdPs).
  • Develop and maintain custom user profile attributes, application profile mappings, and identity schemas to support business and partner requirements.
  • Integrate enterprise applications with Okta while ensuring compliance with organizational security policies and Federal ICAM standards.
  • Troubleshoot complex authentication, federation, provisioning, authorization, and identity synchronization issues across cloud and on-premises environments.
  • Develop and maintain PowerShell automation utilizing the Okta REST APIs to perform administrative functions, user lifecycle management, reporting, and large-scale user profile updates.
  • Design and execute automated batch processes for creating, modifying, and updating user identities while ensuring data integrity, consistency, and auditability.
  • Develop reusable automation scripts and tools that improve operational efficiency and reduce manual administrative effort.
  • Integrate enterprise systems using REST APIs to automate identity management workflows and improve data consistency across identity repositories.
  • Evaluate and develop future automation capabilities using Python to support API integrations, reporting, and enterprise automation initiatives.
  • Support Public Key Infrastructure (PKI), PIV/CAC authentication, certificate-based authentication, and smart card integrations.
  • Develop technical architecture documentation, implementation guides, standard operating procedures, workflow diagrams, and engineering documentation.
  • Participate in Zero Trust initiatives by implementing modern identity-centric security controls and authentication mechanisms.
  • Analyze identity-related security events and assist with audit, compliance, and forensic investigations.
  • Collaborate with cybersecurity, infrastructure, networking, and application teams to implement secure identity solutions.
  • Perform testing, change management, production deployments, and Tier III engineering support for enterprise identity services.
  • Research, evaluate, and recommend new identity technologies and automation solutions that improve security, reliability, and operational efficiency.

Technical Requirements:

  • Okta Identity Cloud
  • Microsoft Entra ID
  • Ping Identity
  • PowerShell
  • Okta REST APIs
  • REST APIs
  • JSON
  • Identity Lifecycle Management
  • SAML 2.0
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • Multi-Factor Authentication
  • Identity Federation
  • Active Directory
  • LDAP
  • PKI
  • PIV/CAC Authentication
  • Zero Trust Architecture
  • Technical Documentation
  • Enterprise Identity Troubleshooting

Expected Experience:

  • Experience implementing and supporting:
  • Single Sign-On (SAML 2.0, OAuth 2.0, OpenID Connect)
  • Multi-Factor Authentication (MFA)
  • Identity Federation
  • User Lifecycle Management
  • Active Directory and LDAP
  • REST API integrations
  • Experience developing automation using PowerShell.
  • Experience consuming and integrating REST APIs.
  • Experience working with JSON and API payloads.

Requirements

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent professional experience.
  • Minimum of 2 (two) years of daily hands-on experience administering and engineering solutions using Okta Identity Cloud, including application integrations, identity lifecycle management, automation, and REST API development.

OR

  • Minimum of 3 (three) years of hands-on experience administering an enterprise Identity and Access Management platform such as Microsoft Entra ID, Ping Identity, ForgeRock, or a comparable IAM solution.
  • Current SECRET level clearance.
  • Ability to travel to Washington, DC for important meetings.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, with employer match)
  • Paid Time Off (Vacation, Sick & Federal Holidays)
  • Short Term & Long Term Disability
  • Training & Development
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.