AWS Cloud Security and ICAM Specialist

<p style="text-align:left"><b><u>Type of Requisition:</u></b></p>Regular<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Clearance Level Must Currently Possess:</b></u></p>None<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><span><span><span><span><span><b>Clearance Level Must Be Able to Obtain:</b></span></span></span></span></span></u></p>None<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><u>Public Trust/Other Required:</u></b></p>BI Full 6C (T4)<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Job Family:</b></u></p>IT Infrastructure and Operations<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><u>Job Qualifications:</u></b></p><p style="text-align:left"><b>Skills:</b></p>Access Management, Identity Governance, Secure Authentication<p style="text-align:left"><b>Certifications:</b></p>None<p style="text-align:left"><b>Experience:</b></p>10 + years of related experience<p style="text-align:left"><b>US Citizenship Required:</b></p>No<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Job Description:</b></u></p><p>The <b>AWS Cloud Security and ICAM Specialist</b> supports the <b>Case Management Modernization (CMM) Program</b> for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with <b>federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA)</b> principles within an <b>AWS</b> environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.</p><h1></h1><h1><b>Key Responsibilities:</b></h1><ul><li>Design and maintain the <b>ICAM architecture</b> for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM</li><li>Implement <b>federated identity and single sign-on (SSO)</b> solutions using modern protocols (SAML, OAuth2.0, OIDC)</li><li>Collaborate with Cloud and Security Architects to enforce <b>Zero Trust Architecture (ZTA)</b> across microservices and APIs</li><li>Configure and maintain <b>directory services and identity providers</b> (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak)</li><li>Deep experience integrating KeyCloak as a <b>broker IdP</b> federating upstream enterprise IdPs while issuing downstream OIDC token to application</li><li>Design <b>ICAM brokerage solutions and support compliance assessments</b>, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls</li><li>Develop and document <b>identity lifecycle management processes</b>—provisioning, deprovisioning, and access reviews</li><li>Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system</li><li>Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak</li><li>Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance</li><li>Provide subject matter expertise in <b>identity federation, PKI, certificate management</b>, and secure API authorization</li><li>Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs</li><li>Design and implement storage level, microservice level Authentication and Authorization</li><li>Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams</li><li>Participate in design sessions and work closely with the security lead</li><li>Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Infrastructure-as-Code</span> (IaC) templates</li><li>Direct and lead Pen testing, Review architecture diagrams produced by different teams</li><li>Independently lead design and implement of vulnerability management</li><li>Heavily participate in ATO activity</li><li>Lead and direct engineering team</li></ul><div></div><h1><b>Deliverable Alignment & Performance Outcomes:</b></h1><ul><li><b>Architecture Diagrams:</b> Depicting identity flow, federation, and integration points with AWS and CMM systems</li><li><b>Access Control Documentation:</b> Policies, RBAC models, and credential management workflows</li><li><b>Compliance Verification Reports:</b> Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards</li><li><b>Zero Trust Implementation Artifacts:</b> Documentation and verification of ZTA enforcement within system components</li><li><b>Performance Outcomes:</b><ul><li>100% of CMM applications integrated with SSO and MFA.</li><li>Zero unauthorized access incidents attributable to configuration error</li><li>100% compliance with NIST and FedRAMP ICAM control requirements</li><li>Reduced account provisioning time by ≥30% through automation</li></ul></li></ul><p></p><p><b>Tools & Technologies:</b></p><ul><li><b>IAM & Federation: </b>AWS Cognito, Azure AD, Okta, PingFederate</li><li><b>Access & Compliance: </b>SailPoint, CyberArk, HashiCorp Vault</li><li><b>Cloud: </b>AWS IAM, KMS, CloudTrail, Lambda</li><li><b>Protocols:</b> SAML, OAuth2.0, OIDC, SCIM</li><li><b>Monitoring & Audit: </b>ELK Stack, Splunk, Datadog, Power BI</li><li><b>Collaboration: </b>Jira, Confluence, SharePoint, MS Teams</li></ul><p></p><h1><b>Required Skills & Experience:</b></h1><ul><li><b>Education: </b>Bachelor’s Degree in Cybersecurity, Information Systems, or related discipline <b>required</b>; Master's Degree <b>preferred</b></li><li><b>Experience: 10+ years</b> of experience in identity and access management, including <b>8+ years</b> in cloud-based federal environments<b> required; </b>12+ years of experience in information systems <b>preferred</b></li><li>Strong knowledge of <b>identity federation protocols</b> (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows</li><li>Hands-on experience with <b>AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify</b> for SSO and MFA implementations</li><li>Expertise with <b>RBAC/ABAC frameworks</b>, policy-based access control, and least-privilege enforcement</li><li>Familiarity with <b>NIST 800-63, FISMA, FedRAMP, and ZTA</b> standards and compliance frameworks</li><li>Experience implementing ICAM solutions in <b>Agile and DevSecOps</b> environments</li><li>Working knowledge of <b>PKI, digital certificates, and encryption technologies</b></li><li>Strong analytical and troubleshooting skills with ability to resolve identity integration issues</li><li>AWS Container security, Network security</li><li>Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system</li><li>Experience supporting <b>federal digital modernization</b> or judiciary IT programs.</li><li>Expert level working experience with <b>AWS services</b> and integration of ICAM with containerized workloads (ECS, EKS)</li><li>Familiarity with <b>Zero Trust Architecture</b> and micro segmentation principles</li><li>Exposure to <b>API gateway authentication</b> (Kong, Apigee, AWS API Gateway).</li><li>Experience integrating <b>identity governance tools</b> (SailPoint, Saviynt).</li><li>Excellent presentation and communication skills</li><li>Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship</li><li>Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies</li><li>Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement</li><li>Demonstrated ability to work effectively, independently, and as part of a team</li></ul><p></p><p><b>Certification(s):</b></p><ul><li><span>Certified Information Systems Security Professional (CISSP)</span><b><span> -</span></b><span> <b>preferred</b></span></li><li>AWS Certified Security – Specialty or Azure Identity & Access Administrator – <b>preferred</b></li><li>Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) –<b> beneficial</b></li><li>SAFe Practitioner (SPC/SSM) – <b>a plus</b></li></ul><p><br><b>Security Clearance Level:</b> Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts.<br> </p><p><b>Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen).</b></p><p><br><b>Location: </b>Remote<br><br><b>GDIT IS YOUR PLACE</b><br><i>At GDIT, the mission is our purpose, and our people are at the center of everything we do.</i></p><ul><li><b>Growth:</b> AI-powered career tool that identifies career steps and learning opportunities</li><li><b>Support:</b> An internal mobility team focused on helping you achieve your career goals</li><li><b>Rewards:</b> Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off</li><li><b>Community:</b> Award-winning culture of innovation and a military-friendly workplace</li></ul><p><br><b>OWN YOUR OPPORTUNITY</b><br>Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.</p><p style="text-align:inherit"></p><p style="text-align:inherit"></p>The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Scheduled Weekly Hours:</b></u></p>40<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><u>Travel Required:</u></b></p>Less than 10%<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><u><span><span>T</span>elecommuting Options:</span></u></b></p>Remote<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Work Location:</b></u></p>Any Location / Remote<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><u><b>Additional Work Locations:</b></u></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><u>Total Rewards at GDIT:</u></b></p>Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.<p style="text-align:inherit"></p><p style="text-align:inherit"></p>We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.<p style="text-align:inherit"></p><p style="text-align:inherit"></p>Join our Talent Community to stay up to date on our career opportunities and events at<p><a href="https://www.gdit.com/tc" target="_blank" rel="noopener noreferrer">gdit.com/tc</a>.</p><p></p><p></p><p></p>Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...