IAM (Identity & Access Management) Engineer

2026-172116

CAtegory:

Information Technology

Clearance:

Top Secret/SCI with Poly

Location:

Chantilly
,
Virginia

Telecommute:

No remote/telework allowed
About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

About The Role

We are seeking Identity & Access Management (IAM) Engineers to design, automate, operate, and sustain identity and access services across a complex, highly secure platform environment.

 

These engineers will support identity federation, authentication, authorization, RBAC/ABAC, single sign-on (SSO), privileged access, and workload identity across shared platform services and tenant environments. The role will integrate enterprise identity and token services with applications, cloud platforms, Kubernetes, development environments, and operational services while maintaining the identity-to-entitlement layer that controls access across the environment.

The ideal candidate brings strong IAM engineering experience and is comfortable working across identity platforms, cloud infrastructure, applications, security controls, and automation. This role offers the opportunity to build and operate identity capabilities that support both human users and machine/workload identities at scale.

Responsibilities

Identity Federation & Single Sign-On

  • Integrate platform services with enterprise identity, token, and directory services.

  • Design, operate, and integrate Keycloak or equivalent identity services.

  • Implement and troubleshoot OAuth/OIDC, SAML, LDAP, and related identity-federation patterns as applicable.

  • Maintain reliable SSO across approved platform services, applications, and environments.

  • Troubleshoot federation and authentication flows across interconnected systems and identity providers.

Authorization & Entitlements

  • Design and maintain Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) patterns for users, tenant administrators, privileged users, and services.

  • Integrate identity and authorization services with GitLab, Kubernetes, mission applications, ServiceNow, and federated AWS access.

  • Design and support workload and service-identity patterns for pipelines, automation, APIs, and platform services.

  • Support access reviews, access recertification, and separation-of-duties requirements.

  • Ensure identity and entitlement models align with established security and access-control requirements.

Automation & Identity Operations

  • Automate user, group, role, and entitlement lifecycle activities where practical.

  • Support privileged-access workflows and elevated-role approval processes.

  • Troubleshoot authentication, authorization, token, and federation issues escalated from Tier 2 support.

  • Maintain identity-service monitoring, documentation, recovery procedures, and operational support processes.

  • Identify opportunities to improve identity lifecycle management and reduce manual access-management activities through automation.

Platform & Security Integration

  • Collaborate with cloud, Kubernetes, platform, application, infrastructure, and cybersecurity teams to integrate identity capabilities across the environment.

  • Support identity requirements for shared services, tenant environments, applications, and automated workloads.

  • Evaluate identity and access impacts of new services, platform changes, and evolving architecture.

  • Support secure identity patterns across highly restricted and multi-domain environments.

Location: This position is fully onsite in Chantilly, VA

Qualifications

Required Qualifications

  • Active TS/SCI clearance with CI Polygraph.
  • Approximately 6–8 years of experience in IAM, cybersecurity, directory services, security engineering, platform engineering, or a related discipline.

  • 6 years' of experience with a BS/BA, an additional 4 years' may be considered in lieu of a degree.
  • Demonstrated experience with identity federation, SSO, OAuth/OIDC, SAML, RBAC, and enterprise identity systems.

  • Experience integrating identity and access services with cloud, applications, or Kubernetes environments.

  • Experience troubleshooting complex authentication, authorization, token, and federation issues.

  • Working knowledge of privileged-access management and identity lifecycle controls.

  • Strong scripting and automation skills.

  • Strong analytical, troubleshooting, documentation, and communication skills.

Desired Qualifications

  • Experience with Keycloak.

  • Experience with AWS IAM and federated-role integration.

  • Experience with Kubernetes RBAC.

  • Experience with GitLab identity integration.

  • Experience with ServiceNow identity or workflow integration.

  • Experience with Zero Trust architectures.

  • Experience supporting classified or multi-domain identity environments.

  • Experience automating identity lifecycle and entitlement management.

Details

Target Salary Range: $112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at&nbsp;<a href="https://www.careers.peraton.com/benefits?" target="_blank" rel="noopener">https://www.careers.peraton.com/benefits.

Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.&nbsp;By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity.&nbsp;Use of artificial intelligence (AI) tools of any kind during Peraton interviews is strictly prohibited unless the candidate has obtained prior written authorization. All interview responses must be the candidate&rsquo;s own.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

VIEW
SAVED
JOBS