Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
We are seeking Identity & Access Management (IAM) Engineers to design, automate, operate, and sustain identity and access services across a complex, highly secure platform environment.
These engineers will support identity federation, authentication, authorization, RBAC/ABAC, single sign-on (SSO), privileged access, and workload identity across shared platform services and tenant environments. The role will integrate enterprise identity and token services with applications, cloud platforms, Kubernetes, development environments, and operational services while maintaining the identity-to-entitlement layer that controls access across the environment.
The ideal candidate brings strong IAM engineering experience and is comfortable working across identity platforms, cloud infrastructure, applications, security controls, and automation. This role offers the opportunity to build and operate identity capabilities that support both human users and machine/workload identities at scale.
Integrate platform services with enterprise identity, token, and directory services.
Design, operate, and integrate Keycloak or equivalent identity services.
Implement and troubleshoot OAuth/OIDC, SAML, LDAP, and related identity-federation patterns as applicable.
Maintain reliable SSO across approved platform services, applications, and environments.
Troubleshoot federation and authentication flows across interconnected systems and identity providers.
Design and maintain Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) patterns for users, tenant administrators, privileged users, and services.
Integrate identity and authorization services with GitLab, Kubernetes, mission applications, ServiceNow, and federated AWS access.
Design and support workload and service-identity patterns for pipelines, automation, APIs, and platform services.
Support access reviews, access recertification, and separation-of-duties requirements.
Ensure identity and entitlement models align with established security and access-control requirements.
Automate user, group, role, and entitlement lifecycle activities where practical.
Support privileged-access workflows and elevated-role approval processes.
Troubleshoot authentication, authorization, token, and federation issues escalated from Tier 2 support.
Maintain identity-service monitoring, documentation, recovery procedures, and operational support processes.
Identify opportunities to improve identity lifecycle management and reduce manual access-management activities through automation.
Collaborate with cloud, Kubernetes, platform, application, infrastructure, and cybersecurity teams to integrate identity capabilities across the environment.
Support identity requirements for shared services, tenant environments, applications, and automated workloads.
Evaluate identity and access impacts of new services, platform changes, and evolving architecture.
Support secure identity patterns across highly restricted and multi-domain environments.
Location: This position is fully onsite in Chantilly, VA
Approximately 6–8 years of experience in IAM, cybersecurity, directory services, security engineering, platform engineering, or a related discipline.
Demonstrated experience with identity federation, SSO, OAuth/OIDC, SAML, RBAC, and enterprise identity systems.
Experience integrating identity and access services with cloud, applications, or Kubernetes environments.
Experience troubleshooting complex authentication, authorization, token, and federation issues.
Working knowledge of privileged-access management and identity lifecycle controls.
Strong scripting and automation skills.
Strong analytical, troubleshooting, documentation, and communication skills.
Experience with Keycloak.
Experience with AWS IAM and federated-role integration.
Experience with Kubernetes RBAC.
Experience with GitLab identity integration.
Experience with ServiceNow identity or workflow integration.
Experience with Zero Trust architectures.
Experience supporting classified or multi-domain identity environments.
Experience automating identity lifecycle and entitlement management.
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.