Demo

Identity & Access Management Engineer (TS/SCI)

Judge Group, Inc.
Somerset, MD Full Time
POSTED ON 4/9/2025
AVAILABLE BEFORE 6/9/2025

Job Details

Location: Somerset, MD
Salary: $160,000.00 USD Annually - $180,000.00 USD Annually
Description: The Judge Group is currently seeking a Identity & Access Management Engineer with an active TS/SCI clearance to support an IC customer in Bethesda, MD. For immediate consideration email your resume to
- Robbie Kissinger

Location: Bethesda, MD

Security Clearance: TS/SCI

About the Role:

As an IAM Engineer, you will ensure the health, status, operations, and maintenance of identity management systems, including Keycloak and OpenID Connect (OIDC) technologies. You will collaborate with a team supporting a large enterprise across multiple enclaves and sites.

Responsibilities:
  • Design and implement IAM solutions using Keycloak for secure authentication and authorization based on OIDC, OAuth2, and SAML protocols.
  • Integrate Keycloak with internal and external applications, APIs, and third-party services to enable secure access and identity federation.
  • Manage and maintain the Keycloak infrastructure, including clustering, performance tuning, and monitoring.
  • Implement custom authentication flows, policies, and user federation strategies using Keycloak.
  • Collaborate with DevOps and infrastructure teams to ensure the scalability, security, and high availability of Keycloak deployments.
  • Automate identity and access workflows, including user provisioning, de-provisioning, and role-based access control (RBAC).
  • Provide technical expertise for OIDC/OAuth2 standards, keeping up with industry trends and ensuring compliance with evolving security requirements.
  • Troubleshoot issues related to authentication, authorization, and access control, ensuring a seamless user experience.
  • Document system configurations, processes, and troubleshooting procedures for internal teams and stakeholders.
  • Conduct regular security audits and recommend improvements for IAM practices and systems.
  • Participate in and contribute to cross-functional teams working on broader IAM, DevSecOps, and security initiatives.
  • Provide support for implementing, troubleshooting, and maintaining identity management systems.
  • Rapidly distinguish isolated user problems from enterprise-wide application/system problems and provide recommended solutions.
  • Provide follow-up reports for root cause analysis, engineering technical assessment, and process improvement initiatives.
  • Update operations and maintenance documentation for 24/7/365 enterprise watch personnel.
  • Work with Operations, Engineering, and vendor support to develop solutions to complex technical issues.
  • Work independently as part of a virtual team.
  • Provide mentorship and training for junior team members.

Basic Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
  • 3-5 years of experience in Identity and Access Management (IAM) with a focus on Keycloak and OIDC/OAuth2 technologies.
  • Strong hands-on experience with configuring, deploying, and managing Keycloak in a production environment.
  • Deep understanding of authentication and authorization protocols including OIDC, OAuth2, SAML, and LDAP.
  • Proficiency in Java, Python, or other scripting languages used for extending and automating Keycloak.
  • Experience with user federation (LDAP, Active Directory, etc.) and social identity providers (Google, Facebook, etc.) using Keycloak.
  • Familiarity with DevOps practices, including CI/CD pipelines, and experience with Docker, Kubernetes, and infrastructure-as-code (IaC) tools such as Terraform.
  • Strong problem-solving and debugging skills, particularly in complex, distributed environments.
  • Ability to work in an Agile/Scrum environment, collaborating with cross-functional teams.
  • Strong communication skills, with the ability to articulate technical solutions to both technical and non-technical stakeholders.
  • Must meet DoD 8570.11- IAT Level II certification requirements (currently Security CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification).
  • Must have a Bachelor's degree with at least 12 years of relevant experience. Additional years of experience may be considered in lieu of a degree.
  • Due to the nature of the government contracts we support, ship is required.
  • TS/SCI clearance with Polygraph required or a TS/SCI and willingness to obtain a Poly.


By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.

Contact:

This job and many more are available through The Judge Group. Please apply with us today!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

Salary : $160,000 - $180,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Identity & Access Management Engineer (TS/SCI)?

Sign up to receive alerts about other jobs on the Identity & Access Management Engineer (TS/SCI) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$59,454 - $77,232
Income Estimation: 
$74,206 - $95,716
Income Estimation: 
$59,454 - $77,232
Income Estimation: 
$74,206 - $95,716
Income Estimation: 
$74,206 - $95,716
Income Estimation: 
$94,625 - $127,578
Income Estimation: 
$94,625 - $127,578
Income Estimation: 
$132,795 - $178,786
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Judge Group, Inc.

Judge Group, Inc.
Hired Organization Address Minneapolis, MN Full Time
Job Details Location: Minneapolis, MN Salary: Negotiable Description: Job Description: The Support Centre Analyst II is ...
Judge Group, Inc.
Hired Organization Address Waterloo, IA Full Time
Job Details Location: Waterloo, IA Salary: $40.00 USD Hourly - $50.00 USD Hourly Description: Job Title: Tool Designer L...
Judge Group, Inc.
Hired Organization Address Charlotte, NC Full Time
Job Details Location: Charlotte, NC Salary: $45.00 USD Hourly - $50.00 USD Hourly Description: Job Title: Systems Operat...
Judge Group, Inc.
Hired Organization Address Charlotte, NC Full Time
Job Details Location: Charlotte, NC Salary: $69.00 USD Hourly - $74.00 USD Hourly Description: Job Title: Systems Archit...

Not the job you're looking for? Here are some other Identity & Access Management Engineer (TS/SCI) jobs in the Somerset, MD area that may be a better fit.

Identity Access & Management Engineer

Bayview Asset Management, LLC, Coral, FL

Senior Access Management Program Specialist

Identity Fusion, Odessa, FL

AI Assistant is available now!

Feel free to start your new journey!