Yesterday
Top Secret/SCI
Unspecified
Polygraph
IT - Security
Bethesda, MD (On-Site/Office)
The Judge Group is currently seeking an Identity & Access Management (IAM) Engineer with an active TS/SCI clearance to support a classified customer in Bethesda, MD. For immediate consideration email your resume to rkissinger@judge.com.
- Robbie Kissinger
Responsibilities:
Basic Qualifications:
- Robbie Kissinger
Responsibilities:
- Design and implement IAM solutions using Keycloak for secure authentication and authorization based on OIDC, OAuth2, and SAML protocols.
- Integrate Keycloak with internal and external applications, APIs, and third-party services to enable secure access and identity federation.
- Manage and maintain the Keycloak infrastructure, including clustering, performance tuning, and monitoring.
- Implement custom authentication flows, policies, and user federation strategies using Keycloak.
- Collaborate with DevOps and infrastructure teams to ensure the scalability, security, and high availability of Keycloak deployments.
- Automate the management of identity and access workflows, including user provisioning, de-provisioning, and role-based access control (RBAC).
- Provide technical expertise for OIDC/OAuth2 standards, keeping up with industry trends and ensuring compliance with evolving security requirements.
- Troubleshoot issues related to authentication, authorization, and access control, ensuring a seamless user experience.
- Document system configurations, processes, and troubleshooting procedures for internal teams and stakeholders.
- Conduct regular security audits and recommend improvements for IAM practices and systems.
- Participate in and contribute to cross-functional teams working on broader IAM, DevSecOps, and security initiatives.
- Provide support for implementing, troubleshooting and maintaining of identity management systems.
- Rapidly distinguish isolated user problems from enterprise-wide application/system problems and provide recommended solutions.
- Provide follow-up reports (technical findings, feedback, resolution steps taken) for root cause analysis, engineering technical assessment and process improvement initiatives.
- Update operations and maintenance documentation for 24/7/365 enterprise watch personnel.
- Work with Operations, Engineering, and vendor support to develop solutions to complex technical issues.
- Work independently as part of a virtual team
- Provide mentorship and training for junior team members.
Basic Qualifications:
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
- 3-5 years of experience working in Identity and Access Management (IAM) with a focus on Keycloak and OIDC/OAuth2 technologies.
- Strong hands-on experience with configuring, deploying, and managing Keycloak in a production environment.
- Deep understanding of authentication and authorization protocols including OIDC, OAuth2, SAML, and LDAP.
- Proficiency in Java, Python, or other scripting languages used for extending and automating Keycloak.
- Experience with user federation (LDAP, Active Directory, etc.) and social identity providers (Google, Facebook, etc.) using Keycloak.
- Familiarity with DevOps practices, including CI/CD pipelines, and experience with Docker, Kubernetes, and infrastructure-as-code (IaC) tools such as Terraform.
- Strong problem-solving and debugging skills, particularly in complex, distributed environments.
- Ability to work in an Agile/Scrum environment, collaborating with cross-functional teams.
- Strong communication skills, with the ability to articulate technical solutions to both technical and non-technical stakeholders.
- Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements (currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification)
- Candidate must have a Bachelor's, with at least 12 years of relevant experience. Additional years of experience may be considered in lieu of degree.
- Due to the nature of the government contracts we support, US Citizenship is required.
- TS/SCI clearance with Polygraph required or a TS/SCI and willingness to get a Poly.
group id: cxjudgpa