ICAM Architect

Trinity Global ConsultingChantilly, VA

About The Position

The ICAM Architect will define and maintain the enterprise ICAM architecture across PEP/PIP, EMS, and RPMS modernization. This role ensures alignment with NGA's Zero Trust and ICAM strategic framework, including the transition from the legacy PDP to JBlocks. The architect will develop end-to-end architectural patterns for identity, attribute services, authorization flows, policy distribution, and resource/role lifecycle management. They will partner with the Technical Lead to validate modernization roadmaps, architectural decisions, and integration strategies for both on-prem and cloud-native, microservices-based ICAM components. This position involves translating mission needs into technical requirements, sequence diagrams, data models, interface specifications, and system architecture artifacts. The architect will oversee the design of modern PEP/PIP interfaces supporting attribute-based access control, dynamic policy evaluation, and event-driven decision making. Additionally, they will architect improved EMS and RPMS capabilities, including resource registration, policy lifecycle automation, attribute orchestration, and enterprise authorization services. The role provides architectural guidance to DevOps and Software teams to ensure solutions meet scalability, resilience, security, and maintainability requirements. Responsibilities include conducting architectural reviews, risk assessments, and compliance verification for modernization milestones and incremental releases. The goal is to ensure modernization reduces operational overhead through automation, standardization, improved observability, and optimized deployment pipelines. The architect will identify opportunities for innovation in identity services, authentication technologies, authorization models, and system integration patterns. Finally, they will serve as a senior advisor to program management, providing technical insight to support planning, budgeting, and customer engagement.

Requirements

  • Master's degree in a Science, Technology, Engineering, and Mathematics (STEM) field and 10+ years of relevant experience, or Bachelor's degree and 12+ years of relevant experience.
  • Demonstrated experience as a solutions architect, systems architect, or enterprise architect supporting complex modernization, security, or ICAM programs.
  • Significant experience designing distributed systems, microservices architectures, and cloud-native solutions.
  • Experience leading or supporting teams engaged in ICAM modernization, enterprise identity technology, or authorization/policy services.
  • Familiarity with Agile methodologies and experience contributing to Program Increment (PI) planning, architectural runway development, and iterative delivery.
  • Ability to define architectural goals, strategic plans, and detailed implementation guidance aligned with mission priorities.
  • Ability to obtain CompTIA Security+ within 90 days of hire.
  • Active Top Secret security clearance upon hire with SCI eligibility.
  • U.S. citizenship.

Nice To Haves

  • Experience with Kubernetes, OpenShift, or container orchestration platforms.
  • Experience with modern programming languages and integration (Java and/or Python).
  • Knowledge of GitOps tools for managing modern environments.
  • Certifications in enterprise architecture frameworks.
  • Expertise with identity and authorization standards (X.509, SAML, OAuth2, OIDC, LDAP).
  • Experience architecting ICAM solutions using Oracle or other enterprise-grade identity platforms.
  • Experience defining ABAC/RBAC models, policy-as-code, and Zero Trust–aligned access patterns.
  • Prior experience supporting NGA or Intelligence Community authorization/identity systems.

Responsibilities

  • Define and maintain the enterprise ICAM architecture across PEP/PIP, EMS, and RPMS modernization, ensuring alignment with NGA's Zero Trust and ICAM strategic framework, including transition from the legacy PDP to JBlocks.
  • Develop end-to-end architectural patterns for identity, attribute services, authorization flows, policy distribution, and resource/role lifecycle management.
  • Partner with the Technical Lead to validate modernization roadmaps, architectural decisions, and integration strategies for on-prem and cloud-native, microservices-based ICAM components.
  • Translate mission needs into technical requirements, sequence diagrams, data models, interface specifications, and system architecture artifacts.
  • Oversee the design of modern PEP/PIP interfaces supporting attribute-based access control, dynamic policy evaluation, and event-driven decision making.
  • Architect improved EMS and RPMS capabilities, including resource registration, policy lifecycle automation, attribute orchestration, and enterprise authorization services.
  • Provide architectural guidance to DevOps and Software teams to ensure solutions meet scalability, resilience, security, and maintainability requirements.
  • Conduct architectural reviews, risk assessments, and compliance verification for modernization milestones and incremental releases.
  • Ensure modernization reduces operational overhead through automation, standardization, improved observability, and optimized deployment pipelines.
  • Identify opportunities for innovation in identity services, authentication technologies, authorization models, and system integration patterns.
  • Serve as a senior advisor to program management, providing technical insight to support planning, budgeting, and customer engagement.

Benefits

  • Medical, Dental & Vision Coverage
  • Paid Time Off
  • Paid Holidays
  • Disability & Life Insurance
  • 401(k) Retirement Plan
  • Professional Training
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service