CACI-posted about 1 month ago
Full-time • Mid Level
San Antonio, TX
5,001-10,000 employees

Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems. Lead the integration and automation of identity services across hybrid cloud and on-premises infrastructures. • Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, HashiCorp Vault, and related technologies. • Collaborate with cybersecurity, DevSecOps, and infrastructure teams to enhance security posture and streamline identity workflows. • Play a critical role in ensuring seamless, secure, and scalable access to secure multi-cloud and on-prem systems across the organization.

  • Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
  • Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
  • Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
  • Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
  • Define and enforce security policies for authentication, authorization, and token management across distributed systems.
  • Collaborate with security teams to implement Zero Trust and least-privilege access principles.
  • Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
  • Monitor, troubleshoot, and optimize performance and reliability of identity systems and associated integrations.
  • Maintain documentation of configurations, operational procedures, and identity management standards.
  • Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
  • Bachelor’s degree in Computer Science, Information Systems, or related technical field.
  • 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
  • Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
  • Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
  • Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).
  • Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
  • Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
  • Solid understanding of networking, PKI, TLS, and secure service-to-service communication.
  • Demonstrated ability to troubleshoot complex system and identity-related issues in production environments.
  • Must be located in San Antonio, TX or willing to relocate.
  • Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
  • Knowledge of Kubernetes, containerized deployments, and service mesh identity integration.
  • Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
  • Experience with GitOps workflows and CI/CD tools such as GitLab CI, Jenkins, or ArgoCD.
  • Relevant certifications such as HashiCorp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified DevOps Engineer.
  • Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives.
  • We offer competitive compensation, benefits and learning and development opportunities.
  • Our broad and competitive mix of benefits options is designed to support and protect employees and their families.
  • At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service