CACI-posted 10 days ago
Full-time • Mid Level
San Antonio, TX
5,001-10,000 employees

Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems. Lead the integration and automation of identity services across hybrid cloud and on-premises infrastructures. Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, HashiCorp Vault, and related technologies. Collaborate with cybersecurity, DevSecOps, and infrastructure teams to enhance security posture and streamline identity workflows. Play a critical role in ensuring seamless, secure, and scalable access to secure multi-cloud and on-prem systems across the organization.

  • Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
  • Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
  • Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
  • Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
  • Define and enforce security policies for authentication, authorization, and token management across distributed systems.
  • Collaborate with security teams to implement Zero Trust and least-privilege access principles.
  • Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
  • Monitor, troubleshoot, and optimize performance and reliability of identity systems and associated integrations.
  • Maintain documentation of configurations, operational procedures, and identity management standards.
  • Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
  • Bachelor’s degree in Computer Science, Information Systems, or related technical field.
  • 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
  • Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
  • Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
  • Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).
  • Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
  • Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
  • Solid understanding of networking, PKI, TLS, and secure service-to-service communication.
  • Demonstrated ability to troubleshoot complex system and identity-related issues in production environments.
  • Must be located in San Antonio, TX or willing to relocate.
  • Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
  • Knowledge of Kubernetes, containerized deployments, and service mesh identity integration.
  • Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
  • Experience with GitOps workflows and CI/CD tools such as GitLab CI, Jenkins, or ArgoCD.
  • Relevant certifications such as HashiCorp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified DevOps Engineer.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service