Systems Engineer (DevSecOps and ICAM)

Tetrad Digital Integrity LLCArlington, VA
$115,000 - $125,000Onsite

About The Position

Tetrad Digital Integrity (TDI) is seeking a Systems Engineer with strong DevSecOps, identity security, and systems-integration expertise to support the Defense Information Systems Agency (DISA) Compartmented Enterprise Services Office (CESO). This role will contribute to the engineering, deployment, automation, and sustainment of an Identity-as-a-Service (IDaaS) platform that underpins CESO’s Zero-Trust Architecture and cross-domain capabilities. The engineer will work hands-on with Ping Identity components, enterprise directory services, automated pipelines, and large-scale ICAM integration patterns across secure environments.

Requirements

  • BS in Computer Science, IT, or related discipline and 8+ years of systems engineering experience (or equivalent experience in lieu of degree).
  • Active TS clearance with SCI eligibility
  • Ability to obtain and maintain a CI Poly and Special Program Access.
  • IAT Level II certification or higher (e.g., Security+ CE, CySA+, SSCP, CISSP).
  • Hands on experience with federation technologies (SAML, OAuth2) and ZeroTrust identity principles.
  • Experience engineering or administering the ForgeRock platform (AM, IDM, DS).
  • Strong understanding of ICAM concepts, identity lifecycle management, and enterprise access controls.
  • Experience with Windows and Linux systems administration, shell scripting, and troubleshooting.

Nice To Haves

  • Experience supporting DISA or DoD mission partners.
  • Active TS/SCI with CI Poly preferred.
  • Experience with any of the following: JISG Access Controls, AWS cloud engineering, IAM, and security services, Ansible playbooks and automated configuration management, CI/CD pipelines (GitLab, Jenkins, etc.)

Responsibilities

  • Engineer, deploy, integrate, secure, and maintain ForgeRock IdP/ICAM components within complex, mission-critical environments.
  • Apply DevSecOps practices—including CI/CD pipelines, automated provisioning, configuration-as-code, and repeatable deployment patterns—to ICAM services.
  • Integrate ICAM services with enterprise directory architecture, federation services, Zero Trust controls, and cross-domain workflows.
  • Implement and maintain access management functions including SSO, identity federation (SAML, OAuth2, OIDC), authentication flows, and policy enforcement.
  • Collaborate with cybersecurity, development, and infrastructure teams to design secure identity solutions aligned with DoD and DISA standards.
  • Conduct system hardening, monitoring, log analysis, and performance tuning across Linux-based ICAM components.
  • Perform systems integration tasks such as API-based connectors, service integrations, and automated provisioning/deprovisioning workflows.
  • Support architectural reviews, internal control assessments, and risk management activities related to ICAM operations.
  • Diagnose and resolve escalated ForgeRock/ICAM issues within defined SLAs, including root-cause analysis and corrective action development.
  • Create, maintain, and version-control engineering documentation including CONOPS, SOPs, API interface documentation, and workflow diagrams.
  • Provide input to audits, ATO support, compliance adherence, and continuous improvement initiatives.
  • Develop and maintain ICAM performance metrics, identity lifecycle reports, and engineering dashboards.
  • Partner with development teams to automate user, group, and credential workflows across secure enclaves.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service