Zero Trust ICAM & PKI SME

General Dynamics Information Technology
$129,813 - $172,500Onsite

About The Position

Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you. As a Zero Trust ICAM & PKI SME, the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM’s network enclaves, aligned with DoD Zero Trust principles.

Requirements

  • Active Secret clearance
  • U.S. Citizenship required
  • Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.
  • Applicable DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III Certification (e.g., Security+ CE, CASP+, CISSP) along with relevant role-based credentials (e.g., CIAM, CIGE, CIMP, Microsoft Certified: Identity and Access Administrator Associate, or Okta Certified Professional).
  • 10+ years of related engineering and operations experience in enterprise IT and cybersecurity.
  • 10+ years of experience in enterprise identity architectures and directory infrastructure (Active Directory, LDAP).
  • Deep understanding of Master User Records (MUR), Identity Governance & Administration (IGA platforms such as SailPoint), and automated provisioning workflows.
  • Familiarity with DISA enterprise identity solutions and federal identity federation models.
  • In-depth expertise in Public Key Infrastructure (PKI) concepts: X.509 certificates, CA trust hierarchies, Certificate Revocation Lists (CRLs), and Online Certificate Status Protocol (OCSP).
  • Hands-on engineering experience administering enterprise CA platforms (e.g., Microsoft AD CS, Keyfactor) and integrating with DoD/Federal PKI (FPKI).
  • Direct experience with Certificate Lifecycle Management (CLM) tools and automated enrollment protocols (SCEP, EST, ACME).
  • Experience with CAC/PIV middleware, hardware tokens, and Hardware Security Modules (HSMs) (e.g., Thales/SafeNet).
  • Advanced proficiency in designing and implementing access control models (RBAC, ABAC, PBAC, and IBAC).
  • Hands-on experience configuring and managing Privileged Access Management (PAM) suites (e.g., Delinea).
  • Strong understanding of modern authentication protocols and federation mechanisms (SAML 2.0, OAuth, OpenID Connect, Kerberos, mTLS).
  • Proven experience supporting Zero Trust policy enforcement points (PEP) and policy decision points (PDP).

Nice To Haves

  • Microsoft Windows Hybrid Administrator or ITIL 4 Foundation Certification.
  • Operational familiarity with USCENTCOM mission networks, enclaves, and operating environments.
  • Scripting and automation proficiency (PowerShell, Python, or Bash) for automating identity provisioning and certificate management workflows.
  • Experience integrating mTLS and certificate validation within enterprise API gateways, microservices, and reverse proxies.
  • Proven ability to author system architecture documents, CONOPS, disaster recovery runbooks, and engineering implementation guides.

Responsibilities

  • Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA’s enterprise solution to ensure seamless integration with Zero Trust architectures.
  • Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.
  • Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.
  • Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.
  • Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.
  • Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.
  • Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).
  • Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.
  • Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.
  • Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).
  • Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.
  • Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).
  • Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.
  • Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.
  • Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).
  • Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.
  • Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.
  • Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.
  • Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.
  • Produce management reports, audit metrics, compliance packages, and system administration runbooks.

Benefits

  • Comprehensive benefits and wellness packages
  • 401K with company match
  • Competitive pay
  • Paid time off
  • Full flex work weeks where possible
  • Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • Short and long-term disability benefits
  • Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service