SonicJobs Logo
Left arrow iconBack to search

SME Systems Engineer (Entra)

Govcio LLC
Posted 23 days ago, valid for 11 days
Location

Alexandria, VA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • GovCIO is hiring a highly experienced SME Systems Engineer specializing in Identity Management (IdM) with a focus on Microsoft Entra, supporting the U.S. Coast Guard's ICAM modernization activities.
  • The role involves designing and executing secure access control frameworks and managing enterprise identity systems in a hybrid position located in Alexandria, VA.
  • Candidates must have a high school diploma with at least 10 years of relevant experience and an active Secret clearance.
  • Required skills include deep knowledge of federated identity concepts and hands-on experience with Smart Card authentication and PKI systems.
  • The salary for this position ranges from $135,000 to $172,000 per year.

GovCIO is currently hiring a highly experienced SME Systems Engineer specializing in Identity Management (IdM) with a primary focus on the Microsoft Entra product area. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). This position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This position will be located in Alexandria, VA, and will be a hybrid position.


Responsibilities

The SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include:
  • Lead Modernize legacy access controls into robust, secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and SSO protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs.
  • Configure and manage enterprise-grade PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and PAM.
  • Build federated identity services to enable secure interoperability with mission partners.
  • Conduct technical root cause analysis, privilege audits, and system performance tuning.
  • Develop custom technical interfaces, architectures, data flows, and compliance documentation.
  • Provide advanced engineering and architecture ownership across the following specialization:
    • Microsoft Entra (Primary Product Area: Identity Management (IdM)): Serve as the definitive technical owner for the Microsoft Entra tenant and its associated services. Architect, manage, and serve as the final escalation point for the Entra Connect Sync identity synchronization service. Own the overall design of the Entra tenant, including security policies, conditional access architecture, and integration strategies. Engineer and architect the technical implementation of Entra ID Governance, specifically Privileged Identity Management (PIM) and Access Reviews.

Qualifications

High School with 10+ years (or commensurate experience)

 

Required Skills & Experience
  • Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).
  • Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture.
  • Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation.
  • Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks.

Clearance Level: Must have an active Secret clearance

 

Preferred Skills & Experience
  • Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
  • Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls.
  • Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
  • Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards.

        #USCG #DICE


Posted Salary Range

USD $135,000.00 - USD $172,000.00 /Yr.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.