Jobs Companies GDIT Zero Trust ICAM & PKI SME

Sobre este puesto de Zero Trust ICAM & PKI SME en GDIT

GDIT · Presencial · USA FL MacDill AFB

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Top Secret/SCI

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Access Management, Credentialing, Identity Management (IdM), PKI Certificate Management

Certifications:

None

Experience:

10 + years of related experience

US Citizenship Required:

Yes

Job Description:

Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.

MEANINGFUL WORK AND PERSONAL IMPACT

As a Zero Trust ICAM & PKI SME, the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM’s network enclaves, aligned with DoD Zero Trust principles.

HOW A ZERO TRUST ICAM & PKI SME WILL MAKE AN IMPACT

Your responsibilities span across the three core ICAM pillars:

1. Identity Management (Identity Lifecycle & Directory Services)

  • Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA’s enterprise solution to ensure seamless integration with Zero Trust architectures.

  • Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.

  • Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.

  • Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.

  • Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.

2. Credentialing & PKI (Authenticators, Non-Person Entities & Cryptography)

  • Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.

  • Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).

  • Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.

  • Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.

  • Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).

  • Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.

3. Access Management & Governance (Authorization, Federation & PAM)

  • Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).

  • Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.

  • Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.

  • Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).

  • Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.

Cross-Pillar Operations & Compliance

  • Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.

  • Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.

  • Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.

  • Produce management reports, audit metrics, compliance packages, and system administration runbooks.

WHAT YOU’LL NEED TO SUCCEED

Bring your technology expertise and drive for innovation to GDIT. The Zero Trust ICAM & PKI SME must have:

  • Clearance: Active Secret

  • Citizenship: U.S. Citizenship required

  • Education: Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.

  • Certification: Applicable DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III Certification (e.g., Security+ CE, CASP+, CISSP) along with relevant role-based credentials (e.g., CIAM, CIGE, CIMP, Microsoft Certified: Identity and Access Administrator Associate, or Okta Certified Professional).

  • Experience: 10+ years of related engineering and operations experience in enterprise IT and cybersecurity.

Technical Competencies by Pillar

1. Identity Management

  • 10+ years of experience in enterprise identity architectures and directory infrastructure (Active Directory, LDAP).

  • Deep understanding of Master User Records (MUR), Identity Governance & Administration (IGA platforms such as SailPoint), and automated provisioning workflows.

  • Familiarity with DISA enterprise identity solutions and federal identity federation models.

2. Credentialing & PKI

  • In-depth expertise in Public Key Infrastructure (PKI) concepts: X.509 certificates, CA trust hierarchies, Certificate Revocation Lists (CRLs), and Online Certificate Status Protocol (OCSP).

  • Hands-on engineering experience administering enterprise CA platforms (e.g., Microsoft AD CS, Keyfactor) and integrating with DoD/Federal PKI (FPKI).

  • Direct experience with Certificate Lifecycle Management (CLM) tools and automated enrollment protocols (SCEP, EST, ACME).

  • Experience with CAC/PIV middleware, hardware tokens, and Hardware Security Modules (HSMs) (e.g., Thales/SafeNet).

3. Access Management & Governance

  • Advanced proficiency in designing and implementing access control models (RBAC, ABAC, PBAC, and IBAC).

  • Hands-on experience configuring and managing Privileged Access Management (PAM) suites (e.g., Delinea).

  • Strong understanding of modern authentication protocols and federation mechanisms (SAML 2.0, OAuth, OpenID Connect, Kerberos, mTLS).

  • Proven experience supporting Zero Trust policy enforcement points (PEP) and policy decision points (PDP).

Desired Skills & Qualifications

  • Microsoft Windows Hybrid Administrator or ITIL 4 Foundation Certification.

  • Operational familiarity with USCENTCOM mission networks, enclaves, and operating environments.

  • Scripting and automation proficiency (PowerShell, Python, or Bash) for automating identity provisioning and certificate management workflows.

  • Experience integrating mTLS and certificate validation within enterprise API gateways, microservices, and reverse proxies.

  • Proven ability to author system architecture documents, CONOPS, disaster recovery runbooks, and engineering implementation guides.

Travel Requirements

  • Required USCENTCOM remote location support of up to 10% Travel during the Year to OCONUS Locations

Company Overview:

GDIT is a leading technology integrator solving our nation's most complex modernization and readiness challenges.  We provide innovative technology solutions and services across Defense, Intelligence, Homeland Security, Federal Civilian, and Health markets.  Join GDIT and be a part of the team of men and women that solve some of the world's most complex technical challenges.

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities

  • Support: An internal mobility team focused on helping you achieve your career goals

  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, competitive pay and paid time off

  • Community: Award-winning culture of innovation and a military-friendly workplace

#gditpriority

#armajobs

The likely salary range for this position is $129,813 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Onsite

Work Location:

USA FL MacDill AFB

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 

 


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

 

 

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
¿Listo para postularte en GDIT?
Postúlate en GDIT

Sobre GDIT

Opportunity Owned From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world. For more information about GDIT's Privacy Policy, click here: Privacy Policy | GDIT

Ver todos los empleos en GDIT →

Empleos similares

GDIT
Salesforce Developer - TS/SCI with Polygraph
GDIT
⚡ Postúlate pronto USA VA McLean Presencial $162,037–$219,227
● Nuevo 👁 Visto ✓ Postulado hace 19h
GDIT
Systems Engineer Sr Principal
GDIT
⚡ Postúlate pronto USA VA Langley AFB Presencial $129,813–$151,800
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Systems Engineer Principal
GDIT
⚡ Postúlate pronto USA VA Virginia Beach Presencial $112,840–$143,750
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Supply Support Activity (SSA) Receiving Section Lead, Kuwait (Secret Clearance required)
GDIT
⚡ Postúlate pronto International Presencial $76,500–$103,500
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Electrical Engineer
GDIT
⚡ Postúlate pronto USA ID Bayview Presencial $73,965–$94,300
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Electronics Technician Maintenance II
GDIT
⚡ Postúlate pronto USA LA Fort Polk - 6235 Georgi... Presencial $56,971–$77,064
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Technical Editor
GDIT
⚡ Postúlate pronto USA AZ Fort Huachuca Presencial $56,950–$77,050
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
ServiceNow Developer Senior
GDIT
⚡ Postúlate pronto Any Location / Remote · restringido por ubicación $97,968–$126,500
● Nuevo 👁 Visto ✓ Postulado hace 1d
GDIT
Senior Contracts Administrator
GDIT
⚡ Postúlate pronto USA VA Falls Church Presencial $81,349–$94,999
● Nuevo 👁 Visto ✓ Postulado hace 1d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en GDIT

Ver todos los empleos en GDIT →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis