Hiring.Camp

IAM Lead

Icf

·

Jul 28, 2026

Salary
$108k – $184k
Location
DC Remote Office (DC99), United States of America · Virginia Remote Office (VA99) · Maryland Remote Office (MD99)
Workplace
Remote
Type
Full-time
Seniority
Lead
Experience
7+ years
Education
Bachelor
Visa
Not sponsored
Source
Workday

Description

This role is contingent upon a contract award. 

ICF is seeking an IAM Lead to architect, implement, and operate the identity and access management platform for a federal technology program. Reporting to engineering leadership, this role is the subject matter authority on how users, devices, and applications authenticate and are authorized across a cloud-first, Zero Trust environment. The IAM Lead owns the full identity lifecycle, from onboarding automation to privileged access controls to external identity federation. 

The ideal candidate is a senior identity engineer who has built and operated IAM programs in federal cloud environments. This is a deeply technical role. The right candidate understands not just the tooling but the underlying standards, can implement NIST identity assurance requirements, and can hold their own with cybersecurity and enterprise architecture teams on access policy design. 

Job Location: This is a remote-friendly position with occasional onsite requirements in the Washington, DC Metro area. 

This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections. 

What You'll Be Doing 

  • Architect, configure, and maintain identity platforms including Entra ID, Entra External ID, and Okta, covering authentication, authorization, provisioning, and lifecycle management across all users, applications, and devices. 

  • Configure and enforce phishing-resistant authentication for all users, including passkeys, FIDO2 security keys, WebAuthn, and biometrics. Drive the transition away from legacy authentication methods toward a fully passwordless posture. 

  • Define and implement Zero Trust access rules based on user risk, device health, location, and behavior using risk-based and conditional access policies. 

  • Design, configure, and operate authorization models including RBAC, PBAC, and ABAC, with fine-grained permissions and attribute-based access rules aligned to job function and least-privilege principles. 

  • Manage privileged accounts and administrative roles using privileged access management (PAM) and just-in-time elevation, ensuring that standing admin access is minimized and all elevated access is logged and time-bound. 

  • Build and maintain HR-driven joiner, mover, and leaver automation, including automated provisioning, license assignment, role changes, access revocation, and data archival triggered by HR system events. 

  • Federate external identities including partners, contractors, and external collaborators using Entra External ID or equivalent, including self-service registration, verification workflows, and consent management. 

  • Configure identity proofing and verification to NIST IAL and AAL levels where required, coordinating with cybersecurity and compliance teams on assurance requirements. 

  • Integrate applications and APIs with identity platforms using OIDC, OAuth2, SAML, and SCIM for single sign-on and automated provisioning. 

  • Monitor sign-in activity, risk signals, and anomalies. Respond to identity-related incidents including account takeover, phishing, access abuse, and fraud in coordination with the cybersecurity team. 

  • Maintain identity data quality and consistency across directories, HR systems, and applications, including synchronization, schema management, and attribute mapping. 

  • Support compliance and audit activities by producing access reports, certifications, attestations, and evidence of controls. 

  • Document identity architectures, configurations, standards, and runbooks. Provide guidance to application teams on how to onboard to central identity platforms and implement authentication best practices. 

 

Minimum Requirements 

  • Bachelor's degree or equivalent 

  • 7+ years of experience in identity and access management engineering or a related discipline 

  • 3+ years of hands-on experience designing and operating Entra ID or Okta in production environments, including conditional access, lifecycle management, and federation 

  • 2+ years implementing PAM solutions and just-in-time elevation controls for privileged accounts 

  • 2+ years configuring authorization models including RBAC, PBAC, or ABAC in enterprise environments 

  • 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies 

  • U.S. Citizenship required due to federal contract requirements 

  • Ability to obtain and maintain a Public Trust background investigation 

  • Candidate must reside in the US, be authorized to work in the US, and work must be performed in the US 

 

Preferred Qualifications 

  • Experience implementing NIST SP 800-63 identity assurance levels (IAL/AAL) in a federal context 

  • Experience federating external identities using Entra External ID, including self-service registration and consent workflows 

  • Familiarity with FISMA, NIST 800-53, and Zero Trust architecture requirements as they apply to identity and access 

  • Experience integrating identity platforms with HR systems for automated joiner, mover, and leaver workflows 

  • Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Okta Certified Administrator, or equivalent 

  • Experience supporting identity incident response including account takeover, phishing, and access abuse investigations 

Working at ICF

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.

We will consider for employment qualified applicants with arrest and conviction records.

 

Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email [email protected] and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.  

Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. 

 

Candidate AI Usage Policy

At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  

However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at [email protected]. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.  


 

Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.

The pay range for this position based on full-time employment is:

$108,006.00 - $183,610.00

DC Remote Office (DC99)

Skills

CybersecurityFDACompliance

Similar Jobs

30

Sr Lead - IAM Privileged Access Engineering

NT Careers·Tempe, AZ

4d ago

Product Lead - IAM

KPN·Rotterdam, ZH·Hybrid

1w ago

Lead IAM Engineer

Braze·Austin +1

1w ago

Lead IAM Engineer

Braze·Chicago +1

1w ago

Lead IAM Engineer

Braze·Toronto +1

1w ago

Lead IAM Analyst

NationsBenefits, LLC·Hyderabad, IN

1w ago

Lead IAM Architect

DRW·Chicago +1

2w ago

Lead IAM Engineer

Braze·New York City

2w ago

IAM Lead - Program Management

Diligentcorporation·Bengaluru, Karnataka

3w ago

IAM Lead Business Analyst

Airbus·Bangalore, India

1mo ago

Lead IAM Engineer

Centene and its subsidiary companies·Remote-MO, US +8·Remote

1mo ago

Senior IAM Lead

Nexthink·Madrid, MD·Hybrid

2mo ago

Full Stack Lead – IAM Solutions

Ahead·Gurugram, Haryana·Remote

2mo ago

Lead, IAM Automation & Strategy

NT Careers·Chicago, IL +1

2mo ago

Senior Technical Lead - IAM Data Integration and Migration

Peraton·US·Remote

2mo ago

Lead IAM Engineer

Thomson Reuters·Canada, Toronto·Hybrid

2mo ago

SailPoint Engineering lead, IAM

Digital Realty Global·Dallas, TX·Hybrid

2mo ago

Lead IAM Engineer

Bcbsma·Boston, US

2mo ago

Identity & Access Management Workstream Lead (IAM/IDAM)

TEC Partners Limited·London·Hybrid

7mo ago

IAM Governance Lead

Marex·London, GB

6d ago

Lead Engineer, IAM Platform Engineering

AmerisourceBergen is now Cencora! Explore our careers.·APAC > India > Pune > Magalwar - PNQ

1w ago

IAM / Automation Lead

Covetrus·Pennsylvania 1 - Remote 100%, US·Remote

1w ago

Lead Engineer, IAM Platform Engineering

AmerisourceBergen is now Cencora! Explore our careers.·APAC > India > Pune > Samrat Ashok Path

3w ago

Lead Engineer, IAM Platform Engineering

AmerisourceBergen is now Cencora! Explore our careers.·APAC > India > Pune > Samrat Ashok Path

1mo ago

Identity & Access Management (IAM/ICAM) Lead

ERP International·Laurel, MD

1mo ago

IAM Operations Lead

Booz Allen Hamilton·Reston, VA +2

1mo ago

Lead SaaS/IAM Specialist

Wrike·Prague

2mo ago

IT Security Manager - IAM Architect / Lead

Wk·IND - Chennai, Neville Towers·Hybrid

2mo ago

Identity & Access Management (IAM) Technology Lead

Bbh·Boston, US +1

3mo ago

Non-Human Identity and Cloud IAM – Platform Lead

AbbVie·North Chicago, IL·Remote

4mo ago