Jobs and Careers
GE

AWS Cloud Security and ICAM Specialist

General Dynamics Information Technology
Baton Rouge, United Statesfull_timeVerifiedPosted 31 May 2026
💰 $207,000/yr($153,000/yr$207,000/yr)

About the role

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

BI Full 6C (T4)

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Access Management, Identity Governance, Secure Authentication

Certifications:

None

Experience:

10 + years of related experience

US Citizenship Required:

No

Job Description:

The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem.

Key Responsibilities:

  • Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM
  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak)
  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
  • Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
  • Develop and document identity lifecycle management processes—provisioning, deprovisioning, and access reviews
  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak
  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
  • Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
  • Design and implement storage level, microservice level Authentication and Authorization
  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
  • Participate in design sessions and work closely with the security lead
  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
  • Direct and lead Pen testing, Review architecture diagrams produced by different teams
  • Independently lead design and implement of vulnerability management
  • Heavily participate in ATO activity
  • Lead and direct engineering team

Deliverable Alignment & Performance Outcomes:

  • Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
  • Access Control Documentation: Policies, RBAC models, and credential management workflows
  • Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
  • Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
  • Performance Outcomes:
    • 100% of CMM applications integrated with SSO and MFA.
    • Zero unauthorized access incidents attributable to configuration error
    • 100% compliance with NIST and FedRAMP ICAM control requirements
    • Reduced account provisioning time by ≥30% through automation

Tools & Technologies:

  • IAM & Federation: Key Cloak, Okta
  • Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
  • Cloud: AWS IAM, KMS, CloudTrail, Lambda

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

General Dynamics Information Technology

View company profile →