Identity and Access Management Engineer
ECS FEDERAL LLC ·
- Seniority
- Senior
- Category
- Security
Everforth ECS is seeking an Identity Infrastructure Engineer to work in our Fairfax, VA office in a hybrid capacity.
Everforth ECS is seeking an experienced and technically sharp Identity Infrastructure Engineer to join a team responsible for managing and maintaining multiple network enclaves to support the DoW community. This role oversees the design, implementation, and ongoing support of the organization's directory and identity management solutions which is the foundational layer that underpins access, authentication, and security across the entire enterprise.
In this role, you will own the health, integrity, and security of the organization's identity infrastructure. That means administering Microsoft Active Directory and related directory services, managing PKI and certificate lifecycle operations, and ensuring that the identity backbone supporting thousands of users and systems is reliable, well-documented, and hardened against threats.
This is a hands-on senior-level role for someone who takes pride in keeping complex infrastructure running cleanly, communicates clearly with teams across the organization, and understands that identity is not just a technical function but a critical security control.
Key Responsibilities:
- Design and implement a formal RBAC framework across associated environments, including EntraID, AWS, NGINX, AppGate, And Keycloak
- Establish and enforce least privilege policies in alignment with Zero Trust Architecture principles and federal directives
- Validate that implemented access controls align with organizational Zero Trust and security requirements.
- Develop and manage identity lifecycle processes for joiners, movers, and leavers across the program, ensuring timely provisioning and deprovisioning
- Implement and manage a Privileged Access Management (PAM) program including identification, governance, and monitoring of privileged accounts
- Lead access review and audit processes to support PAR/RAR reporting requirements and ongoing compliance obligations
- Develop and maintain role-to-privilege mappings and job function definitions across the program to eliminate access ambiguity
- Collaborate with program leadership, system owners, to ensure IAM policies align with organizational changes and personnel transitions
- Support the implementation and ongoing operation of AppGate SDP Zero Trust Network Access solutions.
- Gather user, application, device and connectivity requirements and translate them into documented access-control requirements.
- Assist senior engineers with designing identity-based, least-privilege access policies.
- Support onboarding of users, endpoints, applications and protected network resources into AppGate SDP.
- Produce IAM metrics, reports, and dashboards to communicate access risk and governance posture to program leadership
- Serve as the IAM subject matter expert for program compliance activities, audits, and government stakeholder engagements
- Other duties, as assigned.
Note: Salary is commensurate with skillset, qualifications, experience, and educational background.
Salary Range: $130,000-180,000
General Description of Benefits