Jobless Developer
Fantom Corporation logo

Posted 5 days ago

Open

ICAM Architect

Chantilly, VARemote

AI Summary

The ICAM Architect leads the design and modernization of enterprise Identity, Credential, and Access Management (ICAM) capabilities into a cloud-ready, Zero Trust architecture, defining target state and providing architectural oversight for distributed, secure, and scalable identity services.

About this role

Fantom Corporation is a mission-focused organization supporting critical programs across the defense and intelligence community. We partner with our customers to deliver high-impact technical solutions while fostering a culture built on trust, expertise, and long-term career growth.

We are seeking an experienced ICAM Solutions Architect to support a major Identity, Credential, and Access Management (ICAM) modernization initiative. This role will focus on transforming legacy Identity and Access Management capabilities into a modern, cloud-ready architecture using microservices, automation, and DevSecOps best practices.

As the technical architecture lead, you will define the target enterprise architecture, guide modernization efforts, and provide architectural oversight to ensure solutions are secure, scalable, interoperable, and aligned with Zero Trust (ZT) and enterprise ICAM strategies. You will collaborate closely with technical leadership, engineering teams, and program stakeholders to deliver mission-critical identity services supporting enterprise operations.

Responsibilities

  • Define and maintain the enterprise ICAM architecture supporting the modernization of Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS)
  • Lead the transition from legacy Policy Decision Point (PDP) technologies to modern authorization frameworks
  • Design end-to-end architectures supporting identity services, authorization workflows, policy management, attribute services, and resource lifecycle management
  • Develop architecture artifacts including sequence diagrams, data models, interface specifications, and system design documentation
  • Partner with Technical Leads and engineering teams to validate modernization roadmaps, architectural decisions, and cloud migration strategies
  • Architect modern Policy Enforcement Point (PEP) and Policy Information Point (PIP) services supporting Attribute-Based Access Control (ABAC), dynamic policy evaluation, and event-driven authorization
  • Design enterprise authorization services, policy lifecycle automation, resource registration, and attribute orchestration capabilities
  • Provide technical guidance to software engineering, DevOps, and operations teams throughout the development lifecycle
  • Conduct architecture reviews, technical risk assessments, and compliance evaluations to ensure modernization objectives are achieved
  • Drive improvements in automation, observability, deployment pipelines, scalability, resilience, and operational efficiency
  • Evaluate emerging identity technologies, authentication methods, authorization frameworks, and integration patterns to improve enterprise ICAM capabilities
  • Serve as a trusted technical advisor to program leadership, supporting strategic planning, budgeting, customer engagements, and long-term modernization initiatives

Required Qualifications

  • Must posses an active Top Secret Security Clearance
  • Must be willing to obtain a polygraph upon hire
  • Bachelor's degree in Computer Science, Engineering, Information Technology, or another STEM discipline with 12+ years of relevant experience, or a Master's degree with 10+ years of relevant experience
  • Experience serving as a Solutions Architect, Enterprise Architect, or Systems Architect supporting enterprise modernization initiatives
  • Strong experience designing distributed systems, microservices architectures, and cloud-native applications
  • Experience supporting Identity, Credential, and Access Management (ICAM), enterprise identity services, or authorization and policy management platforms
  • Experience defining enterprise architecture strategies, modernization roadmaps, and technical implementation plans
  • Strong understanding of Zero Trust architecture principles and enterprise security frameworks
  • Experience translating mission requirements into scalable technical architectures and engineering solutions
  • Experience working within Agile development environments, including Program Increment (PI) Planning and iterative software delivery
  • Excellent communication, leadership, and stakeholder engagement skills
  • Ability to obtain CompTIA Security+ certification within 90 days of hire
  • Desired Qualifications

  • Experience with Kubernetes, OpenShift, or other container orchestration platforms
  • Experience developing or integrating applications using Java and/or Python
  • Experience with GitOps methodologies and modern DevSecOps practices
  • Enterprise Architecture certifications such as TOGAF, Zachman, or equivalent
  • Expertise with enterprise identity and authorization standards including X.509, SAML, OAuth2, OpenID Connect (OIDC), and LDAP
  • Experience architecting enterprise ICAM solutions using Oracle Identity Management or similar enterprise identity platforms
  • Experience designing Attribute-Based Access Control (ABAC), Role-Based Access Control (RBAC), Policy-as-Code, and Zero Trust access models
  • Experience supporting Department of Defense or Intelligence Community identity and authorization systems
  • Skills

    ABACDevSecOpsICAMKubernetesLDAPMicroservicesOAuth2OIDCOpenShiftRBACSAMLTOGAFZachmanZero-trust

    Explore related jobs

    Browse these categories