Zero Trust ICAM & PKI SME
Gdit · Florida
📍 USA FL MacDill AFBvia workdayFirst listed here 2026-09-17
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Gdit.
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Secret
Clearance Level Must Be Able to Obtain:
Top Secret/SCI
Public Trust/Other Required:
None
Job Family:
IT Infrastructure and Operations
Job Qualifications:
Skills:
Access Management, Credentialing, Identity Management (IdM), PKI Certificate Management Certifications:
None Experience:
10 + years of related experience US Citizenship Required:
Yes
Job Description:
Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.
MEANINGFUL WORK AND PERSONAL IMPACT
As a Zero Trust ICAM & PKI SME , the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM’s network enclaves, aligned with DoW Zero Trust principles.
HOW A ZERO TRUST ICAM & PKI SME WILL MAKE AN IMPACT
Your responsibilities span across the three core ICAM pillars:
1. Identity Management (Identity Lifecycle & Directory Services)
Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA’s enterprise solution to ensure seamless integration with Zero Trust architectures.
Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.
Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.
Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.
Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.
2. Credentialing & PKI (Authenticators, Non-Person Entities & Cryptography)
Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.
Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).
Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.
Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.
Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).
Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.
3. Access Management & Governance (Authorization, Federation & PAM)
Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).
Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.
Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.
Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).
Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.
Cross-Pillar Operations & Compliance
Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.
Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.
Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.
Produce management reports, audit metrics, compliance packages, and system administration runbooks.
WHAT YOU’LL NEED TO SUCCEED
Bring your technology expertise and drive for innovation to GDIT. The Zero Trust ICAM & PKI SME must have:
Clearance: Active Secret
Citizenship: U.S. Citizenship required
Education: Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.
Certification: Applicable DoW 8140 / DoW 8570 IAT Level II/III or IAM Level II/III Certification (e.g., Security+ CE, CASP+, CISSP) along with relevant role-based credentials (e.g., CIAM, CIGE, CIMP, Microsoft Certified: Identity and Access Administrator Associate, or Okta Certified Professional).
Experience: 10+ years of related engineering and operations experience in enterprise IT and cybersecurity.
Technical Competencies by Pillar
1. Identity Management
10+ years of experience in enterprise identity architectures and directory infrastructure (Active Directory, LDAP).
Deep understanding of Master User Records (MUR), Identity Governance & Administration (IGA platforms such as SailPoint), and automated provisioning workflows.
Familiarity with DISA enterprise identity solutions and federal identity federation models.
2. Credentialing & PKI
In-depth expertise in Public Key Infrastructure (PKI) concepts: X.509 certificates, CA trust hierarchies, Certificate Revocation Lists (CRLs), and Online Certificate Status Protocol (OCSP).
More Florida jobs
Florida jobs · Browse all locations