Ad Hoc LLC is a technology company that empowers organizations to deliver scalable, impactful digital services. They are seeking a PKI / IAM Security Engineer to design, implement, and operate identity and access management capabilities for a federal enterprise cloud platform, ensuring secure access to mission-critical systems serving Veterans.
Responsibilities:
- Engineering and operating identity, credential, and access management (ICAM) services, including authentication, authorization, federation, and single sign-on for platform applications
- Implementing and maintaining public key infrastructure (PKI), including certificate issuance, renewal, revocation, and key lifecycle management
- Integrating Personal Identity Verification (PIV) card-based authentication in accordance with HSPD-12 and FIPS 201
- Configuring and managing cloud identity and access management (AWS IAM), including roles, policies, and least-privilege access across multi-account environments
- Applying federal identity standards and frameworks, including NIST SP 800-63 Digital Identity Guidelines and the Federal ICAM (FICAM) architecture, to platform design and operations
- Advancing zero-trust principles across identity and access controls
- Automating identity and access provisioning through infrastructure as code (Terraform) and supporting the platform's Authority to Operate (ATO) with audit-ready evidence
- Producing technical documentation and translating complex identity and security concepts for a range of stakeholders
- Working with government partners and application teams to ensure systems meet security, compliance, and access requirements
Requirements:
- Bachelor's and 3+ years of experience; relevant experience may be substituted for education
- Hands-on experience with identity and access management (IAM) and/or public key infrastructure (PKI) in an enterprise or cloud environment
- Working knowledge of authentication and authorization protocols (e.g., SAML, OAuth 2.0, OIDC, LDAP) and certificate management
- Familiarity with federal identity standards such as PIV / HSPD-12, FIPS 201, or NIST SP 800-63
- Must be able to obtain and maintain a U.S. Public Trust / suitability determination
- Prior experience with the Department of Veterans Affairs
- Experience with cloud IAM (AWS), federation, and single sign-on at scale
- Familiarity with FICAM, zero-trust architecture, and NIST 800-53
- Relevant certifications (e.g., CompTIA Security+, AWS Security Specialty, identity platform certifications, CISSP)
- Experience automating identity workflows with infrastructure as code (Terraform)