Overview In this role you will lead enterprise ICAM strategy, design, and governance for VA, focusing on secure access, zero-trust principles, and compliant IAM tooling. You'll direct multi-team ICAM programs, partner with senior stakeholders, and drive architecture decisions across SSO, IGA, PAM, and directory services. The position emphasizes collaboration, modernization, and leveraging automation and AI to improve efficiency and security. A strong hook is shaping critical identity solutions that protect veterans and their data at scale.
Compensation / Benefits- health, life, disability benefits
- retirement benefits
- paid leave
- professional development and tuition assistance
- work-life programs
- dependent care
Responsibilities- Design and direct the enterprise ICAM target-state architecture across SSO (Entra ID, Okta), IGA (Saviynt), PAM (CyberArk, PAMaaS), Master Person Index, and Enterprise Workforce Directory
- Own security architecture engineering, security strategy, and regulatory compliance alignment (STIGs, FIPS, NIST 800-53) across the VA ICAM portfolio
- Lead architecture reviews, technical validation, and vendor evaluations for Innovation Lab sessions and technology stack decisions
- Lead multiple Kanban Agile support teams in a large Scaled Agile (SAFe) environment; co-lead quarterly increment planning
- Partner with senior government stakeholders, ICAM program owners, and C-suite executives on architecture discussions
- Support DoW and other external partner federation architecture efforts
- Leverage AI to improve efficiency and output; automate tasks where appropriate
- Develop consistent ways of working to assist agents and automated processes
Key requirements- Experience designing and directing enterprise-scale ICAM strategy, implementation, and governance including Zero Trust, cloud security, and compliance
- Experience leading integration of SSO, MFA, PAM, and directory services as an enterprise SME
- Experience with security architecture, RBAC or Access Certification implementation, and identity or role lifecycle management
- Knowledge of Federal ICAM mandates such as OMB M-19-17, NIST 800-63, EO 14028, and OMB M-22-09
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination
- Bachelor's degree
- CISSP Certification or Cyber/Identity Certification (e.g., AWS Certified Cloud Practitioner, ICAgile, or CyberArk)
- Stakeholder communication and collaboration with government and executive teams
- Strategic thinking and leadership in cross-functional environments
- Vendor evaluation and decision-making across a complex tech stack
- SSO (Entra ID, Okta)
- IGA (Saviynt)
- PAM (CyberArk, PAMaaS)