SME Systems Engineer (Cloud PKI)
Posted today
govcioFranconia (VA)
Computer Systems Engineers/ArchitectsComputer Systems Design Services
SENIORITY
Manager
SALARY
$172,000.00 /Yr
About the role
Overview: GovCIO is currently hiring a highly experienced SME Systems Engineer specializing in Credential Management (CM) with a primary focus on the Cloud Credential & Public Key Infrastructure (PKI) product area. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). This position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This position will be located in Alexandria, VA, and will be a hybrid position. Responsibilities: The SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include: Lead Modernize legacy access controls into robust, secure ICAM solutions. Manage enterprise directories, federation, authentication, authorization, and SSO protocols. Architect identity lifecycles, user provisioning workflows, and privilege management controls. Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs. Configure and manage enterprise-grade PKI systems, credentials, and authenticators. Implement logical and physical access control systems, including MFA, SSO, and PAM. Build federated identity services to enable secure interoperability with mission partners. Conduct technical root cause analysis, privilege audits, and system performance tuning. Develop custom technical interfaces, architectures, data flows, and compliance documentation. Provide advanced engineering and architecture ownership across the following specialization: Cloud Credential & PKI (Primary Product Area: Credential Management (CM)): Lead the engineering and management of the DigiCert Platform and cloud Hardware Security Modules (HSMs). Architect and create new enterprise certificate templates. Lead the engineering analysis and planning for future Yubikey integration to meet NIST AAL3 requirements. Serve as the final escalation point for all PKI-related outages or issues. Qualifications: High School with 10 years (or commensurate experience) Required Skills & Experience Certifications: DoD 8570 IAT Level II or higher (e.g., Security CE, CySA, or vendor-specific identity certifications). Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture. Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation. Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks. Clearance Level: Must have an active Secret clearance Preferred Skills & Experience Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs. Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls. Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI. Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards. USCG DICE Posted Salary Range: USD $135,000.00 - USD $172,000.00 /Yr.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
