AWS Cloud Security and ICAM Specialist designing and managing secure authentication for cloud applications. Ensuring compliance with federal identity governance and cloud security principles.
Responsibilities
Supports the Case Management Modernization Program by designing, implementing, and managing secure authentication and authorization frameworks across cloud-based applications
Ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture principles within an AWS environment
Collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated across all layers of the application ecosystem
Designs and maintains the ICAM architecture for identity, access, and authentication management across AWS-hosted applications
Implements federated identity and single sign-on solutions using modern protocols
Collaborates with Cloud and Security Architects to enforce Zero Trust Architecture across microservices and APIs
Configures and maintains directory services and identity providers
Conducts access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
Provides subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
Supports ATO process by providing documentation and implementation plans
Collaborates with DevSecOps teams to embed ICAM policies within CI/CD pipelines
Requirements
10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required
Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
Hands-on experience with AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify for SSO and MFA implementations
Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
Experience implementing ICAM solutions in Agile and DevSecOps environments
Working knowledge of PKI, digital certificates, and encryption technologies
Strong analytical and troubleshooting skills with ability to resolve identity integration issues
Knowledge of AWS Container security and Network security
Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
Benefits
Comprehensive benefits and wellness packages
401K with company match
Paid time off
Full flex work weeks where possible
Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
GDIT Paid Family Leave program provides up to 160 hours of paid leave in a rolling 12 month period for eligible employees
Short and long-term disability benefits
Life, accidental death and dismemberment, and critical illness insurance
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.