AWS Cloud Security and ICAM Specialist designing and managing secure authentication for cloud applications. Ensuring compliance with federal identity governance and cloud security principles.
Responsibilities
Supports the Case Management Modernization Program by designing, implementing, and managing secure authentication and authorization frameworks across cloud-based applications
Ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture principles within an AWS environment
Collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated across all layers of the application ecosystem
Designs and maintains the ICAM architecture for identity, access, and authentication management across AWS-hosted applications
Implements federated identity and single sign-on solutions using modern protocols
Collaborates with Cloud and Security Architects to enforce Zero Trust Architecture across microservices and APIs
Configures and maintains directory services and identity providers
Conducts access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
Provides subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
Supports ATO process by providing documentation and implementation plans
Collaborates with DevSecOps teams to embed ICAM policies within CI/CD pipelines
Requirements
10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required
Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
Hands-on experience with AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify for SSO and MFA implementations
Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
Experience implementing ICAM solutions in Agile and DevSecOps environments
Working knowledge of PKI, digital certificates, and encryption technologies
Strong analytical and troubleshooting skills with ability to resolve identity integration issues
Knowledge of AWS Container security and Network security
Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
Benefits
Comprehensive benefits and wellness packages
401K with company match
Paid time off
Full flex work weeks where possible
Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
GDIT Paid Family Leave program provides up to 160 hours of paid leave in a rolling 12 month period for eligible employees
Short and long-term disability benefits
Life, accidental death and dismemberment, and critical illness insurance
Desjardins property technician supporting fire prevention, building safety, management, and build - out projects. Providing technical support, process coordination, user training, and operational guidance.
Ingénieur sécurité principal protégeant l'infrastructure, les produits et les données de Shakepay, plateforme canadienne de services financiers bitcoin. Automatisation, IA, détection et réponse aux incidents.
Senior Application Security Researcher advancing AI - driven application security from prompt to production. Building detection systems and autonomous agentic penetration - testing capabilities.
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.