Arlington, VA

Salary
Posted
Jul 21, 2026
Location
Arlington, VA
Last confirmed open
Jul 24, 2026

What this job asks for AI summary

This role centers on building and sustaining a government Identity-as-a-Service platform that supports Zero Trust and cross-domain security architectures. Day-to-day work involves deploying and integrating ForgeRock identity components, managing CI/CD pipelines and configuration-as-code, and implementing enterprise identity protocols such as SAML, OAuth2, and OIDC. It suits an experienced systems engineer with an active Top Secret/SCI clearance and a background in ICAM, DevSecOps, and DoD compliance frameworks.

Senior level · 8+ years · TS/SCI clearance · Full-time

Must have (8)
ForgeRockSAMLOAuth2OpenID ConnectLinuxWindowsShell scriptingSSO
Nice to have (4)
AWSAnsibleGitLab or JenkinsCI/CD

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
OpenID Connect5%SAML6%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Linux75%Shell scripting70%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $101,310 (middle half $79,725–$129,425).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

No work location is specified in the posting; the role supports a government customer in secure environments, which strongly implies an on-site or classified-facility requirement — remote=false is assumed.

The title carries no seniority level word; the title states no level. The 8+ years requirement and mission-critical scope support a Senior classification.

The role is genuinely ambiguous between 15-1244 (operating/administering identity infrastructure — ForgeRock AM/IDM/DS, directory services, Linux systems) and 15-1212 (security analysis — Zero Trust, RMF, ATOs, ICAM security). The primary day-to-day work described — engineering, deploying, administering, and sustaining the ForgeRock/IDaaS platform — leans toward 15-1244, with 15-1212 as a close runner-up.

The posting requires a CI Polygraph in addition to TS/SCI eligibility; the clearance requirement is set to TopSecretSci as the closest available value — the poly requirement cannot be represented in this field.

Degree requirement is set to None because the JD explicitly accepts 'equivalent experience in lieu of degree.'

IAT II certification (Security+, CySA+, GICSP, GSEC, or SSCP) is a hard gate but names no specific technology tool, so it is not emitted as a skill.

JISG Access Controls, API gateway/identity orchestration, and cross-domain service integration patterns appear under the 'preferred' block and are either non-canonical tool names or methodology phrases, so they are not emitted as discrete skills.

Zero Trust is a framework/architecture concept rather than a named tool and is omitted from the skills list per the generic-concept rule.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗