See all roles

[Remote] AWS Cloud Infrastructure Engineer (Keycloak Specialty)

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. GDIT is a global technology and professional services company that delivers consulting and technology services to major U.S. government agencies. They are seeking a Senior AWS Cloud Infrastructure Engineer specializing in Keycloak to support the Case Management Modernization Program by designing and managing secure authentication frameworks in a cloud environment while ensuring compliance with federal standards.

Responsibilities

  • Design and maintain the identity architecture utilizing Keycloak
  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , KeyCloak)
  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
  • Design identity solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
  • Develop and document identity lifecycle management processes—provisioning, deprovisioning, and access reviews
  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and KeyCloak
  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
  • Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
  • Design and implement storage level, microservice level Authentication and Authorization
  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
  • Participate in design sessions and work closely with the security lead
  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
  • Direct and lead Pen testing, Review architecture diagrams produced by different teams
  • Independently lead design and implement of vulnerability management
  • Lead and direct engineering team

Skills

  • Bachelor's Degree in Cybersecurity, Information Systems, or equivalent experience required
  • 10+ years of experience in identity and access management, including 8+ years in cloud-based environments required
  • Hands-on experience with KeyCloak and AWS IAM Identity Center for SSO and MFA implementations
  • Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
  • Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
  • Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
  • Experience implementing ICAM solutions in Agile and DevSecOps environments
  • Working knowledge of PKI, digital certificates, and encryption technologies
  • Strong analytical and troubleshooting skills with ability to resolve identity integration issues
  • Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
  • Experience supporting digital modernization or judiciary IT programs
  • Familiarity with Zero Trust Architecture and micro segmentation principles
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
  • Demonstrated ability to work effectively, independently, and as part of a team
  • AWS Certified Solutions Architect - Professional | Hirecrafto Web Services (AWS) - Tasknexa Web Services (AWS)
  • Master's Degree
  • 12+ years of experience in information systems
  • IBM Verify a plus
  • Experience with AWS Container Security and Network Security
  • AWS Certified Solutions Architect - Associate or Professional
  • Certified Information Systems Security Professional (CISSP)
  • AWS Certified Security – Specialty or Azure Identity & Access Administrator
  • Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP)
  • SAFe Practitioner (SPC/SSM)

Benefits

  • A variety of medical plan options, some with Health Savings Accou

Apply tot his job Apply To this Job

You might like

AWS Cloud Infrastructure Engineer - RPA Operations (REMOTE)

Work from home Full-time role

AWS Engineer - Fully Remote

Work from home Full-time role

[Remote] AWS Connect Engineer/Flexzenith Connect Developer - $77 on 1099 / $67 W2 - REMOTE

Work from home Full-time role

[Remote] AWS Cloud/Infrastructure Engineer/Architect

Work from home Full-time role

Senior Full Stack AWS Engineer- Virtual

Work from home Full-time role

Full-Time :: Local to the NY / NJ / PA (Remote) :: AWS DevOps Engineer (Only G.C / U.S.C)

Work from home Full-time role

Vmware Cloud on Aws (vmc on Aws) Engineer/remote

Work from home Full-time role

Looking for an experienced AWS engineer to help me set up AWS Health Imaging (AHI) infrastructure

Work from home Full-time role

Senior AWS DevOps Engineer - Remote - USA

Work from home Full-time role

Senior AWS Cloud Engineer (IaC/Networking)

Work from home Full-time role

Experienced Customer Service Representative – Remote Opportunity at arenaflex

Work from home Full-time role

Experienced Customer Service Representative – Remote Support for arenaflex

Work from home Full-time role

Experienced Part-Time Data Entry Specialist – Remote Work Opportunity at arenaflex

Work from home Full-time role

Remote Data Entry & IT Support Technician – Full‑Time, $26/hr, Work‑From‑Home – arenaflex

Work from home Full-time role

Experienced Remote Data Entry Specialist – Flexible Work Schedule and Competitive Compensation

Work from home Full-time role

Experienced Remote Data Entry Specialist – Logistics and Shipping Operations

Work from home Full-time role

Bilingual NLP Engineer (Japanese)- Remote

Work from home Full-time role

Arabic Audio Annotation Analyst - Egypt

Work from home Full-time role

Creative Director (or, Lead Writer of Interesting Things)

Work from home Full-time role

Director of Client Marketing Services, Agency (health tech, biotech)

Work from home Full-time role