Technical Lead
Description
Technical Lead – ICAM Modernization (PDP, PEP/PIP, EMS & RPMS Modernization)
This position is considered a limited time position of around 7 months with the possibility of going longer.
General program information and/or position overview:
The Geospatial Intelligence Access and Information Sharing (GEOAxIS) system provides Identity, Credential, and Access Management (ICAM) services for all National Geospatial-Intelligence Agency (NGA) enterprise web applications. GEOAxIS enables secure, attribute-driven access to Geospatial Intelligence (GEOINT) content across security domains using authoritative identity data and enterprise roles. Our mission is to deliver reliable, modernized ICAM services that protect critical mission applications while supporting NGA’s evolving Zero Trust architecture (ZTA).
GEOAxIS is executing a major modernization initiative to upgrade legacy ICAM components including Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS) with state-of-the-art, cloud-ready, vendor and open-source technologies.
The Technical Lead role will guide engineering teams responsible for modernizing authorization services, attribute orchestration, resource/policy management, and enforcement capabilities across NGA systems. This position ensures that Development and Operations (DevOps), Software Engineering, and Mission Integration teams remain aligned throughout the modernization effort, reducing operational overhead while enabling future innovation. This position is a short‑term assignment with an expected duration of seven months, with the possibility of extension based on performance.
Primary Responsibilities:
• Lead the modernization of NGA’s ICAM PEP/PIP/EMS and RPMS components from legacy commercial off the shelf (COTS) products to modern, scalable, vendor and open-source technologies. Transition from the legacy PDP to JBlocks.
• Drive engineering strategy for modern Policy Enforcement Point integrations, enterprise attribute distribution, and centralized policy/resource management capabilities.
• Facilitate strong collaboration between Development and Operations (DevOps), Software, and Systems Engineering teams to ensure seamless integration of authorization, policy, and identity services.
• Partner with program management to ensure technical execution aligns with customer requirements, modernization milestones, and mission priorities.
• Guide the architectural design of secure, resilient ICAM microservices, including attribute services, role lifecycle automation, resource registration, and policy ingestion/distribution.
• Ensure modernization efforts improve operational efficiency, reduce maintenance complexity, and support future ZT capabilities.
• Lead planning, readiness reviews, backlog refinement, and Program Increment (PI) execution across multi-disciplinary teams.
• Provide technical leadership during integration testing, troubleshooting, and deployment activities across security domains.
• Mentor engineers and promote innovation in automation, DevSecOps, and identity-centric development practices.
Basic Qualifications:
• Master’s degree in a Science, Technology, Engineering, and Mathematics (STEM) field and 5+ years of relevant experience, or Bachelor’s degree and 10+ years of experience.
• Experience serving as a Scrum Master, Release Train Engineer (RTE), Product Owner, or comparable leadership role.
• Significant experience providing technical/management leadership for complex modernization or enterprise security/identity initiatives.
• Proven experience leading cross-functional teams delivering software and infrastructure capabilities using Agile methodologies.
• Demonstrated ability to define technical goals, architecture direction, and plans that meet large‑scale project objectives.
• Ability to obtain Security+ within 90 days of hire.
Preferred Qualifications:
• Experience with Kubernetes or OpenShift platforms.
• Hands-on experience developing or integrating services using Java or Python.
• Familiarity with GitOps tools.
• Certifications in Amazon Web Services (AWS), Kubernetes, Linux, or related technologies.
• Experience with enterprise identity standards (X.509, SAML, OAuth2, OIDC, LDAP).
• Experience with Oracle products or similar ICAM/authorization technologies.
• Knowledge of modern ICAM authorization patterns: ABAC, RBAC, policy-based access control, microservice-friendly PEP/PIP designs.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
August 7, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $131,300.00 - $237,350.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
