ICAM Policy Analyst
Job Description:
- Assess the current-state identity, credential, and access management (ICAM) environment, including systems, processes, and governance, to establish a clear baseline of existing capabilities
- Identify gaps between current-state ICAM capabilities and target-state requirements, including alignment with Zero Trust principles and maturity models
- Develop findings, risk-informed recommendations, and prioritized roadmaps to close identified gaps and advance ICAM and Zero Trust maturity
- Interpret and apply relevant federal policy, guidance, and frameworks, including the GSA FICAM Playbook, NIST SP 800-63, NIST SP 800-207, OMB M-22-09, HSPD-12, and FISMA
- Translate policy and framework requirements into actionable guidance for technical teams, program leadership, and agency stakeholders
- Support development of ICAM strategy documents, implementation plans, and governance artifacts, including policy briefs, assessment reports, and roadmaps
- Collaborate with engineering, cybersecurity, and program management teams
- Prepare written products and briefings for technical and executive audiences
- Monitor evolving federal identity and Zero Trust policy, guidance, and standards and assess program impacts
- Support identity-related governance and compliance activities, including control assessments, audits, and reporting
Requirements:
- Bachelor's degree in Information Technology, Cybersecurity, Public Policy, or a related field, and 4+ years of relevant experience; or 6+ years of relevant experience in lieu of a degree
- Demonstrated experience with identity, credential, and access management (ICAM) programs, cybersecurity policy, or federal IT policy and compliance
- Working knowledge of GSA's FICAM Playbook and its application to agency ICAM programs
- Familiarity with Zero Trust principles and frameworks, including NIST SP 800-207 and OMB's Federal Zero Trust Strategy (M-22-09)
- Understanding of federal identity and security guidance, including NIST SP 800-63, HSPD-12, and FISMA
- Experience assessing current-state environments, performing gap analyses, and developing practical recommendations and roadmaps
- Strong analytical, critical-thinking, and problem-solving skills, with the ability to synthesize policy and technical information
- Excellent written and verbal communication skills, with experience briefing both technical staff and program/agency leadership
- Ability to work collaboratively with technical, policy, and program stakeholders across a government engagement
- Must be eligible to obtain a Public Trust government security clearance
- Prior experience directly supporting a federal ICAM, Zero Trust, or identity governance program
- Relevant certification such as CAP, CISSP, or CISA
- Familiarity with NIST SP 800-53 security controls and their intersection with identity and access management
Benefits: