Tetra Tech logo

DevOps Engineer​ (IDP/Keycloak SME)

Tetra Tech

Remotesenior$130k–$150kPosted 2h ago

Visa & sponsorship

  • US persons only (ITAR / export control): a legal requirement, not employer policy.
  • A US security clearance is required, which effectively means citizens only.

Job description

Job Description

The Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as an Identity Provider (IDP) Subject Matter Expert (SME) by providing advanced engineering, implementation, integration, and operational support for enterprise identity and access management (IAM) services. The engineer will serve as a subject matter expert for Keycloak, IDP technologies, and Login.gov integrations, helping design, deploy, secure, automate, and maintain identity services supporting cloud-hosted applications and platforms.

Salary is based on relative years of experience: $130,000 - $150,000

Job Duties & Responsibilities - Essential Job Functions may include (but are not limited to) the following:

The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions

  • Serve as a technical SME for Keycloak, Identity Provider (IdP), IAM, and Login.gov solutions supporting FAA cloud applications and services.

  • Design, deploy, configure, upgrade, and maintain Keycloak environments across development, test, staging, and production environments.

  • Configure and manage Keycloak realms, clients, roles, groups, users, service accounts, identity providers, authentication flows, and authorization policies.

  • Implement and support OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and JWT-based authentication.

  • Design and implement secure integrations between FAA applications and Login.gov for authentication and identity verification use cases.

  • Support applications integrating with Login.gov using OpenID Connect/OAuth 2.0 patterns.

  • Configure and troubleshoot Login.gov identity provider integrations, including client registration, redirect/return URLs, scopes, claims, authentication flows, and token handling.

  • Support integration between Login.gov, Keycloak, and FAA applications where federated identity or identity brokering is required.

  • Troubleshoot authentication issues involving Login.gov, Keycloak, application clients, tokens, claims, certificates, redirects, and federation.

  • Apply Login.gov integration and security requirements to application onboarding and deployment activities.

  • Support testing and validation of Login.gov integrations across development, test, staging, and production environments.

  • Coordinate with application teams and identity/security stakeholders to resolve Login.gov integration issues and ensure proper authentication flows.

  • Implement and support Single Sign-On (SSO) capabilities across cloud applications and enterprise services.

  • Support federation with enterprise directories and identity services, including LDAP/Active Directory and other authoritative identity sources.

  • Configure and manage identity federation, identity brokering, token exchange, identity mapping, claims, scopes, and protocol mappers.

  • Develop and maintain secure authentication and authorization patterns for applications operating within FAA cloud environments.

  • Implement role-based access control (RBAC) and least privilege access patterns.

  • Develop automated processes for Keycloak provisioning, configuration, deployment, and lifecycle management.

  • Use Terraform and Infrastructure as Code (IaC) to automate cloud infrastructure and identity platform configurations.

  • Integrate Keycloak and identity-related deployments into CI/CD pipelines and DevSecOps workflows.

  • Support containerized Keycloak deployments using Red Hat OpenShift/Kubernetes and cloud-native technologies.

  • Configure Keycloak for high availability, scalability, resilience, backup/recovery, and disaster recovery requirements.

  • Monitor identity platform performance, authentication activity, availability, logs, and system health.

  • Support certificate and key management associated with TLS, signing certificates, encryption, SAML, OIDC, and JWT-based integrations.

  • Implement security hardening for Keycloak and supporting identity infrastructure in accordance with FAA cybersecurity requirements and applicable federal security standards.

  • Support vulnerability remediation, patching, configuration management, and security assessments of identity services.

  • Integrate identity services with cloud security, logging, monitoring, and SIEM platforms.

  • Support cybersecurity teams with audit evidence, security assessments, compliance documentation, and remediation activities.

  • Participate in incident response and root-cause analysis for identity and authentication-related incidents.

  • Support change management activities, including technical analysis, implementation planning, testing, deployment, and validation.

  • Develop and maintain architecture documentation, configuration standards, deployment procedures, and troubleshooting guides.

  • Provide technical mentorship and guidance to junior engineers on IAM, Keycloak, Login.gov, authentication, authorization, and DevSecOps practices.

    Required Qualifications - A successful candidate will have

  • 6-10 years of experience in technology support, DevOps, or system administration roles.

  • Proficiency in Linux/Unix and Windows server administration.

  • Hands-on experience administering, engineering, and troubleshooting Keycloak or comparable enterprise IdP/IAM platforms.

  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, authentication, authorization, and identity federation.

  • Experience integrating identity services with enterprise applications and APIs.

  • Experience troubleshooting complex authentication and application integration issues.

  • Understanding of cybersecurity principles, secure configuration, vulnerability remediation, and access control.

  • Hands-on experience integrating applications with Login.gov.

Education

  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or related field (or equivalent experience).

Work Requirements and Additional Information

  • Work Location: Remote

  • Position is: Remote

  • Work Hours: 40

  • Travel: 0%

  • Background check: Must have the ability to obtain and maintain a public trust clearance, which requires U.S. citizenship.

  • Physical Requirements:

    • Extended Computer Use: Regular and prolonged periods of working at a computer terminal.

    • Mobility: Ability to move around the office environment to access computer hardware, networking equipment, and server rooms.

    • Dexterity: Manual dexterity and visual acuity to operate computer equipment, troubleshoot issues, and perform tasks requiring precision.

    • Sitting/Standing: Both prolonged sitting and occasional standing may be required for troubleshooting and attending to system issues.

  • Work Environment/Environmental Factors

    • Primarily computer-based work; meetings or collaboration may be required.

About LS Technologies

At LS Technologies, a Tetra Tech Company, we're enhancing our nation’s critical infrastructure by providing engineering, technical, and professional services to Federal Government agencies. The quality of our work, deep technical expertise, and genuine passion for public service sets us apart. As a growing organization we are expanding our benefits and communication with our employees, offering add-ons that speak to our growing employees’ needs. Join us in delivering high-quality solutions and shaping the future of safety and innovation for our government partners. In 2024 we joined Tetra Tech, enabling us to combine our expertise with the reach and resources of a prestigious global organization.

EEO Commitment

LS Technologies, a Tetra Tech Company, is proud to be an Equal Opportunity Employer. All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sex, marital or familial status, status as a protected veteran, or any other characteristic protected by law. Tetra Tech is a VEVRAA federal contractor, and we request priority referral of veterans.

We invite applications from all interested parties.

Requesting an Accommodation

LS Technologies is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by LS Technologies and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.

If you would like to be considered for employment opportunities with LS Technologies and have accommodation needs for a disability or religious observance, please send us an email hr@lstechllc.com or speak with your recruiter.

Compensation (Pay Bands)

Salary at LST is determined by a wide array of factors, such as (but not limited to) education, certifications, knowledge, skills, competencies, and experience, location, and clearance level, as well as contract-specific affordability and organizational requirements and applicable employment laws. Please note that the salary information is a general guideline only.

The projected compensation range for this position is provided within the posting and is based on full-time, 40 hour/week status. Part-time staff receive compensation at an hourly rate. The estimated minimum and maximum displayed represents the broadest range for this position (inclusive of high geographic and high clearance requirements) and is just one component of LSTs total compensation package for employees. ** In compliance with local laws, LS Technologies presents this reasonable compensation range as a guideline for roles in California, Colorado, New York, or Washington D.C."

Benefits offered to all employees who work 30+ hours per week: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Education Assistance, Parental Leave, Annual Leave, and Holidays.

Life at Tetra Tech:

  • The perks of working at Tetra Tech include:

  • Comprehensive and market-competitive benefits.

  • Merit-based financial rewards.

  • Flexibility and company-wide commitment to work/life balance.

  • Collaborative team atmosphere that values the contributions of all employees.

  • Learning and development opportunities for ongoing professional growth.

About Tetra Tech:

Tetra Tech is the leader in water, environment, and sustainable infrastructure, providing high-end consulting and engineering services for projects worldwide. With 30,000 employees working together, Tetra Tech provides clear solutions to complex problems by Leading with Science® to address the entire water cycle, protect and restore the environment, design sustainable and resilient infrastructure, and support the clean energy transition.

Explore our open positions at https://www.tetratech.com/careers. Follow us on social media to learn more about our people, culture, and opportunities:

LinkedIn: TetraTechCareers; X (Twitter): @TetraTechJobs

Additional Information

  • Organization: 230 LST