Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Wood River Federal

ICAM Policy Analyst

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
85
out of 100
Average of individual scores

Were these scores useful?

Job Description

Position Overview The Identity, Credential, and Access Management (ICAM) Policy Analyst is responsible for evaluating, developing, and aligning enterprise ICAM policy frameworks, governance structures, and security standards. This role bridges technical identity architecture and regulatory compliance across complex federal, defense, or enterprise environments. The ICAM Policy Analyst ensures that identity lifecycle management, digital identity standards, access control models, and Zero Trust Architecture mandates are fully compliant with federal directives, defense standards, and NIST guidelines.
Key Responsibilities:
Draft, review, update, and operationalize enterprise-level ICAM governance documents, strategic roadmaps, policy directives, and Standard Operating Procedures (SOPs). Align agency identity policies with federal mandates, including
OMB M-22-09, OMB
M-19-17, Executive Order 14028, HSPD-12, NIST
SP 800-63
(Digital Identity Guidelines), NIST SP 800-53, and DoD ICAM strategies. Provide policy oversight and compliance guidance for technical capabilities including
PKI, PIV/CAC
integration, Single Sign-On (SSO), Federated Identity (SAML, OIDC/OAuth 2.0), Privileged Access Management (PAM), and Identity Governance and Administration (IGA). Evaluate access control policies (Attribute-Based Access Control / ABAC and Role-Based Access Control / RBAC) to ensure policy definitions directly support Zero Trust Architecture (ZTA) pillars and micro-segmentation strategies. Perform gap analyses, policy reviews, and risk assessments on legacy and emerging systems to identify compliance shortfalls relative to federal identity standards and security baselines. Lead policy working groups, inter-agency ICAM forums, and consensus-building sessions with enterprise architects, cybersecurity officers, system owners, and program managers. Prepare compliance artifacts, policy briefs, decision memos, and executive presentations for agency leadership, inspectors general, or external audit bodies.
Required Qualifications:
Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Public Policy, Management Information Systems (MIS), or a related field. Minimum of two (2) years of professional experience directly supporting identity management policy development, governance, or cybersecurity compliance in government or defense environments. Must possess an active U.S. Government Security Clearance (Secret clearance required). Exceptional written communication and policy-drafting skills. Strong consensus-building, analytical, and executive presentation capabilities.
Technical & Policy Framework Expertise:
Deep familiarity with federal ICAM directives and frameworks:
OMB M-22-09, OMB M-19-17, NIST SP 800-63
(all sub-volumes), NIST
SP 800-53, FIPS
201, and HSPD-12. Applied understanding of core identity components: PKI, MFA, Federation, SAML, OIDC, IGA, PAM, and Directory Services (Active Directory/Entra
ID, LDAP
). Hands-on experience translating high-level regulatory mandates into actionable policy statements, security baselines, and operational governance frameworks. Direct experience supporting Federal ICAM (FICAM) or DoD ICAM architecture and policy implementations. Understanding of cloud identity management policies (AWS IAM, Azure Entra ID, Google Cloud IAM) and hybrid identity topologies. Familiarity with dynamic access control frameworks (ABAC, Policy Decision Points / Policy Enforcement Points). Experience working within the Risk Management Framework process (e.g., EMASS, accreditation packages, PO&Ms, etc.)