Job Overview
CohesionForce is actively seeking candidates for a Trust and Identify Engineer to become part of our team in Huntsville, AL. This individual will design, implement, and support identity and access capabilities for users, applications, services, workloads, and AI-enabled systems. The engineer will work across platform, software, reliability, and customer teams to provide secure authentication, federation, authorization, credential management, and auditable access.
Responsbibilities include:
- Integrate Microsoft Entra ID, Active Directory, and other customer identity providers using OAuth 2.0, OpenID Connect, SAML, and LDAP-based technologies.
- Configure and support identity providers and authentication proxies such as Keycloak, oauth2-proxy, or equivalent products.
- Define stable claims, groups, roles, and application onboarding patterns.
- Design identity for Kubernetes workloads, services, automation, and AI agents using service accounts, short-lived tokens, service principals, certificates, or workload identity federation.
- Implement least-privilege access using RBAC, ABAC, policy as code, and centralized authorization services.
- Establish issuance, delivery, rotation, revocation, and recovery procedures for secrets, keys, tokens, and certificates.
- Automate identity configuration and validation using APIs, scripting, infrastructure as code, GitOps, and CI-CD.
- Troubleshoot login, token, claim, session, certificate, federation, and authorization issues across distributed systems.
- Define identity-related logging and tracing requirements and work with reliability engineers to support monitoring and incident resonse.
- Develop architecture documentation, integration guides, test procedures, runbooks, and customer handoff material.
Basic Qualifications
- Bachelor’s degree in an engineering, computer science, cybersecurity, infommation technology or a related discipline, or equivalent experience and combined education, with 5-10 years of experience, or relevant professional experience.
- Production experience with OAuth 2.0, OpenID Connect, JWTs, federation, token lifecycle, and secure application onboarding.
- Experience integrating Active Directory, Microsoft Entra ID, LDAP, SAML, or comparible enterprise identity systems.
- Experience with Kubernetes or OpenShift service accounts, RBAC, secrets, ingress, or service-mesh identity.
- Experience implementing identity for non-human services, workloads, or automation.
- Experience with fine-grained authorization, policy as code, API scopes, or external authorization services.
- Ability to automate configuration and testing with Python, PowerShell, or comparable language.
- Works well in a fast=paces collaborative team environment.– Must be willing to work onsite in a closed/classified area.