CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
ICAM Administrator
Job Title: Identity, Credential, and Access Management (ICAM) Administrator
Reports To: ICAM Manager / IT Operations Manager
Department: Information Technology - Identity & Access Management
Location: [Remote] - Must live within 50 miles from Washington DC
Employment Type: Full-Time
Clearance: Active Public Trust
Salary: 5-8 YOE - $80-90K; 8+ YOE - $90-105K
Position Summary
We are seeking an experienced ICAM Administrator to support enterprise Identity, Credential, and Access Management services across our on-premises, cloud, and hybrid environments. This role is responsible for managing user and service account lifecycles, configuring and maintaining directory services, implementing access controls, and ensuring compliance with organizational security policies. The ideal candidate will have hands-on experience with Active Directory, Microsoft Entra ID (Azure AD), PowerShell scripting, and enterprise identity platforms. This position plays a critical role in maintaining secure, compliant access to organizational resources while supporting business continuity and security initiatives.
Primary Responsibilities
Account & Identity Lifecycle Management
-
Support identity account provisioning, modification, and deprovisioning activities in accordance with established security policies
-
Perform user and service account lifecycle management tasks, including creation, enablement, modification, disabling, and removal of accounts across supported systems
-
Execute account lifecycle management activities with proper tracking in ticketing or audit systems
-
Identify inactive, non-compliant, or orphaned accounts and escalate findings to support audit, compliance, and cybersecurity requirements
-
Maintain accurate records and audit trails to support compliance reporting, security reviews, and access audits
Directory Services Administration
-
Operate, maintain, and sustain enterprise directory services including Active Directory and Microsoft Entra ID in support of on-premises, cloud, and hybrid environments
-
Manage group policies, organizational units (OUs), and directory structure optimization
-
Configure and maintain role-based access control (RBAC) across directory services
-
Troubleshoot complex authentication and identity-related issues
-
Implement approved configuration changes across directory and SSO platforms
Access Management & Multi-Factor Authentication (MFA)
-
Administer and monitor single sign-on (SSO) and federation services across enterprise systems
-
Manage PIV-based and cloud-based multi-factor authentication (MFA) implementations
-
Monitor and enforce conditional access policies and security baselines
-
Support authentication protocols and access-based assignments
-
Manage privileged access management (PAM) activities and ensure least-privilege principles are maintained
PowerShell Automation & Scripting
-
Develop and maintain PowerShell scripts and automation workflows to streamline account provisioning, modifications, and deprovisioning processes
-
Create scripts for bulk account operations, compliance audits, and reporting
-
Automate routine identity management tasks to improve efficiency and reduce manual errors
-
Document all scripts and automation procedures for knowledge transfer and maintenance
-
Support integration between identity platforms using PowerShell-based solutions
Monitoring & Operations
-
Monitor ICAM request queues, respond to tickets and escalations in accordance with defined Service Level Agreements (SLAs)
-
Generate and review ICAM operational reports, metrics, and performance indicators
-
Maintain security event logs and audit trails for compliance and incident investigation
-
Escalate critical issues to senior engineers and security teams appropriately
Compliance & Security
-
Ensure ICAM operations remain compliant with regulatory requirements (NIST, FISMA, HSPD-12, SOC 2, etc.)
-
Support security audits and compliance reviews by providing accurate documentation and evidence
-
Participate in identity governance initiatives and access reviews
-
Maintain confidentiality and security of sensitive credential information
-
Support incident response activities related to identity compromise or unauthorized access
Documentation & Knowledge Management
-
Maintain comprehensive documentation of identity management processes, configurations, and procedures
-
Create and update standard operating procedures (SOPs) for routine ICAM operations
-
Contribute to knowledge base articles and troubleshooting guides
-
Support training of junior staff and new team members
Required Qualifications & Experience
Education
-
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field; OR equivalent professional experience in enterprise identity/access management
Experience
-
5+ years of demonstrated experience in enterprise identity, directory services, or access management roles
-
3+ years of hands-on experience with Active Directory (AD) administration in Windows Server environments
-
2+ years of demonstrated experience with Microsoft Entra ID (Azure AD) or similar cloud identity platforms
-
2+ years of PowerShell scripting experience for identity management automation and system administration
-
Proven experience performing user and service account provisioning, modification, and deprovisioning using documented procedures
-
Demonstrated ability to manage access requests, incidents, and tasks using IT Service Management (ITSM) or ticketing systems while meeting SLAs
-
Experience supporting or administering additional identity platforms such as Okta, Okta Single Sign-On, LDAP, or SAML-based systems
-
Hands-on experience with Group Policy Objects (GPOs), organizational units (OUs), and group management
Technical Skills & Certifications
Required:
-
Advanced proficiency in Active Directory administration
-
Strong experience with Microsoft Entra ID (Azure AD) implementation and management
-
Expert-level PowerShell scripting and automation capabilities
-
Deep understanding of authentication protocols (Kerberos, OAuth 2.0, SAML, OpenID Connect)
-
Knowledge of role-based access control (RBAC) implementation
-
Experience with Windows Server environments (DNS, DHCP, Certificate Services)
Preferred:
-
Microsoft Certified: Identity and Access Administrator Associate (SC-300)
-
Microsoft Certified: Azure Administrator (AZ-104)
-
MCSA: Windows Server certification
-
Certified Information Systems Security Professional (CISSP) or similar
-
Experience with Okta, Ping Identity, or other enterprise IAM platforms
-
Familiarity with PIV/smartcard integration and credential management systems
-
Experience with Zero Trust architecture and conditional access policies
Core Competencies & Attributes
-
Problem-Solving: Ability to analyze complex identity and access issues, identify root causes, and implement effective solutions
-
Attention to Detail: Meticulous approach to account management, configuration changes, and security procedures
-
Communication Skills: Clear written and verbal communication with technical and non-technical stakeholders
-
Reliability: Ability to work independently while maintaining 24x7 operational support posture
-
Security Mindset: Strong commitment to security best practices and compliance requirements
-
Adaptability: Comfortable learning new technologies and identity management platforms
-
Time Management: Ability to prioritize tasks and manage multiple requests while meeting SLAs
-
Documentation: Strong ability to document procedures, configurations, and troubleshooting steps clearly
-
Collaboration: Works effectively with cross-functional teams including security, compliance, and application teams
Work Environment & Physical Requirements
-
hybrid, or remote position (as applicable)
-
Ability to participate in on-call rotation for 24x7 support environments
-
Valid government-issued ID required for facility access (if applicable)
-
Security clearance may be required for government or regulated industry contracts
-
Ability to maintain focus on detail-oriented tasks for extended period