Identity and Access Management Specialist II
Location: Rockville, MD — Onsite ( 5 days Onsite)
Travel: Approximately 10%–15%
Clearance: Ability to obtain and maintain a Public Trust Tier 2 background investigation and HHS PIV credential
Sponsorship: No sponsorship assistance is available for this position.
Position Overview
LCG is seeking an Account Manager to support enterprise identity, access, and account-management operations within the Health Resources and Services Administration’s secure federal IT environment.
This position supports more than 3,100 active enterprise user accounts across Microsoft Active Directory, Microsoft Entra ID, Okta, and SailPoint Identity Governance. The specialist will ensure that account provisioning, access changes, authentication support, account termination, and compliance reporting are completed accurately, securely, and in accordance with HRSA, HHS, and federal security requirements.
The successful candidate will serve as a dedicated resource for daily account-management operations and work closely with federal IAM administrators, DEUS leadership, system owners, and the Contracting Officer’s Representative. The role will also help improve account-management processes through PowerShell scripting, ServiceNow automation, Entra ID workflows, Okta Workflows, and other identity automation capabilities.
Key Responsibilities
Identity and Access Management
- Administer and maintain user accounts across Microsoft Active Directory, Microsoft Entra ID, and Okta.
- Process employee and contractor account requests in accordance with approved onboarding documentation, ServiceNow tickets, and established standard operating procedures.
- Create, modify, disable, and terminate user accounts throughout the full identity lifecycle.
- Grant access to approved systems, applications, shared mailboxes, distribution lists, security groups, and enterprise resources.
- Update account attributes, group memberships, license assignments, roles, and access permissions based on approved requests.
- Verify that all account-management actions are properly authorized before provisioning, modifying, or removing access.
- Troubleshoot account lockouts, password issues, multifactor authentication failures, synchronization problems, attribute errors, and smart card or PIV authentication issues.
- Support hybrid identity environments involving Active Directory, Entra ID, Microsoft 365, and Okta.
- Escalate terminated, suspended, disabled, or otherwise restricted account issues to the appropriate federal IAM administrator.
- Ensure no account-management action is performed outside approved procedures or authorization channels.
Identity Governance and Access Controls
- Support SailPoint Identity Governance as a managed enterprise service.
- Troubleshoot user-access issues and interpret identity provisioning, certification, and access-review results.
- Coordinate with federal and NIH identity administrators when issues require escalation.
- Assist with the development and implementation of role-based access control models.
- Support birthright provisioning approaches that standardize baseline permissions and improve onboarding efficiency.
- Help identify excessive, outdated, conflicting, or inappropriate user access.
- Support remediation activities directed by system owners or federal IAM administrators.
PowerShell and Workflow Automation
- Develop, test, document, and maintain PowerShell scripts for account creation, modification, deprovisioning, group administration, and compliance reporting.
- Automate onboarding, offboarding, account modification, and access-management workflows.
- Support automation using PowerShell, Microsoft Entra ID, Okta Workflows, and ServiceNow workflows.
- Develop automated reports covering provisioning status, deprovisioning activity, access changes, inactive accounts, and compliance exceptions.
- Identify manual account-management processes that can be improved through automation.
- Ensure scripts and automated workflows include appropriate controls, validation, documentation, and error handling.
Account Recertification and Audit Support
- Conduct quarterly account reviews for assigned systems.
- Compile current users, assigned roles, access permissions, and last-access information.
- Identify inactive, orphaned, duplicate, or potentially inappropriate accounts based on HRSA requirements.
- Provide review findings and recommended corrective actions to system owners.
- Implement approved account modifications or removals.
- Improve the accuracy and efficiency of recertification activities through automation.
- Prepare the Quarterly Account Recertification Report, including findings, inactive accounts, exceptions, and completed corrective actions.
Process Management and Continuous Improvement
- Develop and maintain policies, procedures, standard operating procedures, work instructions, and technical documentation for account-management activities.
- Review and update account-management documentation at least twice annually.
- Collaborate with federal subject-matter experts to identify workflow improvements and automation opportunities.
- Assess the current account-management environment to identify bottlenecks, control gaps, and inefficient manual processes.
- Document recommendations for OIT and DEUS leadership review.
- Prepare the Bi-Annual Process Assessment Report summarizing automation opportunities, expected efficiency gains, and proposed procedural updates.
- Promote consistent identity-management practices across the support organization.
ServiceNow and Enterprise IT Operations
- Record all account-management, authentication-support, and identity-related activities in ServiceNow.
- Maintain complete, accurate, and properly categorized incident, request, change, and CMDB records.
- Ensure requests that arrive outside ServiceNow are entered into the system before work proceeds.
- Support identity-related issues involving Microsoft 365, Teams, Exchange, SharePoint, OneDrive, VPN access, Zscaler connectivity, and network authentication.
- Coordinate escalations with the DEUS IAM Team, HHS OCIO IAM, NIH CIT Service Desk, desktop engineering, network operations, and other technical teams.
- Provide timely status updates and maintain clear documentation throughout the ticket lifecycle.
- Contribute account-management updates to recurring DEUS reports and weekly presentations.
Security and Compliance
- Perform all identity and account-management activities in accordance with HRSA security policies, HHS Information Security and Privacy Policy, HSPD-12, and applicable federal cybersecurity standards.
- Verify the identity of users requesting password, access, MFA, or authentication assistance before taking action.
- Follow federal privacy and security procedures when handling user information and access requests.
- Support identity-related security incident response, vulnerability remediation, and compliance activities.
- Maintain appropriate documentation and evidence for account-management actions, access reviews, and audits.
- Protect sensitive identity, access, and authentication information throughout all support activities.
- Ensure account provisioning and deprovisioning activities are completed accurately and within required timeframes.
Functional Guidance and Knowledge Sharing
- Serve as a subject-matter resource for identity and account-management questions from DEUS support staff.
- Provide functional guidance to Desktop Support Technicians on account-related troubleshooting, PIV authentication, escalation procedures, and ServiceNow documentation.
- Train and mentor support personnel on identity-management procedures and approved support boundaries.
- Coordinate with the Program Assistant on quarterly recertification tracking, reporting inputs, and deliverable preparation.
- Escalate issues beyond the position’s authorized scope to the appropriate federal administrator.
Required Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or an equivalent combination of education and relevant experience.
- Minimum of three years of experience supporting enterprise identity and access management environments.
- Hands-on experience administering:
- Microsoft Active Directory
- Microsoft Entra ID, formerly Azure Active Directory
- Okta
- Demonstrated experience with enterprise user lifecycle administration, including provisioning, access changes, group administration, license assignment, and deprovisioning.
- Proficiency in PowerShell scripting for user, group, access, and reporting automation.
- Experience supporting SailPoint Identity Governance or a comparable identity governance platform.
- Understanding of role-based access control and birthright provisioning concepts.
- Experience troubleshooting authentication, MFA, synchronization, access, and user-account issues.
- Experience using ServiceNow or a comparable IT service-management platform.
- Strong documentation, reporting, analytical, and problem-solving skills.
- Ability to communicate effectively with technical teams, federal stakeholders, system owners, and end users.
- Ability to obtain and maintain a federal Public Trust Tier 2 background investigation and HHS PIV credential.
- Ability to work onsite at HRSA Headquarters in Rockville, Maryland.
- Ability to travel approximately 10%–15%, including occasional travel to regional offices and Baton Rouge, Louisiana.
Certification Requirement
Candidates must hold at least one of the following certifications:
- CompTIA Security+
- ITIL 4 Foundation
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
Preferred Qualifications
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Microsoft Certified: Windows Server Hybrid Administrator Associate.
- Okta Certified Administrator or Okta Certified Professional.
- CompTIA Network+.
- CompTIA CySA+.
- Tanium Certified Operator.
- CISSP, particularly for candidates with more senior-level experience.
- Experience supporting identity and access management within an HHS, HRSA, NIH, or other federal environment.
- Familiarity with HSPD-12, PIV credential management, HHS IS2P, and federal identity-management requirements.
- Experience conducting access certifications, account recertification reviews, and remediation activities.
- Experience integrating PowerShell automation with ServiceNow, Entra ID, Okta, or other identity platforms.
- Experience creating formal compliance, audit, operational, or process-assessment reports.
- Familiarity with Microsoft Intune, Tanium, Zscaler ZIA/ZPA, and Microsoft 365 administration.
Tools and Technologies
The selected candidate may work with technologies including:
- Microsoft Active Directory
- Microsoft Entra ID
- Okta
- SailPoint Identity Governance
- PowerShell
- Okta Workflows
- Microsoft Entra automation
- ServiceNow incident, request, change, CMDB, workflow, and reporting modules
- Microsoft 365
- Microsoft Teams
- Exchange and Outlook
- SharePoint and OneDrive
- Zscaler ZIA/ZPA
- Microsoft Intune
- Tanium
- Microsoft Excel and PowerPoint
- ServiceNow dashboards and reporting tools
Tools and technologies may evolve based on client and program requirements. The successful candidate must be comfortable learning new platforms and adapting to changing federal IT needs.
Compensation and Benefits
The projected compensation range for this position is $108,000 to $130,000 per year benchmarked in the Washington, D.C. metropolitan area. The salary range provided is a good faith estimate representative of all experience levels. Salary at LCG is determined by various factors, including but not limited to role, location, the combination of education/training, knowledge, skills, competencies, certifications, and work experience.
LCG offers a competitive, comprehensive benefits package which includes health insurance options (medical, dental, vision), life and disability insurance, retirement plan contributions, as well as paid leave, federal holidays, professional development, and lifestyle benefits.
Devoted to Fair and Inclusive Practices
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.
If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact our Human Resources department by email at
hr@lcginc.com
.
Securing Your Data
Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advancement of money during the application process. Legitimate communication will only come from lcginc.com or
system@hirebridgemail.com
emails, not free commercial services like Gmail or WhatsApp. If you receive suspicious emails asking for payment or personal information, contact us immediately at
hr@lcginc.com
.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Use of Artificial Intelligence in Recruiting
LCG may use artificial intelligence (AI) and other automated technologies to support portions of the recruiting and hiring process, including resume review, candidate matching, interview scheduling, skills assessment, and other administrative functions. AI-assisted tools are used solely to support our hiring process and do not independently determine employment outcomes. Final hiring decisions are made by trained hiring professionals following a comprehensive review of each candidate's qualifications. We are committed to equal employment opportunity and strive to ensure our hiring practices are fair, transparent, and compliant with applicable laws. Applicants needing a reasonable accommodation during the application or interview process should contact Human Resources.
Identity and Access Management Specialist II
Location: Rockville, MD — Onsite ( 5 days Onsite)
Travel: Approximately 10%–15%
Clearance: Ability to obtain and maintain a Public Trust Tier 2 background investigation and HHS PIV credential
Sponsorship: No sponsorship assistance is available for this position.
Position Overview
LCG is seeking an Account Manager to support enterprise identity, access, and account-management operations within the Health Resources and Services Administration’s secure federal IT environment.
This position supports more than 3,100 active enterprise user accounts across Microsoft Active Directory, Microsoft Entra ID, Okta, and SailPoint Identity Governance. The specialist will ensure that account provisioning, access changes, authentication support, account termination, and compliance reporting are completed accurately, securely, and in accordance with HRSA, HHS, and federal security requirements.
The successful candidate will serve as a dedicated resource for daily account-management operations and work closely with federal IAM administrators, DEUS leadership, system owners, and the Contracting Officer’s Representative. The role will also help improve account-management processes through PowerShell scripting, ServiceNow automation, Entra ID workflows, Okta Workflows, and other identity automation capabilities.
Key Responsibilities
Identity and Access Management
- Administer and maintain user accounts across Microsoft Active Directory, Microsoft Entra ID, and Okta.
- Process employee and contractor account requests in accordance with approved onboarding documentation, ServiceNow tickets, and established standard operating procedures.
- Create, modify, disable, and terminate user accounts throughout the full identity lifecycle.
- Grant access to approved systems, applications, shared mailboxes, distribution lists, security groups, and enterprise resources.
- Update account attributes, group memberships, license assignments, roles, and access permissions based on approved requests.
- Verify that all account-management actions are properly authorized before provisioning, modifying, or removing access.
- Troubleshoot account lockouts, password issues, multifactor authentication failures, synchronization problems, attribute errors, and smart card or PIV authentication issues.
- Support hybrid identity environments involving Active Directory, Entra ID, Microsoft 365, and Okta.
- Escalate terminated, suspended, disabled, or otherwise restricted account issues to the appropriate federal IAM administrator.
- Ensure no account-management action is performed outside approved procedures or authorization channels.
Identity Governance and Access Controls
- Support SailPoint Identity Governance as a managed enterprise service.
- Troubleshoot user-access issues and interpret identity provisioning, certification, and access-review results.
- Coordinate with federal and NIH identity administrators when issues require escalation.
- Assist with the development and implementation of role-based access control models.
- Support birthright provisioning approaches that standardize baseline permissions and improve onboarding efficiency.
- Help identify excessive, outdated, conflicting, or inappropriate user access.
- Support remediation activities directed by system owners or federal IAM administrators.
PowerShell and Workflow Automation
- Develop, test, document, and maintain PowerShell scripts for account creation, modification, deprovisioning, group administration, and compliance reporting.
- Automate onboarding, offboarding, account modification, and access-management workflows.
- Support automation using PowerShell, Microsoft Entra ID, Okta Workflows, and ServiceNow workflows.
- Develop automated reports covering provisioning status, deprovisioning activity, access changes, inactive accounts, and compliance exceptions.
- Identify manual account-management processes that can be improved through automation.
- Ensure scripts and automated workflows include appropriate controls, validation, documentation, and error handling.
Account Recertification and Audit Support
- Conduct quarterly account reviews for assigned systems.
- Compile current users, assigned roles, access permissions, and last-access information.
- Identify inactive, orphaned, duplicate, or potentially inappropriate accounts based on HRSA requirements.
- Provide review findings and recommended corrective actions to system owners.
- Implement approved account modifications or removals.
- Improve the accuracy and efficiency of recertification activities through automation.
- Prepare the Quarterly Account Recertification Report, including findings, inactive accounts, exceptions, and completed corrective actions.
Process Management and Continuous Improvement
- Develop and maintain policies, procedures, standard operating procedures, work instructions, and technical documentation for account-management activities.
- Review and update account-management documentation at least twice annually.
- Collaborate with federal subject-matter experts to identify workflow improvements and automation opportunities.
- Assess the current account-management environment to identify bottlenecks, control gaps, and inefficient manual processes.
- Document recommendations for OIT and DEUS leadership review.
- Prepare the Bi-Annual Process Assessment Report summarizing automation opportunities, expected efficiency gains, and proposed procedural updates.
- Promote consistent identity-management practices across the support organization.
ServiceNow and Enterprise IT Operations
- Record all account-management, authentication-support, and identity-related activities in ServiceNow.
- Maintain complete, accurate, and properly categorized incident, request, change, and CMDB records.
- Ensure requests that arrive outside ServiceNow are entered into the system before work proceeds.
- Support identity-related issues involving Microsoft 365, Teams, Exchange, SharePoint, OneDrive, VPN access, Zscaler connectivity, and network authentication.
- Coordinate escalations with the DEUS IAM Team, HHS OCIO IAM, NIH CIT Service Desk, desktop engineering, network operations, and other technical teams.
- Provide timely status updates and maintain clear documentation throughout the ticket lifecycle.
- Contribute account-management updates to recurring DEUS reports and weekly presentations.
Security and Compliance
- Perform all identity and account-management activities in accordance with HRSA security policies, HHS Information Security and Privacy Policy, HSPD-12, and applicable federal cybersecurity standards.
- Verify the identity of users requesting password, access, MFA, or authentication assistance before taking action.
- Follow federal privacy and security procedures when handling user information and access requests.
- Support identity-related security incident response, vulnerability remediation, and compliance activities.
- Maintain appropriate documentation and evidence for account-management actions, access reviews, and audits.
- Protect sensitive identity, access, and authentication information throughout all support activities.
- Ensure account provisioning and deprovisioning activities are completed accurately and within required timeframes.
Functional Guidance and Knowledge Sharing
- Serve as a subject-matter resource for identity and account-management questions from DEUS support staff.
- Provide functional guidance to Desktop Support Technicians on account-related troubleshooting, PIV authentication, escalation procedures, and ServiceNow documentation.
- Train and mentor support personnel on identity-management procedures and approved support boundaries.
- Coordinate with the Program Assistant on quarterly recertification tracking, reporting inputs, and deliverable preparation.
- Escalate issues beyond the position’s authorized scope to the appropriate federal administrator.
Required Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or an equivalent combination of education and relevant experience.
- Minimum of three years of experience supporting enterprise identity and access management environments.
- Hands-on experience administering:
- Microsoft Active Directory
- Microsoft Entra ID, formerly Azure Active Directory
- Okta
- Demonstrated experience with enterprise user lifecycle administration, including provisioning, access changes, group administration, license assignment, and deprovisioning.
- Proficiency in PowerShell scripting for user, group, access, and reporting automation.
- Experience supporting SailPoint Identity Governance or a comparable identity governance platform.
- Understanding of role-based access control and birthright provisioning concepts.
- Experience troubleshooting authentication, MFA, synchronization, access, and user-account issues.
- Experience using ServiceNow or a comparable IT service-management platform.
- Strong documentation, reporting, analytical, and problem-solving skills.
- Ability to communicate effectively with technical teams, federal stakeholders, system owners, and end users.
- Ability to obtain and maintain a federal Public Trust Tier 2 background investigation and HHS PIV credential.
- Ability to work onsite at HRSA Headquarters in Rockville, Maryland.
- Ability to travel approximately 10%–15%, including occasional travel to regional offices and Baton Rouge, Louisiana.
Certification Requirement
Candidates must hold at least one of the following certifications:
- CompTIA Security+
- ITIL 4 Foundation
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
Preferred Qualifications
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Microsoft Certified: Windows Server Hybrid Administrator Associate.
- Okta Certified Administrator or Okta Certified Professional.
- CompTIA Network+.
- CompTIA CySA+.
- Tanium Certified Operator.
- CISSP, particularly for candidates with more senior-level experience.
- Experience supporting identity and access management within an HHS, HRSA, NIH, or other federal environment.
- Familiarity with HSPD-12, PIV credential management, HHS IS2P, and federal identity-management requirements.
- Experience conducting access certifications, account recertification reviews, and remediation activities.
- Experience integrating PowerShell automation with ServiceNow, Entra ID, Okta, or other identity platforms.
- Experience creating formal compliance, audit, operational, or process-assessment reports.
- Familiarity with Microsoft Intune, Tanium, Zscaler ZIA/ZPA, and Microsoft 365 administration.
Tools and Technologies
The selected candidate may work with technologies including:
- Microsoft Active Directory
- Microsoft Entra ID
- Okta
- SailPoint Identity Governance
- PowerShell
- Okta Workflows
- Microsoft Entra automation
- ServiceNow incident, request, change, CMDB, workflow, and reporting modules
- Microsoft 365
- Microsoft Teams
- Exchange and Outlook
- SharePoint and OneDrive
- Zscaler ZIA/ZPA
- Microsoft Intune
- Tanium
- Microsoft Excel and PowerPoint
- ServiceNow dashboards and reporting tools
Tools and technologies may evolve based on client and program requirements. The successful candidate must be comfortable learning new platforms and adapting to changing federal IT needs.
Compensation and Benefits
The projected compensation range for this position is $108,000 to $130,000 per year benchmarked in the Washington, D.C. metropolitan area. The salary range provided is a good faith estimate representative of all experience levels. Salary at LCG is determined by various factors, including but not limited to role, location, the combination of education/training, knowledge, skills, competencies, certifications, and work experience.
LCG offers a competitive, comprehensive benefits package which includes health insurance options (medical, dental, vision), life and disability insurance, retirement plan contributions, as well as paid leave, federal holidays, professional development, and lifestyle benefits.
Devoted to Fair and Inclusive Practices
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.
If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact our Human Resources department by email at
hr@lcginc.com
. Securing Your Data
Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advancement of money during the application process. Legitimate communication will only come from lcginc.com or
system@hirebridgemail.com
emails, not free commercial services like Gmail or WhatsApp. If you receive suspicious emails asking for payment or personal information, contact us immediately at hr@lcginc.com
. If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Use of Artificial Intelligence in Recruiting
LCG may use artificial intelligence (AI) and other automated technologies to support portions of the recruiting and hiring process, including resume review, candidate matching, interview scheduling, skills assessment, and other administrative functions. AI-assisted tools are used solely to support our hiring process and do not independently determine employment outcomes. Final hiring decisions are made by trained hiring professionals following a comprehensive review of each candidate's qualifications. We are committed to equal employment opportunity and strive to ensure our hiring practices are fair, transparent, and compliant with applicable laws. Applicants needing a reasonable accommodation during the application or interview process should contact Human Resources.