| Location | Huntsville, AL |
Job Title: Trust and Identity Engineer
Reference: 26-014
Job Type: Full-time
Job Status: Interviewing
Date Posted: 07-31-2026
Location: Huntsville
Duration: Permanent
Company Address: CohesionForce, Inc.
Street: 101 Quality Circle
Suite: Suite 140
City: Huntsville, AL 35806
Website: http://www.CohesionForce.com
Job Description:
CohesionForce is actively seeking candidates for a Trust and Identify Engineer to become part of our team in Huntsville, AL. This individual will design, implement, and support identity and access capabilities for users, applications, services, workloads, and AI-enabled systems. The engineer will work across platform, software, reliability, and customer teams to provide secure authentication, federation, authorization, credential management, and auditable access.
Responsbibilities include:
Integrate Microsoft Entra ID, Active Directory, and other customer identity providers using OAuth 2.0, OpenID Connect, SAML, and LDAP-based technologies.
Configure and support identity providers and authentication proxies such as Keycloak, oauth2-proxy, or equivalent products.
Define stable claims, groups, roles, and application onboarding patterns.
Design identity for Kubernetes workloads, services, automation, and AI agents using service accounts, short-lived tokens, service principals, certificates, or workload identity federation.
Implement least-privilege access using RBAC, ABAC, policy as code, and centralized authorization services.
Establish issuance, delivery, rotation, revocation, and recovery procedures for secrets, keys, tokens, and certificates.
Automate identity configuration and validation using APIs, scripting, infrastructure as code, GitOps, and CI-CD.
Troubleshoot login, token, claim, session, certificate, federation, and authorization issues across distributed systems.
Define identity-related logging and tracing requirements and work with reliability engineers to support monitoring and incident resonse.
Develop architecture documentation, integration guides, test procedures, runbooks, and customer handoff material.
Basic Qualifications:
Bachelor's degree in an engineering, computer science, cybersecurity, infommation technology or a related discipline, or equivalent experience and combined education, with 5-10 years of experience, or relevant professional experience.
Production experience with OAuth 2.0, OpenID Connect, JWTs, federation, token lifecycle, and secure application onboarding.
Experience integrating Active Director, Microsoft Entra ID, LDAP, SAML, or comparible enterprise identity systems.
Experience with Kubernetes or OpenShift service accounts, RBAC, secrets, ingress, or service-mesh identity.
Experience implementing identity for non-human services, workloads, or automation.
Experience with fine-grained authorization, policy as code, API scopes, or external authorization services.
Ability to automate configuration and testing with Python, PowerShell, or comparable language.
Works well in a fast=paces collaborative team environment.
Must be willing to work onsite in a closed/classified area.
Active Department of Defense (DoD) Secret clearance.
Preferred Qualifications:
Experience operating Keycloak or another self-hosted identity provider in Kubernetes.
Experience with Microsoft Entra workload identity, managed identities, or service-principal governance.
Experience with OPA, Envoy, Istio, SPIFFE/SPIRE, or comparable technogies.
Experience with OpenBao, Vault, External Secrets, cert-manager, or enterprise certificate-management systems.
Experience applying identity and delegated authorization to AI agents and tool integrations.
Experience using OpenTelemetry for attributable activity and security-event diagnosis.
Strong oral and written communication skills.
Strong interpersonal and collaboration skills.