1

Sso Engineer Jobs in Colorado (NOW HIRING)

... SSO, member join flows, and seat management. * Ensure that organization-scoped roles and ... Work with engineering to ensure robust sync reliability, conflict resolution, and real-time de ...

... SSO, member join flows, and seat management. * Ensure that organization-scoped roles and ... Work with engineering to ensure robust sync reliability, conflict resolution, and real-time de ...

Senior DevSecOps Engineer

Boulder, CO · On-site +1

$118K - $162K/yr

You'll be the person the engineering org comes to on security and the one who defines what good ... Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud-native identity controls ...

Senior DevSecOps Engineer

Boulder, CO · On-site +1

$118K - $162K/yr

You'll be the person the engineering org comes to on security and the one who defines what good ... Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud-native identity controls ...

CapTech is seeking a SaaS platform engineer to play a hands-on role in the engineering ... Design and manage SSO integrations using SAML and OIDC, ensuring secure and consistent access ...

The primary role of the IT Systems Engineer is to manage core IT systems and support both ... Experience with Active Directory and Entra ID user and group management, Single Sign-On (SSO) and ...

Showing results 41-60

Sso Engineer information

What skills and qualifications are needed to thrive as an SSO engineer?

To thrive as an SSO Engineer, you need expertise in identity and access management (IAM), authentication protocols like SAML, OAuth, and OpenID Connect, and often a degree in computer science or a related field. Familiarity with IAM platforms (such as Okta or Azure AD), scripting languages, and relevant certifications such as CISSP or vendor-specific credentials is highly valuable. Strong analytical skills, excellent communication, and a proactive approach to problem-solving help an SSO Engineer excel in both team and client interactions. These skills are essential for designing secure, scalable single sign-on solutions and ensuring seamless user experiences across organizational systems.

What is an SSO engineer?

An SSO (Single Sign-On) Engineer is responsible for designing, implementing, and maintaining authentication and identity management solutions that allow users to access multiple applications with a single login. They work with identity providers (IdPs), protocols like SAML, OAuth, and OpenID Connect, and enterprise authentication systems to enhance security and user experience. SSO Engineers troubleshoot authentication issues, integrate new applications, and ensure compliance with security best practices. Their role is crucial in protecting sensitive data and improving IT efficiency within an organization.

What does an SSO engineer do?

As an SSO Engineer, your daily tasks often include implementing and maintaining single sign-on solutions, troubleshooting authentication issues, and managing user access across multiple applications. You will regularly collaborate with IT security teams, software developers, and business units to integrate new applications and ensure secure access protocols are in place. The role may also involve reviewing security logs, updating configurations, and participating in security incident response. This position is both technical and collaborative, offering opportunities to make a direct impact on organizational security and efficiency.

What are popular job titles related to Sso Engineer jobs in Colorado? For Sso Engineer jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Sso Engineer jobs in Colorado look for? The top searched job categories for Sso Engineer jobs in Colorado are:
Infographic showing various Sso Engineer job openings in Colorado as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution.

$132K - $220K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 4 days ago


Job description

Salary StatementEstimated Starting Salary Range: USD $132,250.00/Yr. - USD $220,400.00/Yr. Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.Description

The Systems Automation Engineer architects, secures, and sustains a fully air-gapped, multi-account Kubernetes platform in AWS GovCloud, built on RHEL, RKE2, and self-managed GitLab. This role is built on an automation-first mindset infrastructure-as-code, one-shot repeatable deployments, CI/CD pipelines, and containerization to deliver highly scalable, resilient, and secure solutions in a disconnected environment. The engineer eliminates manual processes in favor of bundled, offline-reproducible deployments, embeds DevSecOps and zero-trust identity across the full system lifecycle, and operates the platform to meet NIST, RMF, STIG, and IL5/IL6/TS-SCI requirements.

Platform & Infrastructure Engineering

  • Designing, deploying, and sustaining RHEL 8/9/10 environments and RKE2 Kubernetes clusters across multiple AWS accounts and VPCs
  • Operating the cluster control plane and per-environment agent pools (dev/test/staging/prod) with node labeling, taints, and workload isolation
  • Performing hardening, patching, and performance tuning in a disconnected environment using bundled RPM delivery (no upstream repos), SELinux, and host firewalls
  • Administering platform-native core services CoreDNS, AWS Route 53, ingress/load balancing, and certificate lifecycle (cert-manager / TLS secrets)
  • Designing HA/DR and resilience multi-node control planes, automated backup/restore of stateful workloads (PVCs, GitLab, databases), and failover across availability zones

Cloud & Network Engineering

  • Architecting and managing AWS GovCloud environments (EC2, S3, EBS, VPC, IAM, Route 53) across multiple accounts with cross-account roles, key pairs, and AMI strategy
  • Designing secure, scalable multi-VPC network architectures Transit Gateway meshes, subnets, routing, and CIDR-based security-group rules (cross-VPC SG references are not available in GovCloud)
  • Implementing all infrastructure as code with Terraform (reusable per-VPC modules, cross-account providers, programmatically rendered variables)
  • Standing up and operating an in-environment OCI/container registry and bootstrap services for offline image distribution
  • Optimizing cloud cost, performance, and availability through right-sizing, repeatable destroy/redeploy, and monitoring

DevSecOps & GitLab Platform

  • Building and sustaining CI/CD pipelines on self-managed GitLab EE, including version-ladder upgrades, the container registry, and auto-registered Kubernetes runners
  • Integrating DevSecOps container/image CVE scanning (e.g., Trivy, Grype, Clair), secrets management, and policy/gating in pipelines
  • Operating container build and delivery tooling (Docker/podman, kaniko, Helm) with helm-template-derived, air-gap-reproducible image bundles
  • Implementing GitOps delivery with ArgoCD (pull-based, per-app Applications, environment promotion and prod gating)

Automation & Air-Gap Delivery

  • Developing automation that eliminates manual intervention single-command, phase-driven deployments validated end-to-end before delivery
  • Engineering self-contained, offline deployment bundles (RPMs, OCI images, Helm charts, binaries) for reproducible installs in disconnected networks
  • Writing and maintaining automation in Ansible, Python, and Bash; automating provisioning, configuration management, and patching
  • Maintaining idempotent, resumable deploy/upgrade/teardown workflows

Identity, Security & Compliance

  • Implementing zero-trust identity and SSO with Keycloak (OIDC/SAML), federating platform services (GitLab, ArgoCD, monitoring, admin UIs) and supporting CAC/PIV X.509 smart-card authentication
  • Implementing system hardening in accordance with DISA STIGs and NIST baselines as automated, repeatable controls
  • Supporting RMF/ATO processes authoring control evidence, security documentation, POA&M items, and continuous-monitoring inputs
  • Implementing centralized logging, monitoring, and alerting (Elastic/SIEM, host/audit telemetry, and AWS-native sources where applicable)
  • Ensuring IL5/IL6/TS-SCI compliance through enforced security controls, secrets-at-rest protection, and system hardening

Observability, Operations & Support

  • Standing up and operating monitoring/observability (Prometheus, Grafana, node/cluster metrics) and vulnerability scanning (ACAS Tenable.sc/Nessus)
  • Monitoring system performance, availability, and capacity to ensure reliability and scalability
  • Troubleshooting complex, cross-component issues across the platform (networking, DNS, container runtime, registry, identity) to restore operations
  • Providing Tier III support and leading root-cause analysis to resolve issues and prevent recurrence
  • Maintaining architecture documentation, deployment guides, and standard operating procedures/runbooks

#LI-LH1

Requirements
  • Five plus years of experience in systems/infrastructure engineering with strong Linux (RHEL 8/9/10) depth
  • Five plus years of experience in DevSecOps, automation, and AWS cloud environments
  • Strong hands-on experience with AWS core services and multi-account/VPC networking
  • Production experience operating Kubernetes (RKE2 preferred) RBAC, ingress, Helm, troubleshooting
  • Experience with scripting/automation in Ansible, Python, and Bash
  • Hands-on experience with Infrastructure as Code (Terraform)
  • Experience building and sustaining CI/CD pipelines (GitLab)
  • Working knowledge of networking fundamentals (routing, host firewalls, load balancers, DNS)
  • Experience applying DISA STIG / NIST hardening and supporting RMF/ATO in DoD or regulated environments
  • Ability to obtain/maintain a security clearance consistent with IL5/IL6/TS-SCI work

Certifications:

  • Red Hat Certified System Administrator (RHCSA) or higher
  • Certified Kubernetes Administrator (CKA)
  • CompTIA Security+ (or higher, e.g., CISSP) DoD 8570/8140 baseline
  • AWS Certified Solutions Architect (Associate or Professional)
Desired Skills
  • Experience with Kubernetes (RKE2, EKS, OpenShift, NKP, Rancher Federal, or similar)
  • Knowledge of zero-trust architecture and modern identity solutions
  • Experience with HashiCorp Vault, ArgoCD, or GitOps workflows, and service mesh technologies
  • Familiarity with monitoring tools (Prometheus, Grafana)
  • Experience in DoD or regulated environments (RMF, IL5/IL6/TS-SCI)
Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL.

Travel Requirements
  • Locally within US Space Command's Colorado Springs AOR. Peterson SFB, Schriever SFB and other locations in Colorado Springs
  • Up to two weeks per month to US Space Command facilities at Redstone Arsenal, Hunstville Alabama
About Us

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

EEO

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Employment Type: FULL_TIME