Job Description
Koniag IT Systems, LLC, a Koniag Government Services company, is seeking an Okta/SailPoint Engineer with a Secret security clearance to support KITS and our government customer. The position is remote.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Okta/SailPoint Engineer to support a critical Government Identity, Credential, and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Okta/SailPoint Engineer will serve as a dedicated platform specialist responsible for the configuration, administration, integration, and sustainment of the centralized ICAM technical stack—leveraging Okta for Identity Provider (IdP) services and SailPoint IdentityIQ (IIQ) for Identity Governance and Administration (IGA)—in direct support of the Department of Defense (DoD) Zero Trust Execution Roadmap.
The ideal candidate is a technically deep platform engineer with hands-on expertise in Okta and SailPoint IdentityIQ, a strong understanding of enterprise identity protocols, and a demonstrated ability to deliver complex integration solutions in a federal IT environment. This individual must be comfortable operating in a fast-paced, high-volume program where platform reliability, security, and scalability are mission-critical priorities.
This position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed remotely.
The Okta/SailPoint Engineer will serve as the primary platform subject matter expert (SME) for the ICAM technical stack, responsible for the hands-on configuration, administration, troubleshooting, and continuous improvement of the Okta and SailPoint IdentityIQ platforms. This individual will work closely with migration engineers, the migration team lead, and application owners to ensure the ICAM technical stack is properly configured, performant, and capable of supporting the full application enablement pipeline. The Okta/SailPoint Engineer is expected to deliver technically sound, secure, and scalable platform solutions while maintaining rigorous documentation standards and supporting program compliance requirements.
Principal responsibilities will include but are not limited to:
• Serve as the primary technical SME for the Okta Identity Provider (IdP) platform, including the administration, configuration, and ongoing optimization of Okta Universal Directory, SSO integrations, MFA policies, application integrations, and identity federation services.
• Serve as the primary technical SME for SailPoint IdentityIQ (IIQ), including the administration, configuration, and ongoing optimization of identity governance workflows, automated provisioning and deprovisioning, entitlement management, access certification campaigns, and Segregation of Duties (SOD) enforcement.
• Design, configure, and deploy application integrations with the Okta IdP using industry-standard protocols including SAML, OAuth 2.0, OIDC, and SCIM, leveraging existing Okta connectors and integration frameworks where available.
• Design, configure, and deploy application integrations with SailPoint IIQ, including the setup of application connectors, automated provisioning workflows, role and entitlement models, access request processes, and audit reporting capabilities.
• Engineer and develop custom connectors, scripts, APIs, and middleware solutions to facilitate the integration of legacy applications that cannot natively support modern identity protocols or standard SailPoint/Okta connectors.
• Develop, implement, and sustain the identity protocol connectors and APIs that application owners will use to connect their systems to the ICAM technical stack, ensuring these resources are reliable, well-documented, and accessible.
• Provide deep technical guidance and platform-specific expertise to migration engineers and application owners throughout the enablement lifecycle, including troubleshooting complex integration failures, diagnosing authentication and authorization issues, and resolving platform-level defects.
• Support the configuration and management of alternative credential solutions and non-PKI based authentication mechanisms within the Okta platform as required by individual application enablement needs.
• Administer and maintain Okta Universal Directory as the Authoritative Directory Aggregator, ensuring accurate, consistent, and synchronized identity data across integrated applications and identity sources.
• Implement and enforce access control models including Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) configurations within Okta and SailPoint, providing architectural recommendations to application owners on maximizing utilization of these frameworks.
• Support the establishment and ongoing maintenance of Single Sign-On (SSO) integrations and Active Directory connections, including troubleshooting federation issues and ensuring compliance with enterprise identity standards.
• Monitor platform health, performance, and security across the Okta and SailPoint environments, proactively identifying and resolving issues that could impact the application enablement pipeline or overall ICAM platform availability.
• Contribute to the development and maintenance of platform runbooks, integration guides, architectural documentation, and standard operating procedures to support consistent and repeatable enablement processes.
• Support the testing program by developing integration test cases, executing platform-level testing, and providing technical observations and findings for UAT events and Software Test Reports.
• Ensure all platform configurations, custom developments, and integration solutions comply with applicable DoD security requirements, including CUI handling, OPSEC, Section 508 accessibility standards, supply chain risk management requirements per DFARS 239.73, and DoD cybersecurity certification requirements.
• Vet all third-party connectors, scripts, code libraries, and enhancements integrated into the ICAM environment to prevent the introduction of cybersecurity vulnerabilities, malicious code, or unauthorized data exfiltration.
• Maintain current knowledge of Okta and SailPoint platform updates, new features, and evolving identity standards, proactively applying this knowledge to improve platform capabilities and program outcomes.
Education and Experience:
Required:
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university.
• Minimum of 5 years of hands-on experience in information technology, with at least 3 years of direct, production-level experience administering and configuring Okta and/or SailPoint IdentityIQ in an enterprise environment.
• Demonstrated experience designing and implementing SSO integrations using SAML, OAuth 2.0, and OIDC in a production enterprise environment.
• Demonstrated experience configuring automated provisioning and deprovisioning workflows, entitlement management, and access certification campaigns within SailPoint IIQ.
• Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.
Preferred:
• Prior experience supporting DoD IT programs, particularly within an ICAM or Zero Trust context.
• Experience working in a federal government IT contracting environment.
• Experience administering both Okta and SailPoint IIQ concurrently in a large-scale enterprise environment.
Required Skills and Competencies:
• Deep, hands-on technical expertise with the Okta Identity Provider platform, including Universal Directory, SSO, MFA, application integrations, identity federation, lifecycle management, and Okta Workflows.
• Deep, hands-on technical expertise with SailPoint IdentityIQ (IIQ), including connector configuration, identity lifecycle management, role modeling, entitlement management, access certifications, SOD policy enforcement, and audit reporting.
• Strong working knowledge and practical implementation experience with SAML 2.0, OAuth 2.0, OIDC, and SCIM identity and authorization protocols.
• Experience developing custom integration solutions including scripts, connectors, REST APIs, and middleware to bridge legacy or non-standard applications with modern identity platforms.
• Proficiency in one or more scripting or programming languages commonly used in identity engineering contexts, such as Java, Python, JavaScript, PowerShell, or BeanShell.
• Familiarity with Active Directory and LDAP directory services, including integration with enterprise IdP platforms.
• Experience implementing and managing RBAC and ABAC access control frameworks within enterprise identity platforms.
• Ability to troubleshoot and resolve complex platform-level authentication, authorization, and provisioning failures, including interpreting SAML assertions, OAuth token flows, OIDC authentication responses, and SailPoint workflow errors.
• Strong attention to detail with the ability to maintain accurate, comprehensive technical documentation across multiple concurrent platform configurations and integration efforts.
• Familiarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, DFARS 239.73 supply chain risk management, and DoDM 8140.03 cybersecurity certification requirements.
• Strong communication skills in English—both written and oral—with the ability to clearly convey complex platform concepts and integration guidance to both technical peers and non-technical application owners.
• Ability to work effectively both independently and as part of a collaborative cross-functional team.
• Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.
• Ability to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent).
Clearance Requirement:
• Secret clearance
Desired Skills and Competencies:
• Okta Certified Professional certification.
• Okta Certified Administrator certification.
• Okta Certified Developer certification.
• SailPoint IdentityIQ Engineer or Administrator certification.
• Experience implementing SCIM-based automated provisioning integrations between enterprise identity platforms and target applications.
• Experience configuring and managing Okta as an identity provider in a DoD or federal government PKI and CAC-based authentication environment.
• Knowledge of Zero Trust Architecture (ZTA) principles and their practical application to identity platform engineering within a DoD context.
• Experience with platform-level performance monitoring, alerting, and health management for Okta and SailPoint environments.
• Familiarity with identity federation concepts including cross-domain trust relationships, identity bridging, and multi-tenant identity architectures.
• Experience developing and maintaining platform runbooks, integration playbooks, and technical architecture documentation in a federal contracting environment.
• Certified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification.
• Experience with CDRL deliverable contribution and technical documentation requirements in a federal contracting environment.
• Familiarity with Section 508 compliance requirements for electronic and information technology.
• Knowledge of Segregation of Duties (SOD) concepts and their implementation within enterprise IGA platforms in support of financial audit and compliance requirements.
• Experience with enterprise application portfolio migrations or large-scale IT modernization programs within the federal defense sector.
• Familiarity with Agile and/or hybrid Agile-Waterfall program execution methodologies.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352