Lead Engineer, CDO-L Study

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Lead Koniag’s Air Force ICAM study for secure identity in disconnected, degraded, and denied environments. Develop architectures, gap analyses, roadmaps, and the government-ready technical report.

Responsibilities:

  • Serve as primary technical authority for Study 1 of the DAF ICAM System Enhancement Studies effort
  • Lead analysis, architecture development, and documentation for a decision-ready Technical Study Report within 45 calendar days of Task Order award
  • Review Government-provided CDO-L requirements and catalog them by denied, degraded, intermittent, and limited-bandwidth conditions
  • Map requirements against DAF ICAM components including Okta UD, Okta IdP, and SailPoint IIQ
  • Conduct gap analysis between current DAF ICAM capabilities and CDO-L operational demands
  • Evaluate approved ICAM solutions across comparable Federal Defense programs
  • Analyze on-premises replication or caching options for identity and access data at disconnected nodes
  • Evaluate a tiered edge identity broker model across Connected, Degraded/Limited Bandwidth, and Denied states
  • Assess synchronization schedules, connectivity requirements, degraded-mode parameters, and cache staleness thresholds
  • Evaluate Okta Access Gateway and Tactical Identity Bridge Appliance for tactical-edge ICAM operations
  • Assess mirroring of SailPoint IIQ governance workflows at the edge
  • Document tradeoffs among full replication, selective caching, and read-only policy mirroring and recommend an approach
  • Develop emergency break-glass access provisioning recommendations, including governance, immutable audit logging, revocation, and re-synchronization
  • Evaluate PKI certificate validation, CRL caching, and local OCSP stapling for CAC authentication
  • Analyze endpoint security telemetry integration and autonomous access revocation based on device posture
  • Develop methodology for attribute transfer and synchronization between NIPRNet, SIPRNet, and disconnected nodes
  • Coordinate software-component identification, licensing, deployment constraints, classified-network restrictions, and interoperability considerations
  • Develop a phased implementation roadmap and ROM cost estimate
  • Consolidate study outputs into the CDO-L Technical Study Report (CDRL B010), including a draft Performance Work Statement
  • Verify assigned personnel hold required clearances and notify the Government of clearance changes
  • Present findings to the Government Program Manager and Contracting Officer's Representative
  • The study runs for 120 days

Requirements:

  • Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university
  • 7+ years of experience in systems engineering, enterprise architecture, or identity and access management within Defense or Federal government IT environments
  • Demonstrated experience designing or analyzing identity and access management architectures in disconnected, air-gapped, or operationally constrained network environments
  • Experience with the DoD Authority to Operate (ATO) process and security accreditation requirements for Defense information systems
  • Active Secret security clearance with final adjudication required prior to assignment
  • Deep technical knowledge of enterprise ICAM platforms, specifically Okta Universal Directory, Identity Provider, Access Gateway, and Workflows, and SailPoint IdentityIQ
  • Strong understanding of Zero Trust Architecture principles and application to tactical edge and disconnected identity environments
  • Experience designing identity federation, replication, and caching architectures for disconnected or intermittently connected operational environments
  • Proficiency in PKI-based authentication, including CRL, OCSP, and CAC authentication
  • Knowledge of ABAC and RBAC policy frameworks and implementation within Okta and SailPoint
  • Familiarity with NIPRNet and SIPRNet network architecture, classification requirements, and cross-domain constraints
  • Ability to perform and document structured gap analyses, architectural tradeoff assessments, and comparative technology evaluations
  • Experience developing phased implementation roadmaps with entry/exit criteria, dependencies, and Government review and accreditation timelines
  • Strong technical writing skills for formal study reports, architectural documentation, and draft Performance Work Statements
  • Ability to work collaboratively across architects, engineers, cost analysts, and program managers
  • Exceptional written and oral communication skills in English
  • Ability to obtain and maintain a Secret security clearance
  • Preferred: Master's degree in a related technical field
  • Preferred: 10+ years of experience in Defense ICAM, enterprise identity architecture, or related cybersecurity engineering
  • Preferred experience supporting DISA-aligned programs or DAF/Air Force ICAM initiatives
  • Desired familiarity or experience with OAG, TIBA, DoD Enterprise ICAM IL5/IL6 DDIL requirements, break-glass access governance, endpoint security telemetry integration, SIEM, DISA STIGs, ROM cost estimates, Agile methodologies, and related certifications

Benefits:

  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off
  • Paid parental leave
  • Life and disability insurance
  • Flexible spending accounts
  • Commuter benefits
  • Tuition reimbursement