NPE Governance Study Lead Engineer, Study 2
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Lead a 120-day DAF ICAM study for Koniag Government Services, which delivers Federal enterprise solutions. Design NPE governance, SailPoint workflows, Okta architecture, and Zero Trust roadmaps.
Responsibilities:
- Lead Study 2 of the DAF ICAM System Enhancement Studies effort as the primary technical authority
- Review and analyze Government-Furnished Information and federal references
- Design standardized attribute schemas for a centralized Master Device/Entity Record in the Enterprise Identity Catalog
- Define alignment between NPE attribute schemas and Okta dual-server authentication architecture
- Develop NPE identity naming conventions with the DAF Chief Data and Artificial Intelligence Office
- Develop a technical plan to discover existing NPEs across the hybrid DAF enterprise and consolidate them into a unified catalog
- Define secure data exchange and synchronization flows with enterprise identity, credential, automation, and AI platforms
- Define manual validation, discrepancy resolution, and data enrichment processes for system owners
- Design NPE lifecycle governance workflows in SailPoint IGA from request through deactivation/revocation
- Design accountability and Babysitter enforcement controls
- Formulate recurring NPE access recertification tied to SSP and ATO maintenance
- Design credential management governance covering PKI/token authentication, 90-day rotation, and secret vault storage
- Develop a scalable target architecture integrating DoD Zero Trust Architecture, PDPs, SOC/ELICSAR, UEBA, and AI anomaly detection
- Define standardization and rationalization using SPIFFE/SPIRE, OAuth 2.0, and mTLS
- Conduct legacy NPE authentication rationalization and remediation assessment
- Extend Zero Trust governance to AI Agents, RAG pipelines, and orchestration platforms
- Produce phased implementation roadmaps and coordinate ROM cost estimates
- Consolidate outputs into the NPE Governance and Management Strategy Technical Study Report (CDRL B010)
- Present findings to Government stakeholders including the Program Manager and COR
- Verify assigned personnel security clearances and report status changes
- Perform analytical and planning work only; no software development, system configuration, or live deployment
Requirements:
- Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university
- 7+ years of experience in identity governance, enterprise architecture, or identity and access management within Defense or Federal government IT environments
- Demonstrated experience designing or analyzing identity governance frameworks for non-person entities, service accounts, machine identities, or workload identities in enterprise environments
- Experience with SailPoint IdentityIQ (IIQ) or SailPoint IdentityNow in an engineering, architecture, or governance design capacity
- Experience with Okta platform components including Universal Directory, authentication server configuration, and application integration
- Active Secret security clearance; final adjudication required prior to assignment
- Deep technical knowledge of enterprise Identity Governance and Administration platforms, specifically SailPoint IdentityIQ, including lifecycle management workflow design, access certification, and provisioning architecture
- Proficiency in Okta platform architecture, including Universal Directory schema design, authentication server configuration, and application integration for person and non-person entity populations
- Strong understanding of Non-Person Entity identity types including service accounts, software bots, APIs, workload identities, and IoT devices
- Knowledge of Zero Trust Architecture principles and application to machine identities, workload identities, and NPE governance within DoD environments
- Familiarity with DoD and DAF ICAM policy frameworks including NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and related mandates
- Experience designing attribute schemas, naming conventions, and master record structures for enterprise identity catalogs
- Knowledge of automated NPE discovery tools and enterprise data sources including Azure AD Connect, AWS IAM Inventory, Microsoft InTune, ServiceNow CMDB, Tenable Nessus, and ACAS
- Understanding of PKI-based credential management, certificate lifecycle management, credential rotation policies, and enterprise secret vault architectures
- Familiarity with SPIFFE/SPIRE, OAuth 2.0, mTLS, and their application to NPE and API security in DoD environments
- Ability to perform structured governance workflow design, architecture tradeoff analysis, and legacy rationalization assessments
- Experience developing phased implementation roadmaps with entry/exit criteria, dependencies, and Government review and accreditation timelines
- Strong technical writing skills for formal study reports, governance framework documentation, architectural diagrams, and leadership-facing business cases
- Ability to work collaboratively across cross-functional technical teams
- Exceptional written and oral communication skills in English
- Ability to obtain and maintain a Secret security clearance
- Preferred: Master's degree in a related technical field
- Preferred: 10+ years of experience in Defense or Federal ICAM, identity governance and administration, or related cybersecurity engineering disciplines
- Preferred experience supporting DAF, Air Force, Space Force, or other DoD component ICAM or cybersecurity modernization programs
- Preferred experience with DoD PKI, ECMS, or NPE PKI certificate lifecycle management
- Desired experience with SOC/SIEM integration, UEBA, AI-driven anomaly detection, enterprise secret vault platforms, MuleSoft, AppGate, Xage, UiPath, AI Agent orchestration, Zero Trust AI governance, legacy rationalization, ROM cost estimates, and relevant certifications
Benefits:
- Medical, dental, and vision insurance
- 401(k) retirement plan
- Paid time off
- Paid parental leave
- Life and disability insurance
- Flexible spending accounts
- Commuter benefits
- Tuition reimbursement














