
Lead Engineer, CDO-L Study
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Act as the leading technical authority for Study 1 of the DAF ICAM System Enhancement Studies initiative.
• Oversee the analysis, architecture creation, and documentation needed for a decision-ready Technical Study Report within 45 calendar days following the Task Order award.
• Review the Government-supplied CDO-L requirements and categorize them by denied, degraded, intermittent, and limited-bandwidth conditions.
• Align requirements with DAF ICAM components such as Okta UD, Okta IdP, and SailPoint IIQ.
• Perform a gap analysis between current DAF ICAM capabilities and CDO-L operational requirements.
• Assess approved ICAM solutions utilized in similar Federal Defense programs.
• Analyze on-premises replication or caching solutions for identity and access data in disconnected nodes.
• Evaluate a tiered edge identity broker model across Connected, Degraded/Limited Bandwidth, and Denied states.
• Review synchronization schedules, connectivity needs, degraded-mode parameters, and cache staleness thresholds.
• Assess the Okta Access Gateway and Tactical Identity Bridge Appliance for operations in a tactical-edge ICAM environment.
• Examine the mirroring of SailPoint IIQ governance workflows at the edge.
• Document trade-offs among full replication, selective caching, and read-only policy mirroring, and provide recommendations.
• Develop recommendations for emergency break-glass access provisioning, encompassing governance, immutable audit logging, revocation, and re-synchronization.
• Evaluate PKI certificate validation, CRL caching, and local OCSP stapling for CAC authentication.
• Analyze endpoint security telemetry integration and autonomous access revocation based on device posture.
• Create a methodology for attribute transfer and synchronization between NIPRNet, SIPRNet, and disconnected nodes.
• Coordinate the identification of software components, licensing, deployment constraints, classified-network limitations, and interoperability factors.
• Formulate a phased implementation roadmap along with a ROM cost estimate.
• Consolidate study outputs into the CDO-L Technical Study Report (CDRL B010), which includes a draft Performance Work Statement.
• Ensure that assigned personnel possess the necessary clearances and inform the Government about any clearance changes.
• Present findings to the Government Program Manager and the Contracting Officer's Representative.
• The duration of the study is set for 120 days.
• A Bachelor’s degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited institution.
• A minimum of 7 years of experience in systems engineering, enterprise architecture, or identity and access management within Defense or Federal government IT sectors.
• Proven experience in designing or analyzing identity and access management architectures in disconnected, air-gapped, or operationally constrained network scenarios.
• Familiarity with the DoD Authority to Operate (ATO) process and the security accreditation requirements for Defense information systems.
• An active Secret security clearance with final adjudication required before assignment.
• Extensive technical knowledge of enterprise ICAM platforms, particularly Okta Universal Directory, Identity Provider, Access Gateway, and Workflows, as well as SailPoint IdentityIQ.
• A strong grasp of Zero Trust Architecture principles and their application in tactical edge and disconnected identity environments.
• Experience in designing identity federation, replication, and caching architectures for disconnected or intermittently connected operational settings.
• Expertise in PKI-based authentication, including CRL, OCSP, and CAC authentication.
• Understanding of ABAC and RBAC policy frameworks and their implementation within Okta and SailPoint.
• Knowledge of NIPRNet and SIPRNet network architecture, classification requirements, and cross-domain constraints.
• Capability to perform and document structured gap analyses, architectural trade-off assessments, and comparative technology evaluations.
• Experience in developing phased implementation roadmaps that include entry/exit criteria, dependencies, and timelines for Government review and accreditation.
• Strong technical writing abilities for formal study reports, architectural documentation, and draft Performance Work Statements.
• Ability to collaborate effectively with architects, engineers, cost analysts, and program managers.
• Excellent written and verbal communication skills in English.
• Capability to obtain and maintain a Secret security clearance.
• Preferred: A Master's degree in a related technical field.
• Preferred: Over 10 years of experience in Defense ICAM, enterprise identity architecture, or related cybersecurity engineering.
• Preferred experience in supporting DISA-aligned programs or DAF/Air Force ICAM initiatives.
• Desired familiarity or experience with OAG, TIBA, DoD Enterprise ICAM IL5/IL6 DDIL requirements, break-glass access governance, endpoint security telemetry integration, SIEM, DISA STIGs, ROM cost estimates, Agile methodologies, and related certifications.
• Medical, dental, and vision insurance.
• 401(k) retirement plan.
• Paid time off.
• Paid parental leave.
• Life and disability insurance.
• Flexible spending accounts.
• Commuter benefits.
• Tuition reimbursement.
Shield AI
Netflix
Travoom
HeroSoftware GmbH - Shopify Apps
Get handpicked remote jobs straight to your inbox weekly.