
Lead Engineer, DAF365
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Oversee Study 3 of the DAF ICAM System Enhancement Studies initiative.
• Deliver a decision-ready DAF365 JML Transformation Framework Technical Study Report within 90 calendar days.
• Map identity attributes from MILPDS and DCPDS into Okta Universal Directory while identifying data quality issues and deficiencies.
• Establish attribute schemas, source-of-record assignments, data formats, sanitization, and normalization rules.
• Evaluate data pipelines to determine the placement of transformation logic in Okta Workflows, upstream ETL, or both.
• Create target-state architecture for routing DAF365 identity management through DAF ICAM and directly into Microsoft Entra ID.
• Document current and future provisioning flows utilizing SCIM and Microsoft Graph API.
• Define usage for Okta on-premises provisioning agents concerning legacy Active Directory dependencies.
• Specify requirements for Entra ID tenant, federation, and application integration.
• Design workflows for Joiners, Movers, and Leavers, including triggers, provisioning, group and license management, error handling, approvals, escalations, expiration dates, and revocations.
• Document foundational administrator provisioning procedures, role-based access controls, approval gates, and audit trails.
• Measure provisioning latency reductions achieved through administrator delegation and automation.
• Collaborate with program management, architecture, systems analysis, and cost analysis stakeholders on a phased roadmap and ROM cost estimate.
• Compile study outputs into CDRL B010 and correlate sections to PWS Section 4.3.
• Submit a draft report for Government review and present findings to the Government Program Manager and COR.
• Confirm required clearances and report any changes in clearance status.
• A Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited institution.
• Over 7 years of experience in identity and access management engineering, enterprise architecture, or identity lifecycle management within Defense or Federal government IT environments.
• Practical experience in designing attribute-based provisioning workflows in Okta Universal Directory integrated with Microsoft Entra ID or Azure Active Directory.
• Experience in designing or analyzing Joiner, Mover, Leaver identity lifecycle management processes for enterprise populations in DoD or Federal environments.
• Familiarity with Microsoft Entra ID, including SCIM provisioning, Microsoft Graph API integration, tenant configuration, and domain federation settings.
• Active Secret security clearance with final adjudication required before assignment.
• In-depth technical knowledge of Okta platform architecture, Universal Directory schema design, attribute mapping, ABAC rule configuration, Okta Workflows, provisioning agent deployment, and application integration.
• Proficient in Microsoft Entra ID architecture, SCIM provisioning, Microsoft Graph API integration, tenant structure, domain federation, and Entra ID group and license management.
• Experience in designing workflows for attribute sanitization and normalization.
• Understanding of legacy Active Directory environments and bridging architectures.
• Familiarity with MILPDS and DCPDS and their attribute structures.
• Knowledge of Microsoft 365 license management, mailbox provisioning, SharePoint and Microsoft Teams group membership management, and DoD data retention policies.
• Understanding of delegated administration models, role-based access controls, and approval workflow design.
• Ability to conduct current-state/future-state architecture analysis, quantify provisioning latency, and develop implementation roadmaps.
• Experience in creating phased implementation roadmaps with entry/exit criteria, dependencies, and timelines for Government review and accreditation.
• Strong technical writing skills for formal study reports, architecture documentation, workflow specifications, and procedural guidance.
• Excellent written and verbal communication skills in English.
• Capability to obtain and maintain a Secret security clearance.
• Preferred: Master's degree, over 10 years of Defense or Federal experience, and experience with DAF/DoD ICAM or Microsoft 365 modernization programs.
• Desired certifications include Okta certifications, Microsoft identity certifications, CISSP, or CISM.
• Medical, dental, and vision insurance.
• 401(k) retirement plan.
• Paid time off.
• Paid parental leave.
• Life and disability insurance.
• Flexible spending accounts.
• Commuter benefits.
• Tuition reimbursement.
Shield AI
Netflix
Travoom
HeroSoftware GmbH - Shopify Apps
Get handpicked remote jobs straight to your inbox weekly.