NPE Governance Study Lead Engineer, Study 2

Posted Sep 16

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the primary technical authority for Study 2 of the DAF ICAM System Enhancement Studies initiative.

• Evaluate and interpret Government-Furnished Information along with federal references.

• Create standardized attribute schemas for a centralized Master Device/Entity Record within the Enterprise Identity Catalog.

• Establish alignment between NPE attribute schemas and the Okta dual-server authentication framework.

• Collaborate with the DAF Chief Data and Artificial Intelligence Office to develop NPE identity naming conventions.

• Formulate a technical strategy to identify existing NPEs throughout the hybrid DAF enterprise and unify them into a single catalog.

• Outline secure data exchange and synchronization processes with enterprise identity, credentialing, automation, and AI platforms.

• Specify manual validation, discrepancy resolution, and data enrichment procedures for system owners.

• Develop NPE lifecycle governance workflows in SailPoint IGA, covering the process from request to deactivation/revocation.

• Create accountability measures and Babysitter enforcement controls.

• Establish recurring NPE access recertification linked to SSP and ATO maintenance.

• Design governance for credential management, which includes PKI/token authentication, 90-day rotation, and secret vault storage.

• Develop a scalable target architecture that integrates DoD Zero Trust Architecture, PDPs, SOC/ELICSAR, UEBA, and AI anomaly detection.

• Define standardization and rationalization utilizing SPIFFE/SPIRE, OAuth 2.0, and mTLS.

• Conduct an assessment of legacy NPE authentication rationalization and remediation.

• Expand Zero Trust governance to include AI Agents, RAG pipelines, and orchestration platforms.

• Produce phased implementation roadmaps and coordinate ROM cost estimates.

• Compile findings into the NPE Governance and Management Strategy Technical Study Report (CDRL B010).

• Present results to Government stakeholders, including the Program Manager and COR.

• Verify the security clearances of assigned personnel and report any status changes.

• Engage in analytical and planning tasks exclusively; software development, system configuration, or live deployment is not included.


⛳️ Requirements

• A Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited institution.

• Over 7 years of experience in identity governance, enterprise architecture, or identity and access management within Defense or Federal government IT settings.

• Proven experience in designing or analyzing identity governance frameworks for non-person entities, service accounts, machine identities, or workload identities in enterprise contexts.

• Familiarity with SailPoint IdentityIQ (IIQ) or SailPoint IdentityNow in an engineering, architecture, or governance design capacity.

• Experience with Okta platform components, including Universal Directory, authentication server configuration, and application integration.

• Possession of an active Secret security clearance; final adjudication must be completed prior to assignment.

• Extensive technical knowledge of enterprise Identity Governance and Administration platforms, particularly SailPoint IdentityIQ, including lifecycle management workflow design, access certification, and provisioning architecture.

• Proficient in Okta platform architecture, encompassing Universal Directory schema design, authentication server configuration, and application integration for both person and non-person entity populations.

• Strong comprehension of Non-Person Entity identity types, such as service accounts, software bots, APIs, workload identities, and IoT devices.

• Understanding of Zero Trust Architecture principles and their application to machine identities, workload identities, and NPE governance within DoD environments.

• Acquainted with DoD and DAF ICAM policy frameworks, including NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and related mandates.

• Experience in designing attribute schemas, naming conventions, and master record structures for enterprise identity catalogs.

• Knowledge of automated NPE discovery tools and enterprise data sources, including Azure AD Connect, AWS IAM Inventory, Microsoft InTune, ServiceNow CMDB, Tenable Nessus, and ACAS.

• Understanding of PKI-based credential management, certificate lifecycle management, credential rotation policies, and enterprise secret vault architectures.

• Familiarity with SPIFFE/SPIRE, OAuth 2.0, mTLS, and their relevance to NPE and API security in DoD environments.

• Capability to execute structured governance workflow design, architecture tradeoff analysis, and legacy rationalization assessments.

• Experience in developing phased implementation roadmaps with entry/exit criteria, dependencies, and timelines for Government review and accreditation.

• Strong technical writing abilities for formal study reports, governance framework documentation, architectural diagrams, and business cases directed at leadership.

• Capacity to work collaboratively across diverse technical teams.

• Exceptional written and verbal communication skills in English.

• Ability to obtain and maintain a Secret security clearance.

• Preferred: A Master's degree in a relevant technical field.

• Preferred: Over 10 years of experience in Defense or Federal ICAM, identity governance and administration, or related cybersecurity engineering disciplines.

• Preferred background supporting DAF, Air Force, Space Force, or other DoD component ICAM or cybersecurity modernization initiatives.

• Preferred experience in DoD PKI, ECMS, or NPE PKI certificate lifecycle management.

• Desired experience with SOC/SIEM integration, UEBA, AI-driven anomaly detection, enterprise secret vault platforms, MuleSoft, AppGate, Xage, UiPath, AI Agent orchestration, Zero Trust AI governance, legacy rationalization, ROM cost estimates, and relevant certifications.


🏝️ Benefits

• Medical, dental, and vision insurance.

• 401(k) retirement plan.

• Paid time off.

• Paid parental leave.

• Life and disability insurance.

• Flexible spending accounts.

• Commuter benefits.

• Tuition reimbursement.

People also viewed

Shield AI1 day ago

Staff Engineer, State Estimation

US flagUnited States OnlyFull-timeFull-stack Engineer$200k – $300k/year
ApplyView job
Netflix1 day ago

Software Engineer L5, Open Connect Platform

US flagUnited States OnlyFull-timeFull-stack Engineer$388k – $558k/year
ApplyView job
Travoom1 day ago

Principal Full Stack Engineer – Travel & Ticketing

US flagTexas OnlyFull-timeFull-stack Engineer
ApplyView job
HeroSoftware GmbH - Shopify Apps1 day ago

Senior Full Stack Developer

DE flagGermany OnlyFull-timeFull-stack Engineer€50k – €80k/year
ApplyView job
EverCommerce1 day ago

Lead Software Engineer

US flagUnited States OnlyFull-timeFull-stack Engineer$170k – $195k/year
ApplyView job
GiveDirectly1 day ago

Senior Software Engineer – Fundraising

US flagUnited States, +2 more countriesFull-timeFull-stack Engineer$181.1k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers