
NPE Governance Study Lead Engineer, Study 2
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Act as the primary technical authority for Study 2 of the DAF ICAM System Enhancement Studies initiative.
• Evaluate and interpret Government-Furnished Information along with federal references.
• Create standardized attribute schemas for a centralized Master Device/Entity Record within the Enterprise Identity Catalog.
• Establish alignment between NPE attribute schemas and the Okta dual-server authentication framework.
• Collaborate with the DAF Chief Data and Artificial Intelligence Office to develop NPE identity naming conventions.
• Formulate a technical strategy to identify existing NPEs throughout the hybrid DAF enterprise and unify them into a single catalog.
• Outline secure data exchange and synchronization processes with enterprise identity, credentialing, automation, and AI platforms.
• Specify manual validation, discrepancy resolution, and data enrichment procedures for system owners.
• Develop NPE lifecycle governance workflows in SailPoint IGA, covering the process from request to deactivation/revocation.
• Create accountability measures and Babysitter enforcement controls.
• Establish recurring NPE access recertification linked to SSP and ATO maintenance.
• Design governance for credential management, which includes PKI/token authentication, 90-day rotation, and secret vault storage.
• Develop a scalable target architecture that integrates DoD Zero Trust Architecture, PDPs, SOC/ELICSAR, UEBA, and AI anomaly detection.
• Define standardization and rationalization utilizing SPIFFE/SPIRE, OAuth 2.0, and mTLS.
• Conduct an assessment of legacy NPE authentication rationalization and remediation.
• Expand Zero Trust governance to include AI Agents, RAG pipelines, and orchestration platforms.
• Produce phased implementation roadmaps and coordinate ROM cost estimates.
• Compile findings into the NPE Governance and Management Strategy Technical Study Report (CDRL B010).
• Present results to Government stakeholders, including the Program Manager and COR.
• Verify the security clearances of assigned personnel and report any status changes.
• Engage in analytical and planning tasks exclusively; software development, system configuration, or live deployment is not included.
• A Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited institution.
• Over 7 years of experience in identity governance, enterprise architecture, or identity and access management within Defense or Federal government IT settings.
• Proven experience in designing or analyzing identity governance frameworks for non-person entities, service accounts, machine identities, or workload identities in enterprise contexts.
• Familiarity with SailPoint IdentityIQ (IIQ) or SailPoint IdentityNow in an engineering, architecture, or governance design capacity.
• Experience with Okta platform components, including Universal Directory, authentication server configuration, and application integration.
• Possession of an active Secret security clearance; final adjudication must be completed prior to assignment.
• Extensive technical knowledge of enterprise Identity Governance and Administration platforms, particularly SailPoint IdentityIQ, including lifecycle management workflow design, access certification, and provisioning architecture.
• Proficient in Okta platform architecture, encompassing Universal Directory schema design, authentication server configuration, and application integration for both person and non-person entity populations.
• Strong comprehension of Non-Person Entity identity types, such as service accounts, software bots, APIs, workload identities, and IoT devices.
• Understanding of Zero Trust Architecture principles and their application to machine identities, workload identities, and NPE governance within DoD environments.
• Acquainted with DoD and DAF ICAM policy frameworks, including NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and related mandates.
• Experience in designing attribute schemas, naming conventions, and master record structures for enterprise identity catalogs.
• Knowledge of automated NPE discovery tools and enterprise data sources, including Azure AD Connect, AWS IAM Inventory, Microsoft InTune, ServiceNow CMDB, Tenable Nessus, and ACAS.
• Understanding of PKI-based credential management, certificate lifecycle management, credential rotation policies, and enterprise secret vault architectures.
• Familiarity with SPIFFE/SPIRE, OAuth 2.0, mTLS, and their relevance to NPE and API security in DoD environments.
• Capability to execute structured governance workflow design, architecture tradeoff analysis, and legacy rationalization assessments.
• Experience in developing phased implementation roadmaps with entry/exit criteria, dependencies, and timelines for Government review and accreditation.
• Strong technical writing abilities for formal study reports, governance framework documentation, architectural diagrams, and business cases directed at leadership.
• Capacity to work collaboratively across diverse technical teams.
• Exceptional written and verbal communication skills in English.
• Ability to obtain and maintain a Secret security clearance.
• Preferred: A Master's degree in a relevant technical field.
• Preferred: Over 10 years of experience in Defense or Federal ICAM, identity governance and administration, or related cybersecurity engineering disciplines.
• Preferred background supporting DAF, Air Force, Space Force, or other DoD component ICAM or cybersecurity modernization initiatives.
• Preferred experience in DoD PKI, ECMS, or NPE PKI certificate lifecycle management.
• Desired experience with SOC/SIEM integration, UEBA, AI-driven anomaly detection, enterprise secret vault platforms, MuleSoft, AppGate, Xage, UiPath, AI Agent orchestration, Zero Trust AI governance, legacy rationalization, ROM cost estimates, and relevant certifications.
• Medical, dental, and vision insurance.
• 401(k) retirement plan.
• Paid time off.
• Paid parental leave.
• Life and disability insurance.
• Flexible spending accounts.
• Commuter benefits.
• Tuition reimbursement.
Shield AI
Netflix
Travoom
HeroSoftware GmbH - Shopify Apps
Get handpicked remote jobs straight to your inbox weekly.