user avatar

Sr Okta IAM Engineer

Koniag Government Services

Posted today

Job Requirements

Washington, DC
Intel Agency (NSA, CIA, FBI, etc) Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Okta IAM Engineer (Senior) to support enterprise identity and access management operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Okta Identity and Access Management capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, hybrid environments, and enterprise applications.

The ideal candidate is a highly experienced and technically authoritative identity and access management engineer with deep, hands-on expertise across the full Okta platform portfolio-including Okta Workforce Identity Cloud, Okta Customer Identity Cloud (Auth0), Okta Universal Directory, Adaptive Multi-Factor Authentication (AMFA), Single Sign-On (SSO), Lifecycle Management, API Access Management, Advanced Server Access, and Privileged Access-combined with a comprehensive understanding of enterprise identity architecture, Zero Trust identity principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Okta IAM capabilities that protect Government identities, enforce least-privilege access, and support Zero Trust objectives in a highly regulated federal IT environment.

The Okta IAM Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Okta platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise identity and access management infrastructure. This individual works closely with security engineers, network engineers, cloud operations teams, Zero Trust engineers, DevSecOps engineers, application developers, Microsoft infrastructure teams, and Government stakeholders to ensure Okta IAM capabilities are architected, deployed, and operated in a manner that delivers maximum identity security, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.

Principal responsibilities will include but are not limited to:

Architecture & Engineering Leadership
  • Serve as the program's technical authority and subject matter expert for all Okta platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders on identity architecture, access management strategy, and Zero Trust identity implementation.
  • Lead the design and architecture of enterprise Okta IAM solutions, including Okta tenant architecture design, Universal Directory configuration, Adaptive MFA policy frameworks, SSO integration architectures, Lifecycle Management automation configurations, and API Access Management implementations aligned with Federal Zero Trust requirements and program security objectives.
  • Develop and maintain enterprise Okta architecture documentation, including identity architecture diagrams, authentication flow diagrams, SSO integration catalogs, Universal Directory schema designs, Lifecycle Management workflow documentation, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
  • Lead identity architecture reviews for new systems, applications, cloud migrations, and infrastructure changes, assessing Okta platform impact, identifying identity security risks, and recommending configuration and policy improvements to maintain Zero Trust identity posture.
  • Design and implement Zero Trust identity architectures leveraging Okta capabilities, including risk-based adaptive authentication, continuous session monitoring, phishing-resistant MFA enforcement, device trust integration, and least-privilege access governance across the enterprise.
  • Evaluate emerging Okta platform capabilities, identity security industry developments, and Federal identity policy requirements, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance identity security and advance Zero Trust maturity.
  • Provide senior technical leadership and mentorship to junior and mid-level engineers, sharing Okta IAM expertise, guiding technical development, and ensuring consistent application of identity engineering best practices across the team.

Okta Tenant Administration & Engineering
  • Lead the engineering, implementation, and administration of the enterprise Okta tenant, ensuring the tenant is properly configured, secured, and continuously maintained in alignment with Federal security requirements, Okta security best practices, and applicable security baseline standards.
  • Design and maintain the enterprise Okta tenant configuration, including org-level security settings, session management policies, network zone definitions, ThreatInsight configurations, and delegated authentication policies aligned with Zero Trust identity principles.
  • Implement and maintain enterprise Okta authenticator configurations, ensuring phishing-resistant authentication factors-including FIDO2 WebAuthn security keys, Okta Verify with device biometrics, PIV/CAC certificate-based authentication, and other approved strong authentication methods-are deployed, enforced, and operationally managed across all user populations.
  • Configure and maintain Okta branding and customization settings, including custom domains, sign-in page customization, and email template configurations, ensuring consistent and professional user authentication experiences aligned with Government identity and branding requirements.
  • Administer Okta directory objects, including user profiles, group configurations, organizational units, and agent-managed directory integrations, ensuring accurate provisioning, lifecycle management, and deprovisioning in accordance with defined identity governance procedures.
  • Implement and maintain Okta group management policies, including group rules for dynamic group membership assignment, group naming conventions, and group-based application access assignment configurations.
  • Monitor Okta tenant health, service availability, and operational metrics using Okta System Log and Health Insight dashboard capabilities, proactively identifying and resolving tenant configuration issues, service disruptions, and security anomalies.

Okta Universal Directory Engineering
  • Lead the engineering, implementation, and administration of Okta Universal Directory (UD), designing and maintaining a comprehensive, well-structured directory architecture that serves as the authoritative identity aggregation and management layer for all enterprise identity sources.
  • Design and implement Okta Universal Directory profile schemas, including custom attribute definitions, profile mappings, and attribute sourcing configurations, ensuring the UD accurately represents all relevant user identity attributes from all integrated identity sources.
  • Configure and maintain Okta directory integrations, including Active Directory (AD) agent deployments, LDAP directory integrations, HR system integrations (e.g., Workday, SAP SuccessFactors), and custom API-based identity source integrations, ensuring accurate and reliable identity data synchronization across all connected sources.
  • Implement and maintain Okta profile mastering configurations, defining authoritative attribute source hierarchies and conflict resolution policies that ensure directory data quality and consistency across all integrated identity sources.
  • Develop and maintain Universal Directory documentation, including directory schema specifications, profile mapping configurations, integration architecture diagrams, and data governance procedures.

Adaptive Multi-Factor Authentication (AMFA) Engineering
  • Lead the design, implementation, and continuous optimization of the enterprise Okta Adaptive Multi-Factor Authentication policy framework, ensuring all access to Government applications and resources is protected by risk-appropriate, continuously evaluated authentication requirements aligned with Zero Trust principles.
  • Design and implement a comprehensive Okta authentication policy architecture, including global session policies, authentication enrollment policies, application-level authentication policies, and assurance-based policy structures that collectively enforce least-privilege, risk-based authentication requirements across the enterprise.
  • Implement and maintain phishing-resistant MFA enforcement configurations, ensuring FIDO2 WebAuthn, PIV/CAC certificate-based authentication, and other approved phishing-resistant factors are required for all high-value and privileged access scenarios.
  • Configure and maintain Okta ThreatInsight and behavioral risk signal integrations, ensuring sign-in risk context-including device reputation, network anomalies, velocity signals, and behavioral patterns-is accurately incorporated into adaptive authentication policy decisions.
  • Implement and maintain device trust policy integrations between Okta AMFA and enterprise endpoint management platforms, including Microsoft Intune and other MDM solutions, ensuring device compliance signals are accurately assessed and integrated into authentication policy enforcement decisions.
  • Manage AMFA policy lifecycle, including regular policy review and optimization cycles, policy documentation maintenance, exclusion management, and impact assessment for proposed policy changes.

Single Sign-On (SSO) Engineering & Application Integration
  • Lead the engineering, implementation, and administration of enterprise Okta SSO integrations, designing and implementing a comprehensive SSO architecture that enables seamless, secure, and policy-governed access to all integrated Government applications.
  • Design and implement SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0-based SSO integrations between enterprise applications and Okta, ensuring all integrated applications leverage centralized Okta authentication and MFA enforcement rather than application-managed credential stores.
  • Implement and maintain Okta Integration Network (OIN) application configurations for commercial SaaS applications, custom SAML and OIDC application integrations for Government-developed applications, and Secure Web Authentication (SWA) configurations where modern federation protocols are not supported.
  • Configure and maintain application-level sign-on policies, ensuring appropriate authentication assurance levels, MFA requirements, and session controls are enforced for each integrated application based on its sensitivity, data classification, and user population.
  • Develop and maintain an enterprise SSO application catalog, documenting all Okta-integrated applications, their integration protocols, assigned sign-on policies, provisioning configurations, and responsible application owner contacts.
  • Support the evaluation and onboarding of new applications to the Okta SSO platform, providing integration guidance, technical feasibility assessment, and implementation support to application development teams and Government stakeholders.

Lifecycle Management Engineering
  • Lead the engineering, implementation, and administration of Okta Lifecycle Management capabilities, designing and implementing automated identity provisioning, profile synchronization, and deprovisioning workflows that ensure user access is accurately managed throughout the identity lifecycle.
  • Design and implement Okta Lifecycle Management provisioning integrations for all in-scope enterprise applications, configuring application-specific provisioning mappings, attribute synchronization rules, and deprovisioning action configurations.
  • Implement and maintain Okta workflows for complex lifecycle automation scenarios, including joiner, mover, and leaver process automation, access request fulfillment, exception handling, and custom provisioning logic using Okta Workflows (formerly Okta Workflow Automation).
  • Configure and maintain HR-driven identity lifecycle integrations, ensuring user account provisioning, profile updates, and deprovisioning are automatically triggered based on authoritative HR system events and defined workflow logic.
  • Develop and maintain lifecycle management documentation, including provisioning integration specifications, workflow logic documentation, and exception handling procedures, ensuring lifecycle automation is well-documented and maintainable.
  • Monitor lifecycle management process health, identifying and resolving provisioning failures, synchronization errors, and workflow execution issues that may impact user access or identity data quality.

API Access Management Engineering
  • Lead the engineering, implementation, and administration of Okta API Access Management capabilities, designing and implementing a comprehensive API security framework that protects Government APIs through centralized, policy-governed OAuth 2.0 and OIDC-based authorization.
  • Design and implement Okta Authorization Server configurations, including custom authorization servers, OAuth 2.0 scope definitions, claim configurations, and access policy rules that enforce least-privilege API access across all protected Government APIs.
  • Implement and maintain Okta API access policies, including client credential flow configurations for machine-to-machine API access, authorization code flow configurations for user-delegated API access, and token validation configurations for API gateway integrations.
  • Configure and maintain Okta OAuth 2.0 client application registrations, ensuring all API clients are properly registered, access-controlled, and subject to appropriate token lifetime and refresh policies.
  • Integrate Okta API Access Management with enterprise API gateways and API security platforms, ensuring all API access is centrally authenticated, authorized, and auditable through the Okta authorization framework.
  • Develop and maintain API access management documentation, including authorization server configurations, scope catalogs, client application registries, and API security policy specifications.

Okta Privileged Access Engineering
  • Lead the engineering, implementation, and administration of Okta Privileged Access capabilities, ensuring privileged access to enterprise infrastructure, servers, and administrative interfaces is governed through just-in-time access provisioning, session recording, and continuous monitoring.
  • Design and implement Okta Advanced Server Access (ASA) or Okta Privileged Access configurations for server and infrastructure access management, replacing standing privileged credentials with ephemeral, just-in-time access certificates and providing comprehensive privileged session visibility.
  • Configure and maintain privileged access policies, approval workflows, and session monitoring configurations, ensuring all privileged access is properly authorized, time-limited, auditable, and continuously monitored.
  • Integrate Okta privileged access capabilities with enterprise SIEM and security monitoring platforms, ensuring privileged access events are incorporated into the program's broader security monitoring and anomaly detection workflows.

Security Operations & Threat Intelligence Integration
  • Lead the integration of Okta System Log, security event data, ThreatInsight detections, and Identity Governance findings with the enterprise SIEM platform, ensuring Okta identity telemetry is reliably forwarded, accurately parsed, and available for detection, investigation, and compliance reporting.
  • Develop and maintain Okta-specific SIEM detection content, including correlation rules, behavioral analytics, and alerting configurations that leverage Okta telemetry to detect identity-based threats, account compromise, credential stuffing, privilege escalation, and anomalous authentication patterns.
  • Support incident response activities involving identity-based security events, providing expert Okta platform knowledge and remediation capabilities to investigation and containment efforts, including account suspension, session revocation, and MFA factor resets.
  • Conduct Okta threat hunting activities, proactively searching for indicators of identity compromise, anomalous authentication patterns, and unauthorized access within Okta System Log data.
  • Integrate Okta with enterprise threat intelligence platforms, ensuring threat intelligence signals are incorporated into Okta ThreatInsight and risk-based authentication policy decisions.

Change Management & Operations
  • Lead the preparation and submission of Okta change requests for Change Advisory Board (CAB) review, developing comprehensive implementation plans, technical impact assessments, rollback procedures, and test plans for all significant platform changes.
  • Coordinate with the change management process to ensure all Okta platform changes are properly reviewed, approved, scheduled, and implemented without degradation to identity services, authentication availability, or security posture.
  • Conduct post-implementation reviews for significant Okta platform changes, documenting outcomes, unexpected impacts, and lessons learned to continuously improve change execution practices.
  • Develop and maintain comprehensive Okta operational runbooks, standard operating procedures, and knowledge base articles, ensuring documentation supports reliable and consistent platform operations.

Compliance, ATO & Continuous Monitoring
  • Ensure all Okta platform configurations are maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, HSPD-12/FIPS 201, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies.
  • Support ATO activities for Okta-dependent systems and applications, including identity security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence co
group id: 10201473
Find Koniag Government Services on Social Media
Recruiters
user avatar
About Us
Koniag Government Services (KGS) supports the values and traditions of our Native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services, and Operational Management to Federal Government Agencies. We apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and Native communities. Through our wholly-owned subsidiary companies, including SBA Certified 8(a) and HUBZone companies, we provide exceptional service to our Government clients with a committed focus on: Community Mission. Solution Oriented. Exceptional People.

Koniag Government Services Jobs