Skip to content

Open nowPosted 34 days ago

Sr Okta IAM Engineer

kgs404 open roles

Where
Washington, DC, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr Okta IAM Engineerkgs · Washington, DC, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kgs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 34 days ago

The posting

  This position may be filled prior to the posted deadline.  Interested candidates are encouraged to apply as soon as possible.   Koniag Operations Services, LLC (KOS), a Koniag Government Services company, is seeking an experienced Okta IAM Engineer (Senior) to support enterprise identity and access management operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.   Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.    This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Okta Identity and Access Management capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, hybrid environments, and enterprise applications.   The ideal candidate is a highly experienced and technically authoritative identity and access management engineer with deep, hands-on expertise across the full Okta platform portfolio—including Okta Workforce Identity Cloud, Okta Customer Identity Cloud (Auth0), Okta Universal Directory, Adaptive Multi-Factor Authentication (AMFA), Single Sign-On (SSO), Lifecycle Management, API Access Management, Advanced Server Access, and Privileged Access—combined with a comprehensive understanding of enterprise identity architecture, Zero Trust identity principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Okta IAM capabilities that protect Government identities, enforce least-privilege access, and support Zero Trust objectives in a highly regulated federal IT environment.   The Okta IAM Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Okta platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise identity and access management infrastructure. This individual works closely with security engineers, network engineers, cloud operations teams, Zero Trust engineers, DevSecOps engineers, application developers, Microsoft infrastructure teams, and Government stakeholders to ensure Okta IAM capabilities are architected, deployed, and operated in a manner that delivers maximum identity security, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.   Principal responsibilities will include but are not limited to: Architecture & Engineering Leadership

Serve as the program's technical authority and subject matter expert for all Okta platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders on identity architecture, access management strategy, and Zero Trust identity implementation. Lead the design and architecture of enterprise Okta IAM solutions, including Okta tenant architecture design, Universal Directory configuration, Adaptive MFA policy frameworks, SSO integration architectures, Lifecycle Management automation configurations, and API Access Management implementations aligned with Federal Zero Trust requirements and program security objectives. Develop and maintain enterprise Okta architecture documentation, including identity architecture diagrams, authentication flow diagrams, SSO integration catalogs, Universal Directory schema designs, Lifecycle Management workflow documentation, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality. Lead identity architecture reviews for new systems, applications, cloud migrations, and infrastructure changes, assessing Okta platform impact, identifying identity security risks, and recommending configuration and policy improvements to maintain Zero Trust identity posture. Design and implement Zero Trust identity architectures leveraging Okta capabilities, including risk-based adaptive authentication, continuous session monitoring, phishing-resistant MFA enforcement, device trust integration, and least-privilege access governance across the enterprise. Evaluate emerging Okta platform capabilities, identity security industry developments, and Federal identity policy requirements, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance identity security and advance Zero Trust maturity. Provide senior technical leadership and mentorship to junior and mid-level engineers, sharing Okta IAM expertise, guiding technical development, and ensuring consistent application of identity engineering best practices across the team.

Okta Tenant Administration & Engineering

Lead the engineering, implementation, and administration of the enterprise Okta tenant, ensuring the tenant is properly configured, secured, and continuously maintained in alignment with Federal security requirements, Okta security best practices, and applicable security baseline standards. Design and maintain the enterprise Okta tenant configuration, including org-level security settings, session management policies, network zone definitions, ThreatInsight configurations, and delegated authentication policies aligned with Zero Trust identity principles. Implement and maintain enterprise Okta authenticator configurations, ensuring phishing-resistant authentication factors—including FIDO2 WebAuthn security keys, Okta Verify with device biometrics, PIV/CAC certificate-based authentication, and other approved strong authentication methods—are deployed, enforced, and operationally managed across all user populations. Configure and maintain Okta branding and customization settings, including custom domains, sign-in page customization, and email template configurations, ensuring consistent and professional user authentication experiences aligned with Government identity and branding requirements. Administer Okta directory objects, including user profiles, group configurations, organizational units, and agent-managed directory integrations, ensuring accurate provisioning, lifecycle management, and deprovisioning in accordance with defined identity governance procedures. Implement and maintain Okta group management policies, including group rules for dynamic group membership assignment, group naming conventions, and group-based application access assignment configurations. Monitor Okta tenant health, service availability, and operational metrics using Okta System Log and Health Insight dashboard capabilities, proactively identifying and resolving tenant configuration issues, service disruptions, and security anomalies.

Okta Universal Directory Engineering

Lead the engineering, implementation, and administration of Okta Universal Directory (UD), designing and maintaining a comprehensive, well-structured directory architecture that serves as the authoritative identity aggregation and management layer for all enterprise identity sources. Design and implement Okta Universal Directory profile schemas, including custom attribute definitions, profile mappings, and attribute sourcing configurations, ensuring the UD accurately represents all relevant user identity attributes from all integrated identity sources. Configure and maintain Okta directory integrations, including Active Directory (AD) agent deployments, LDAP directory integrations, HR system integrations (e.g., Workday, SAP SuccessFactors), and custom API-based identity source integrations, ensuring accurate and reliable identity data synchronization across all connected sources. Implement and maintain Okta profile mastering configurations, defining authoritative attribute source hierarchies and conflict resolution policies that ensure directory data quality and consistency across all integrated identity sources. Develop and maintain Universal Directory documentation, including directory schema specifications, profile mapping configurations, integration architecture diagrams, and data governance procedures.

Adaptive Multi-Factor Authentication (AMFA) Engineering

Lead the design, implementation, and continuous optimization of the enterprise Okta Adaptive Multi-Factor Authentication policy framework, ensuring all access to Government applications and resources is protected by risk-appropriate, continuously evaluated authentication requirements aligned with Zero Trust principles. Design and implement a comprehensive Okta authentication policy architecture, including global session policies, authentication enrollment policies, application-level authentication policies, and assurance-based policy structures that collectively enforce least-privilege, risk-based authentication requirements across the enterprise. Implement and maintain phishing-resistant MFA enforcement configurations, ensuring FIDO2 WebAuthn, PIV/CAC certificate-based authentication, and other approved phishing-resistant factors are required for all high-value and privileged access scenarios. Configure and maintain Okta ThreatInsight and behavioral risk signal integrations, ensuring sign-in risk context—including device reputation, network anomalies, velocity signals, and behavioral patterns—is accurately incorporated into adaptive authentication policy decisions. Implement and maintain device trust policy integrations between Okta AMFA and enterprise endpoint management platforms, including Microsoft Intune and other MDM solutions, ensuring device compliance signals are accurately assessed and integrated into authentication policy enforcement decisions. Manage AMFA policy lifecycle, including regular policy review and optimization cycles, policy documentation maintenance, exclusion management, and impact assessment for proposed policy changes.

Single Sign-On (SSO) Engineering & Application Integration

Lead the engineering, implementation, and administration of enterprise Okta SSO integrations, designing and implementing a comprehensive SSO architecture that enables seamless, secure, and policy-governed access to all integrated Government applications. Design and implement SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0-based SSO integrations between enterprise applications and Okta, ensuring all integrated applications leverage centralized Okta authentication and MFA enforcement rather than application-managed credential stores. Implement and maintain Okta Integration Network (OIN) application configurations for commercial SaaS applications, custom SAML and OIDC application integrations for Government-developed applications, and Secure Web Authentication (SWA) configurations where modern federation protocols are not supported. Configure and maintain application-level sign-on policies, ensuring appropriate authentication assurance levels, MFA requirements, and session controls are enforced for each integrated application based on its sensitivity, data classification, and user population. Develop and maintain an enterprise SSO application catalog, documenting all Okta-integrated applications, their integration protocols, assigned sign-on policies, provisioning configurations, and responsible application owner contacts. Support the evaluation and onboarding of new applications to the Okta SSO platform, providing integration guidance, technical feasibility assessment, and implementation support to application development teams and Government stakeholders.

Lifecycle Management Engineering

Lead the engineering, implementation, and administration of Okta Lifecycle Management capabilities, designing and implementing automated identity provisioning, profile synchronization, and deprovisioning workflows that ensure user access is accurately managed throughout the identity lifecycle. Design and implement Okta Lifecycle Management provisioning integrations for all in-scope enterprise applications, configuring application-specific provisioning mappings, attribute synchronization rules, and deprovisioning action configurations. Implement and maintain Okta workflows for complex lifecycle automation scenarios, including joiner, mover, and leaver process automation, access request fulfillment, exception handling, and custom provisioning logic using Okta Workflows (formerly Okta Workflow Automation). Configure and maintain HR-driven identity lifecycle integrations, ensuring user account provisioning, profile updates, and deprovisioning are automatically triggered based on authoritative HR system events and defined workflow logic. Develop and maintain lifecycle management documentation, including provisioning integration specifications, workflow logic documentation, and exception handling procedures, ensuring lifecycle automation is well-documented and maintainable. Monitor lifecycle management process health, identifying and resolving provisioning failures, synchronization errors, and workflow execution issues that may impact user access or identity data quality.

API Access Management Engineering

Lead the engineering, implementation, and administration of Okta API Access Management capabilities, designing and implementing a comprehensive API security framework that protects Government APIs through centralized, policy-governed OAuth 2.0 and OIDC-based authorization. Design and implement Okta Authorization Server configurations, including custom authorization servers, OAuth 2.0 scope definitions, claim configurations, and access policy rules that enforce least-privilege API access across all protected Government APIs. Implement and maintain Okta API access policies, including client credential flow configurations for machine-to-machine API access, authorization code flow configurations for user-delegated API access, and token validation configurations for API gateway integrations. Configure and maintain Okta OAuth 2.0 client application registrations, ensuring all API clients are properly registered, access-controlled, and subject to appropriate token lifetime and refresh policies. Integrate Okta API Access Management with enterprise API gateways and API security platforms, ensuring all API access is centrally authenticated, authorized, and auditable through the Okta authorization framework. Develop and maintain API access management documentation, including authorization server configurations, scope catalogs, client application registries, and API security policy specifications.

Okta Privileged Access Engineering

Lead the engineering, implementation, and administration of Okta Privileged Access capabilities, ensuring privileged access to enterprise infrastructure, servers, and administrative interfaces is governed through just-in-time access provisioning, session recording, and continuous monitoring. Design and implement Okta Advanced Server Access (ASA) or Okta Privileged Access configurations for server and infrastructure access management, replacing standing privileged credentials with ephemeral, just-in-time access certificates and providing comprehensive privileged session visibility. Configure and maintain privileged access policies, approval workflows, and session monitoring configurations, ensuring all privileged access is properly authorized, time-limited, auditable, and continuously monitored. Integrate Okta privileged access capabilities with enterprise SIEM and security monitoring platforms, ensuring privileged access events are incorporated into the program's broader security monitoring and anomaly detection workflows.

Security Operations & Threat Intelligence Integration

Lead the integration of Okta System Log, security event data, ThreatInsight detections, and Identity Governance findings with the enterprise SIEM platform, ensuring Okta identity telemetry is reliably forwarded, accurately parsed, and available for detection, investigation, and compliance reporting. Develop and maintain Okta-specific SIEM detection content, including correlation rules, behavioral analytics, and alerting configurations that leverage Okta telemetry to detect identity-based threats, account compromise, credential stuffing, privilege escalation, and anomalous authentication patterns. Support incident response activities involving identity-based security events, providing expert Okta platform knowledge and remediation capabilities to investigation and containment efforts, including account suspension, session revocation, and MFA factor resets. Conduct Okta threat hunting activities, proactively searching for indicators of identity compromise, anomalous authentication patterns, and unauthorized access within Okta System Log data. Integrate Okta with enterprise threat intelligence platforms, ensuring threat intelligence signals are incorporated into Okta ThreatInsight and risk-based authentication policy decisions.

Change Management & Operations

Lead the preparation and submission of Okta change requests for Change Advisory Board (CAB) review, developing comprehensive implementation plans, technical impact assessments, rollback procedures, and test plans for all significant platform changes. Coordinate with the change management process to ensure all Okta platform changes are properly reviewed, approved, scheduled, and implemented without degradation to identity services, authentication availability, or security posture. Conduct post-implementation reviews for significant Okta platform changes, documenting outcomes, unexpected impacts, and lessons learned to continuously improve change execution practices. Develop and maintain comprehensive Okta operational runbooks, standard operating procedures, and knowledge base articles, ensuring documentation supports reliable and consistent platform operations.

Compliance, ATO & Continuous Monitoring

Ensure all Okta platform configurations are maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, HSPD-12/FIPS 201, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies. Support ATO activities for Okta-dependent systems and applications, including identity security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence collection. Conduct regular Okta configuration compliance assessments, identifying and remediating configuration deviations from applicable security baselines and Federal identity security requirements. Support vulnerability management activities for Okta platform components, tracking and remediating platform vulnerabilities and security configuration weaknesses identified through vendor advisories, security assessments, and continuous monitoring activities. Develop and maintain Okta compliance documentation, including configuration baseline specifications, security control implementation evidence, authentication policy documentation, and audit artifacts supporting the program's ATO and continuous monitoring obligations.

  Education and Experience: Required:

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered. Minimum of 7 years of hands-on experience in identity and access management engineering, cloud security, or a closely related discipline, with at least 4 years of demonstrated hands-on experience engineering and administering Okta Workforce Identity Cloud in an enterprise environment. Demonstrated hands-on experience designing and implementing enterprise Okta SSO integrations using SAML 2.0, OIDC, and OAuth 2.0 protocols across a diverse application portfolio. Demonstrated experience with Okta Adaptive Multi-Factor Authentication policy framework design, including risk-based authentication policies, phishing-resistant MFA enforcement, and device trust integration. Experience with Okta Lifecycle Management configuration, including application provisioning integrations, profile synchronization, and automated deprovisioning. Experience supporting identity and access management activities in a federal government IT contracting environment, including familiarity with applicable Federal cybersecurity compliance frameworks. Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.

Preferred:

Prior experience serving as a senior Okta IAM engineer or architect on a federal IT program of comparable scale and complexity. Hands-on experience with Okta API Access Management, Okta Workflows, and Okta Advanced Server Access or Okta Privileged Access platform capabilities. Experience supporting FedRAMP authorization activities and implementing Okta-based identity security controls within a Federal agency environment.

  Required Skills and Competencies:

Deep technical expertise across the Okta Workforce Identity Cloud platform portfolio, with demonstrated hands-on proficiency in tenant administration, Universal Directory engineering, Adaptive MFA policy design, SSO integration architecture, Lifecycle Management automation, and API Access Management configuration. Strong Zero Trust identity architecture skills with demonstrated ability to design, implement, and maintain enterprise-grade identity security architect

  Our Equal Employment Opportunity Policy: The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.   The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at [email protected] or by calling 703-488-9377 to request accommodations.   Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.   Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kgs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kgs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kgs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.