For Employers
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The CDO-L Study Lead Engineer will lead a focused technical study to extend secure ICAM capabilities into contested and disconnected environments. Responsibilities include conducting gap analyses, developing architectural recommendations, and producing a decision-ready Technical Study Report.

This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible. 

Koniag IT Systems, LLC a Koniag Government Services company, is seeking a CDO-L Study Lead Engineer with a Secret security clearance to support KITS and our government customer. The position is remote. 

 

Koniag IT Systems, LLC a Koniag Government Services company, is seeking an experienced CDO-L Study Lead Engineer to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will lead a focused, technically grounded study effort under Task Order 0003, System Enhancement Studies, with a primary focus on extending secure ICAM capabilities into Contested, Degraded, and Operationally Limited (CDO-L) environments. The ideal candidate is a technically seasoned engineer and collaborative leader with deep experience in Defense ICAM architectures, Zero Trust frameworks, and disconnected/edge identity solutions who can translate complex operational requirements into actionable architectures and implementation roadmaps.

 

*This study will run 120 days. All personnel assigned to CDO-L study activities must hold a final Secret security clearance. 

 

The CDO-L Study Lead Engineer will serve as the primary technical authority for Study 1 of the DAF ICAM System Enhancement Studies effort, leading the analysis, architecture development, and documentation required to produce a decision-ready Technical Study Report within 45 calendar days of Task Order award. The Lead Engineer will coordinate closely with the Program Manager, Systems Architecture Team, Licensing/Cost Analyst, and Government stakeholders to ensure all study outputs are technically sound, operationally grounded, and fully traceable to Performance Work Statement (PWS) Section 4.1 requirements.

 

Principal responsibilities will include but are not limited to:

  • Lead the structured review of Government-provided CDO-L requirements published at the DoD Enterprise ICAM IL5 and IL6 DDIL reference site, cataloging each requirement by operational condition (denied, degraded, intermittent, and limited bandwidth) and mapping them against existing DAF ICAM solution components including Okta Universal Directory (UD), Okta Identity Provider (IdP), and SailPoint IdentityIQ (IIQ).
  • Conduct a gap analysis between current DAF ICAM capabilities and CDO-L operational demands to serve as the foundation for all architectural recommendations.
  • Evaluate existing approved ICAM solutions across comparable Federal Defense programs and assess their applicability to DAF CDO-L requirements, prioritizing solutions that extend existing approved capabilities rather than introducing net-new vendor stacks.
  • Lead the architectural analysis of options for on-premises replication or caching of identity and access data at disconnected nodes, evaluating a tiered edge identity broker model across three operational states: Connected, Degraded/Limited Bandwidth, and Denied.
  • Assess and document synchronization schedules, minimum connectivity requirements, degraded-mode operating parameters, and cache staleness thresholds for each operational state.
  • Evaluate specific DAF ICAM-aligned edge components including Okta Access Gateway (OAG) and Tactical Identity Bridge Appliance (TIBA) for their suitability in extending ICAM operations to the tactical edge.
  • Assess how existing SailPoint IIQ governance workflows can be mirrored at the edge to maintain entitlement integrity during disconnected operations.
  • Document tradeoffs between full replication, selective caching, and read-only policy mirroring, and provide a recommended approach with clear technical rationale grounded in DAF operational requirements.
  • Develop recommendations for emergency "break-glass" access provisioning in fully offline or denied-state conditions, including governance controls, immutable local audit logging, and automated revocation and re-synchronization workflows.
  • Evaluate approaches for PKI certificate validation in CDO-L conditions, including Certificate Revocation List (CRL) caching and local Online Certificate Status Protocol (OCSP) stapling at edge nodes to sustain Common Access Card (CAC)-based authentication.
  • Analyze how endpoint security telemetry collected locally during a disconnected period integrates with the identity layer and how the edge identity broker can autonomously enforce access revocation when device security posture degrades.
  • Develop a formal methodology for attribute transfer and synchronization between enterprise NIPRNet and SIPRNet environments and disconnected nodes upon reconnection, addressing conflict resolution, synchronization priorities, audit log consolidation, reconciliation validation, and failure/fallback procedures.
  • Coordinate with the Licensing/Cost Analyst to produce a structured identification of all software components required for the recommended CDO-L architecture, including licensing structure, edge deployment constraints, classified-network restrictions, and interoperability considerations.
  • Coordinate with the Program Manager and Licensing/Cost Analyst to develop a detailed, phased implementation roadmap and ROM cost estimate covering development, licensing, hardware, integration, testing, and deployment.
  • Consolidate all study outputs into the CDO-L Technical Study Report (CDRL B010), ensuring each section maps directly to a PWS Section 4.1 requirement and includes a draft Performance Work Statement suitable for a subsequent implementation Task Order.
  • Verify that all assigned personnel hold the required security clearances prior to engagement and notify the Government immediately of any clearance status changes.
  • Present study findings to Government Program Manager and Contracting Officer's Representative (COR) as required throughout the study period.

 

Education and Experience:

Required:

  • Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university.
  • 7+ years of experience in systems engineering, enterprise architecture, or identity and access management within Defense or Federal government IT environments.
  • Demonstrated experience designing or analyzing identity and access management architectures in disconnected, air-gapped, or operationally constrained network environments.
  • Experience with the DoD Authority to Operate (ATO) process and security accreditation requirements for Defense information systems.
  • Active Secret security clearance (final adjudication required prior to assignment).

Preferred:

  • Master's degree in a related technical field.
  • 10+ years of experience in Defense ICAM, enterprise identity architecture, or related cybersecurity engineering disciplines.
  • Experience supporting DISA-aligned programs or DAF/Air Force ICAM initiatives.

 

Required Skills and Competencies:

  • Deep technical knowledge of enterprise Identity, Credential, and Access Management (ICAM) platforms, with specific expertise in Okta (Universal Directory, Identity Provider, Access Gateway, Workflows) and SailPoint IdentityIQ (IIQ).
  • Strong understanding of Zero Trust Architecture (ZTA) principles and their application to tactical edge and disconnected identity environments.
  • Experience designing identity federation, replication, and caching architectures for disconnected or intermittently connected operational environments.
  • Proficiency in PKI-based authentication concepts, including Certificate Revocation Lists (CRL), Online Certificate Status Protocol (OCSP), and Common Access Card (CAC) authentication.
  • Knowledge of Attribute-Based Access Control (ABAC) and Role-Based Access Control (RBAC) policy frameworks and their implementation within Okta and SailPoint platforms.
  • Familiarity with NIPRNet and SIPRNet network architecture, classification requirements, and cross-domain constraints.
  • Ability to perform and document structured gap analyses, architectural tradeoff assessments, and comparative technology evaluations.
  • Experience developing phased implementation roadmaps with clearly defined entry/exit criteria, dependencies, and realistic Government review and accreditation timelines.
  • Strong technical writing skills with the ability to produce formal study reports, architectural documentation, and draft Performance Work Statements suitable for Government use.
  • Ability to work collaboratively across cross-functional technical teams including architects, engineers, cost analysts, and program managers.
  • Exceptional communication skills in English—both written and oral—with the ability to present complex technical findings clearly to both technical and non-technical Government stakeholders.
  • Ability to obtain and maintain a Secret security clearance.

 

Desired Skills and Competencies:

  • Experience with Okta Access Gateway (OAG) and/or Tactical Identity Bridge Appliance (TIBA) in edge deployment contexts.
  • Familiarity with DoD Enterprise ICAM IL5/IL6 DDIL requirements and related DoD ICAM policy frameworks.
  • Knowledge of emergency "break-glass" access provisioning governance and associated audit/logging requirements in classified environments.
  • Experience integrating endpoint security telemetry with identity and access management platforms for continuous posture-based access enforcement.
  • Familiarity with Security Information and Event Management (SIEM) systems and audit log consolidation in Defense environments.
  • Knowledge of Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and their application to identity platform components.
  • Experience developing Rough Order of Magnitude (ROM) cost estimates for complex, multi-phase Defense IT implementation programs.
  • Okta Certified Professional, Okta Certified Administrator, SailPoint Certified IdentityIQ Engineer, or equivalent identity platform certification.
  • CISSP, CISM, or equivalent cybersecurity certification.
  • Experience supporting DAF, Air Force, or Space Force IT modernization programs.
  • Familiarity with Agile development methodologies and their application within hybrid Agile/Waterfall Government program environments.

 

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

 

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

 

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

 

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Junior Network Engineer

Full Time United States Software Development

Databricks Platform Engineer

Full Time United States Software Development

Data Engineer II

Full Time Brazil Software Development

Power Platform & Copilot Studio Architect

Full Time Canada, United States 120K - 151K per year Software Development

Sr Guidance, Navigation & Controls Engineer

Full Time United States $142K - $195K per year Software Development

Senior Perception Engineer

Full Time United States Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 221,287+ Jobs in Software Development

Answer easy questions

Answer easy questions

221,287+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified