Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Middleware Engineer with a Secret security clearance to support KITS and our government customer. The position is remote.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Middleware Engineer to support a critical Government Identity, Credential, and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Middleware Engineer will serve as a specialized technical contributor responsible for designing, developing, and deploying custom middleware solutions, integration tools, connectors, and scripts that enable legacy and non-standard applications to integrate with the centralized ICAM technical stack—leveraging Okta for Identity Provider (IdP) services and SailPoint IdentityIQ (IIQ) for Identity Governance and Administration (IGA)—in direct support of the Department of Defense (DoD) Zero Trust Execution Roadmap.
The ideal candidate is a skilled software and integration engineer with deep experience in middleware development, API design, and enterprise application integration. This individual must be comfortable operating in a complex federal IT environment where applications span a wide spectrum of technical maturity—from modern cloud-native systems to deeply entrenched legacy codebases—and where custom engineering solutions are often required to bridge the gap between legacy identity mechanisms and modern ICAM capabilities.
This position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed remotely.
The Middleware Engineer will serve as the primary technical expert for custom integration development within the ICAM enablement program, responsible for engineering bespoke middleware solutions that facilitate the onboarding of applications that cannot natively support modern identity protocols. This individual will work closely with migration engineers, the Okta/SailPoint platform engineer, the migration team lead, and application owners to analyze integration requirements, design appropriate technical solutions, and deliver production-ready middleware capabilities that are secure, scalable, and maintainable. The Middleware Engineer is expected to apply sound software engineering principles and federal security standards to all developed solutions while maintaining rigorous documentation and contributing to the broader enablement program.
Principal responsibilities will include but are not limited to:
- Design, develop, test, and deploy custom middleware solutions, integration proxies, protocol translators, and adapter components that enable legacy applications to authenticate and authorize through the ICAM technical stack when native protocol support is unavailable.
- Engineer custom connectors, REST and SOAP APIs, scripts, and integration libraries that facilitate the connection of non-standard applications to Okta IdP and SailPoint IIQ, leveraging existing platform connectors where possible and developing bespoke solutions where they are not.
- Analyze legacy application architectures, authentication mechanisms, and data flows to identify integration gaps and design technically sound middleware approaches that bridge proprietary or outdated identity systems with modern SAML, OAuth 2.0, OIDC, and SCIM-based ICAM capabilities.
- Develop and maintain reusable integration libraries, sample code repositories, and middleware components that can be leveraged across multiple application enablement efforts to accelerate onboarding velocity and reduce duplicative engineering effort.
- Collaborate with migration engineers to support the technical triage of assigned applications, providing middleware feasibility assessments and contributing to the documentation of integration pathways, risk registers, and gap analyses in the Enablement Tracking Database.
- Provide technical guidance and engineering support to Application Owners who are undertaking their own integration efforts, including advising on middleware architecture, providing sample code for common integration patterns, and troubleshooting application-side integration failures.
- Support the design and implementation of automated provisioning and deprovisioning workflows, including the development of SCIM endpoints, directory synchronization scripts, and lifecycle management hooks for applications that require custom provisioning solutions.
- Develop and implement solutions that support the configuration of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) frameworks within target applications, including the development of attribute mapping logic, claims transformation middleware, and authorization policy enforcement components.
- Participate in the engineering and development of self-service and automated enablement pathway tooling, contributing reusable middleware components and integration accelerators that simplify the onboarding process for application owners navigating the enablement pipeline independently.
- Conduct rigorous unit testing, integration testing, and security testing of all developed middleware solutions prior to deployment, ensuring solutions are functionally correct, secure, and compliant with applicable DoD standards.
- Support the testing program by contributing to test plan development, executing technical integration tests, providing sample code and reusable libraries for UAT events, and assisting with defect diagnosis and resolution for middleware-related integration failures.
- Ensure all developed middleware, connectors, scripts, and custom tools comply with applicable supply chain risk management requirements per DFARS 239.73, including vetting all third-party code libraries and dependencies to prevent the introduction of cybersecurity vulnerabilities, malicious code, or unauthorized data exfiltration pathways.
- Produce and maintain comprehensive technical documentation for all developed middleware solutions, including architecture diagrams, data flow diagrams, API specifications, deployment guides, and operational runbooks.
- Contribute to the development and continuous improvement of middleware engineering standards, coding best practices, reusable component libraries, and integration playbooks that drive consistency and quality across the application portfolio.
- Ensure all developed solutions comply with Section 508 accessibility standards and applicable DoD security requirements, including CUI handling, OPSEC, and DFARS 252.204-7012.
- Maintain current knowledge of evolving middleware technologies, identity integration patterns, and DoD Zero Trust requirements, proactively applying this knowledge to improve the quality and capability of developed solutions.
Education and Experience:
Required:
- Bachelor's degree in Computer Science, Software Engineering, Information Technology, Information Systems, or a related field from an accredited college or university.
- Minimum of 5 years of hands-on software or systems engineering experience, with at least 3 years of direct experience in middleware development, API engineering, or enterprise application integration.
- Demonstrated experience designing and developing custom integration solutions, including REST APIs, SOAP web services, protocol adapters, or middleware components in a production enterprise environment.
- Experience integrating applications with enterprise identity platforms using SAML, OAuth 2.0, OIDC, or SCIM.
- Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.
Preferred:
- Prior experience supporting DoD IT programs, particularly within an ICAM, cybersecurity, or Zero Trust context.
- Experience working in a federal government IT contracting environment.
- Experience developing middleware solutions specifically for legacy application modernization or enterprise identity migration programs.
Required Skills and Competencies:
- Strong proficiency in one or more programming languages commonly used in enterprise middleware and integration development, such as Java, Python, JavaScript, Node.js, C#, or PowerShell.
- Hands-on experience developing and consuming REST APIs and SOAP web services, including API design, versioning, authentication, and error handling best practices.
- Working knowledge and practical implementation experience with SAML 2.0, OAuth 2.0, OIDC, and SCIM identity and authorization protocols, including the ability to develop custom protocol handlers, token transformation logic, and claims mapping components.
- Experience analyzing and reverse-engineering legacy application authentication and authorization mechanisms to design compatible middleware integration approaches.
- Familiarity with enterprise Identity Provider (IdP) platforms, particularly Okta, and Identity Governance and Administration (IGA) platforms, particularly SailPoint IdentityIQ (IIQ), including their integration APIs and connector frameworks.
- Experience developing and working with directory services integration, including LDAP, Active Directory, and SCIM-based directory synchronization.
- Proficiency with source code version control systems such as Git, including branching strategies, code review processes, and collaborative development workflows.
- Experience implementing secure coding practices, including input validation, secrets management, least-privilege access, and vulnerability mitigation in developed middleware solutions.
- Ability to conduct unit testing, integration testing, and security-focused code reviews of developed solutions, ensuring quality and compliance prior to deployment.
- Strong analytical and problem-solving skills with the ability to assess complex legacy application architectures and design pragmatic, technically sound middleware integration solutions.
- Strong technical documentation skills, including the ability to produce clear and comprehensive architecture diagrams, data flow diagrams, API specifications, and operational runbooks.
- Familiarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, DFARS 239.73 supply chain risk management, and DoDM 8140.03 cybersecurity certification requirements.
- Strong communication skills in English—both written and oral—with the ability to clearly explain middleware architecture and integration approaches to both technical peers and non-technical application owners.
- Ability to work effectively both independently and as part of a collaborative cross-functional team.
- Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.
- Ability to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent).
Clearance Requirement:
Desired Skills and Competencies:
- Experience with enterprise service bus (ESB) platforms, integration platforms as a service (iPaaS), or API gateway technologies such as MuleSoft, Apache Camel, Kong, or AWS API Gateway.
- Experience developing middleware solutions specifically for identity protocol translation, including building SAML service providers, OAuth authorization servers, or OIDC relying party components.
- Familiarity with containerization and container orchestration technologies such as Docker and Kubernetes, including the deployment and management of containerized middleware components.
- Experience with CI/CD pipeline development and automation tools such as Jenkins, GitLab CI, or Azure DevOps for automated build, test, and deployment of middleware solutions.
- Okta Certified Developer certification or demonstrated advanced proficiency with the Okta platform APIs and integration frameworks.
- SailPoint IdentityIQ developer experience, including custom connector development using the SailPoint connector framework and BeanShell scripting.
- Knowledge of Zero Trust Architecture (ZTA) principles and their practical application to middleware and integration engineering within a DoD context.
- Experience developing SCIM 2.0 compliant endpoints and providers for automated identity provisioning and synchronization.
- Familiarity with claims-based identity concepts, including claims transformation, attribute mapping, and token enrichment in federated identity environments.
- Experience with enterprise application portfolio migrations or large-scale IT modernization programs in a federal defense environment.
- Certified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification.
- Familiarity with Section 508 compliance requirements for electronic and information technology.
- Experience with CDRL deliverable contribution and technical documentation requirements in a federal contracting environment.
- Familiarity with Agile and hybrid Agile-Waterfall program execution methodologies, including experience working in sprint-based development cycles.
- Experience developing reusable code libraries and integration accelerators in support of large-scale, repeatable application onboarding or migration programs.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352