DAF365 JML Lead Engineer (Study 3) (REMOTE)
KgsThis position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking a DAF365 JML Lead Engineer (Study 3) with a Secret security clearance to support KITS and our government customer. The position is remote.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
Koniag IT Systems, LLC , a Koniag Government Services company, is seeking an experienced DAF365 JML Lead Engineer to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will lead a comprehensive technical study effort under Task Order 0003, System Enhancement Studies, with a primary focus on defining the architecture, workflows, and implementation roadmap required to transform the DAF365 Joiner, Mover, Leaver (JML) process from a legacy, manual, script-based identity creation model into a robust, automated, DAF ICAM-driven provisioning framework. The ideal candidate is a technically seasoned identity engineer and collaborative leader with deep hands-on experience designing attribute-based provisioning workflows in Okta Universal Directory environments integrated with Microsoft Entra ID who can translate complex operational requirements into actionable, decision-ready technical architectures and phased implementation roadmaps.
*Note, this is a 120-day study. All personnel assigned to DAF365 JML study activities must hold a final Secret security clearance. This position is Remote.
The DAF365 JML Lead Engineer will serve as the primary technical authority for Study 3 of the DAF ICAM System Enhancement Studies effort, leading the analysis, workflow design, architecture development, and documentation required to produce a decision-ready Technical Study Report within 90 calendar days of Task Order award.The Lead Engineer will coordinate closely with the Program Manager, Identity Architects, Licensing/Cost Analyst, Systems Analyst, and Government stakeholders to ensure all study outputs are technically precise, operationally grounded, and fully traceable to Performance Work Statement (PWS) Section 4.3 requirements. The study will progress through five tightly scoped analytical workstreams, each corresponding to a PWS requirement, and culminate in a phased implementation roadmap with a ROM cost estimate suitable for informing a subsequent implementation Task Order.
Principal responsibilities will include but are not limited to:
- Lead the comprehensive mapping of identity attributes currently flowing from DAF authoritative Human Resources (HR) sources—including Military Personnel Data System (MILPDS) for military personnel and Defense Civilian Personnel Data System (DCPDS) for civilian employees—into the Okta Universal Directory (UD), exposing attribute quality deficiencies, naming convention inconsistencies, and data gaps that prevent reliable Attribute-Based Access Control (ABAC) rule execution downstream.
- Define a formal attribute schema specifying required fields, accepted value formats, data type constraints, and source-of-record assignments for each attribute class relevant to DAF365 provisioning, including rank, unit, Air Force Specialty Code (AFSC), clearance level, and duty status.
- Document explicit sanitization and normalization rules defining how incoming raw HR data is transformed into clean, policy-actionable attributes within the Okta UD before any downstream provisioning event is triggered.
- Assess current data pipeline quality and identify where transformation logic must reside—within Okta Workflows, an upstream extract-transform-load (ETL) process, or a combination of both—and specify the controls that prevent attribute errors from propagating to incorrect license assignments, improper group memberships, and access control failures requiring manual remediation.
- Design a target-state technical architecture that routes all DAF365 identity management actions directly through DAF ICAM, removing the dependency on legacy intermediary systems such as Area52 Active Directory (AD), decoupling reliance on physical and logical base locations, and advancing the DAF toward full provisioning automation capability.
- Document the current-state provisioning path, identify integration touchpoints where legacy systems currently insert latency and manual steps, and define the future-state flow in which Okta serves as the authoritative orchestration layer pushing identity events directly into Microsoft Entra ID via System for Cross-domain Identity Management (SCIM) provisioning and Microsoft Graph API.
- Specify the role of Okta's on-premises provisioning agents as a bridging mechanism for environments where on-premises Active Directory dependencies remain for legacy application authentication, enabling cloud-native orchestration to extend into legacy domain environments without requiring those environments to be modernized as a precondition of JML automation.
- Document specific Entra ID configuration requirements, including tenant structure, domain federation settings, and Okta application integration parameters, required to support direct ICAM-driven provisioning, leveraging current Entra ID architecture guidance to ensure alignment with current platform capabilities and near-term feature availability.
- Define the end-to-end technical architecture for three discrete JML event types within the DAF365 environment:
- Joiner: Specify how Okta detects a new identity record in the authoritative HR source, creates a UD profile, applies ABAC rules to determine group membership, and pushes a provisioned identity into Entra ID with the correct DAF365 license tier, mailbox configuration, and group assignments before the individual arrives at their duty station. Define attribute thresholds that trigger Joiner events, the sequence of provisioning actions, and error handling behavior when required attributes are missing or malformed.
- Mover: Address the full range of organizational change events that alter a DAF member's access requirements, including Permanent Change of Station (PCS), promotion, role change, Temporary Duty (TDY), and deployment. For each event type, specify which HR system attribute change serves as the trigger, which Okta group memberships are revoked and granted, and which downstream DAF365 actions result. Define workflow routing logic, approver roles, and escalation timelines for elevated privilege changes, and specify how hardcoded expiration dates are set and enforced for temporary access grants to prevent TDY-based access from persisting beyond the operational requirement.
- Leaver: Specify the cascading revocation sequence initiated upon receipt of a separation or termination date from the HR system, including Okta disablement of the primary identity to terminate active authentication sessions across all federated applications; Entra ID session token revocation to force immediate logouts on desktop and mobile clients; DAF365 license reclamation to return the license to the enterprise pool; and automated mailbox handling to convert the O365 mailbox to a shared mailbox or place it on litigation hold in compliance with DoD data retention policy. Specify which automation tooling—such as Okta Workflows or Microsoft Power Automate—executes each step and document expected execution latency for each revocation action.
- Document the procedural framework enabling base-level administrators to provision DAF365 accounts and network access directly through DAF ICAM interfaces without requiring elevated enterprise-level access or manual intervention from centralized identity teams.
- Define the role-based access model for base-level administrators within the DAF ICAM toolset, specifying which provisioning actions are delegable, what approval gates apply, and how audit trails are generated for each action.
- Document administrator-facing workflows within Okta and SailPoint IIQ interfaces, providing step-by-step procedural guidance that base-level administrators can follow to execute Joiner, Mover, and Leaver actions within their delegated authority, and specify any configuration changes required to expose base-level provisioning capabilities.
- Quantify, based on current manual provisioning timelines, the projected reduction in provisioning latency achievable through the base-level administrator delegation model.
- Coordinate with the Program Manager and Licensing/Cost Analyst to synthesize study findings into a phased implementation roadmap and ROM cost estimate, sequencing implementation activities beginning with attribute schema formalization and data pipeline remediation as the foundational first phase, followed by direct Entra ID integration architecture, JML group management workflows, and base-level administrator delegation model in dependency-sequenced order.
- Consolidate all study outputs into the DAF365 JML Transformation Framework Technical Study Report (CDRL B010), ensuring each section maps directly to PWS Section 4.3 requirements and presents a technically precise, decision-ready product suitable for informing a future implementation Task Order.
- Submit a draft report to the Government Program Manager and COR in advance of the final 90-calendar-day delivery date to allow sufficient time for Government review and revision cycles within the 120-day Period of Performance.
- Present study findings to the Government Program Manager and Contracting Officer's Representative (COR) as required throughout the study period.
- Verify that all assigned personnel hold the required security clearances prior to engagement and notify the Government immediately of any clearance status changes.
Education and Experience:
Required:
- Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university.
- 7+ years of experience in identity and access management engineering, enterprise architecture, or identity lifecycle management within Defense or Federal government IT environments.
- Demonstrated hands-on experience designing attribute-based provisioning workflows in Okta Universal Directory environments integrated with Microsoft Entra ID or Azure Active Directory.
- Experience designing or analyzing Joiner, Mover, Leaver identity lifecycle management processes for enterprise populations in DoD or Federal environments.
- Experience with Microsoft Entra ID, including SCIM provisioning, Microsoft Graph API integration, tenant configuration, and domain federation settings.
- Active Secret security clearance (final adjudication required prior to assignment).
Preferred:
- Master's degree in a related technical field.
- 10+ years of experience in Defense or Federal ICAM, identity lifecycle engineering, or enterprise identity architecture.
- Experience supporting DAF, Air Force, Space Force, or other DoD component ICAM, Microsoft 365, or enterprise identity modernization programs.
- Direct experience with DAF365, Air Force identity management systems, or legacy identity provisioning processes including AFID-based identity creation.
- Familiarity with MILPDS, DCPDS, or other DoD authoritative HR data systems and their integration with enterprise identity platforms.
Required Skills and Competencies:
- Deep technical knowledge of Okta platform architecture, including Universal Directory schema design, attribute mapping, ABAC rule configuration, Okta Workflows, provisioning agent deployment, and application integration for enterprise JML automation.
- Proficiency in Microsoft Entra ID architecture, including SCIM provisioning configuration, Microsoft Graph API integration, tenant structure, domain federation, and Entra ID group and license management.
- Strong understanding of identity lifecycle management processes—Joiner, Mover, and Leaver—and the technical event triggers, workflow sequences, and downstream provisioning actions associated with each event type in large enterprise environments.
- Experience designing attribute sanitization and normalization workflows that transform raw authoritative HR source data into clean, policy-actionable identity attributes suitable for ABAC-driven provisioning automation.
- Knowledge of legacy Active Directory environments and their role as provisioning intermediaries, and experience designing bridging architectures that enable cloud-native orchestration to extend into legacy AD-dependent environments.
- Familiarity with DoD HR data systems, including MILPDS and DCPDS, and their attribute structures relevant to DAF member identity provisioning.
- Understanding of Microsoft 365 license management, mailbox provisioning, SharePoint and Microsoft Teams group membership management, and DoD data retention policy requirements applicable to Leaver mailbox handling.
- Knowledge of delegated administration models, role-based access controls within ICAM platforms, and approval workflow design for base-level administrator provisioning authority.
- Ability to perform structured current-state/future-state architecture analysis, provisioning latency quantification, and dependency-sequenced implementation roadmap development.
- Experience developing phased implementation roadmaps with clearly defined entry/exit criteria, dependencies, and realistic Government review and accreditation timelines.
- Strong technical writing skills with the ability to produce formal study reports, architecture documentation, workflow specifications, and procedural guidance suitable for Government use and base-level administrator consumption.
- Ability to work collaboratively across cross-functional technical teams including identity architects, systems analysts, cost analysts, and program managers.
- Exceptional communication skills in English—both written and oral—with the ability to present complex identity lifecycle architecture findings clearly to both technical and non-technical Government stakeholders.
- Ability to obtain and maintain a Secret security clearance.
Required Skills and Competencies:
- Deep technical knowledge of Okta platform architecture, including Universal Directory schema design, attribute mapping, ABAC rule configuration, Okta Workflows, provisioning agent deployment, and application integration for enterprise JML automation.
- Proficiency in Microsoft Entra ID architecture, including SCIM provisioning configuration, Microsoft Graph API integration, tenant structure, domain federation, and Entra ID group and license management.
- Strong understanding of identity lifecycle management processes—Joiner, Mover, and Leaver—and the technical event triggers, workflow sequences, and downstream provisioning actions associated with each event type in large enterprise environments.
- Experience designing attribute sanitization and normalization workflows that transform raw authoritative HR source data into clean, policy-actionable identity attributes suitable for ABAC-driven provisioning automation.
- Knowledge of legacy Active Directory environments and their role as provisioning intermediaries, and experience designing bridging architectures that enable cloud-native orchestration to extend into legacy AD-dependent environments.
- Familiarity with DoD HR data systems, including MILPDS and DCPDS, and their attribute structures relevant to DAF member identity provisioning.
- Understanding of Microsoft 365 license management, mailbox provisioning, SharePoint and Microsoft Teams group membership management, and DoD data retention policy requirements applicable to Leaver mailbox handling.
- Knowledge of delegated administration models, role-based access controls within ICAM platforms, and approval workflow design for base-level administrator provisioning authority.
- Ability to perform structured current-state/future-state architecture analysis, provisioning latency quantification, and dependency-sequenced implementation roadmap development.
- Experience developing phased implementation roadmaps with clearly defined entry/exit criteria, dependencies, and realistic Government review and accreditation timelines.
- Strong technical writing skills with the ability to produce formal study reports, architecture documentation, workflow specifications, and procedural guidance suitable for Government use and base-level administrator consumption.
- Ability to work collaboratively across cross-functional technical teams including identity architects, systems analysts, cost analysts, and program managers.
- Exceptional communication skills in English—both written and oral—with the ability to present complex identity lifecycle architecture findings clearly to both technical and non-technical Government stakeholders.
- Ability to obtain and maintain a Secret security clearance.
Desired Skills and Competencies:
- Experience with Okta Workflows or Microsoft Power Automate for enterprise-scale identity event automation, including event trigger configuration, action sequencing, error handling, and execution latency optimization.
- Familiarity with SailPoint IdentityIQ (IIQ) and its role in delegated provisioning, access certification, and base-level administrator workflow enablement within DAF ICAM environments.
- Experience designing or documenting cascading access revocation architectures that systematically eliminate active credentials, tokens, and sessions across federated application ecosystems within defined latency thresholds.
- Knowledge of DoD data retention policies applicable to Microsoft 365 mailbox handling, litigation hold configuration, and shared mailbox conversion for separated personnel.
- Experience quantifying provisioning latency in current-state manual identity management processes and projecting latency reduction achievable through automation architecture.
- Familiarity with Area52 Active Directory or other DAF legacy identity intermediary systems and their structural role in current DAF365 provisioning processes.
- Experience developing draft Performance Work Statements or acquisition documentation for Defense IT identity lifecycle management implementation programs.
- Okta Certified Professional, Okta Certified Administrator, Okta Certified Developer, or Okta Workflows certification.
- Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure AD Engineer, or equivalent Microsoft identity platform certification.
- CISSP, CISM, or equivalent cybersecurity certification.
- Experience supporting DAF, Air Force, or Space Force IT modernization, Microsoft 365 deployment, or ICAM programs.
- Familiarity with Zero Trust Architecture principles and their application to identity lifecycle management automation in DoD enterprise environments.
- Familiarity with Agile development methodologies and their application within hybrid Agile/Waterfall Government program environments.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352