Microsoft Identity SME (REMOTE)
KgsThis position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking a Microsoft Identity SME with a Secret security clearance to support KITS and our government customer. The position is remote.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
KITS, a Koniag Government Services company, is seeking an experienced Microsoft Identity Subject Matter Expert (SME) to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will provide dedicated Microsoft identity platform expertise across three concurrent System Enhancement Studies under Task Order 0003, covering Contested, Degraded, and Operationally Limited (CDO-L) ICAM environments, Non-Person Entity (NPE) Governance and Management, and the DAF365 Joiner, Mover, Leaver (JML) Transformation Framework. The ideal candidate is a technically seasoned Microsoft identity engineer with deep hands-on experience across Microsoft Entra ID, Active Directory, Microsoft 365, and related Microsoft identity and access management technologies, with a strong understanding of how these platforms integrate within the broader DAF ICAM enterprise stack including Okta and SailPoint.
*Note – This is for a 120-day study. All personnel assigned to this effort must hold a final Secret security clearance.
The Microsoft Identity SME will serve as the primary technical authority on Microsoft identity platform architecture, integration, and configuration requirements across all three studies within the DAF ICAM System Enhancement Studies effort. Working in close coordination with the Program Manager, Study Lead Engineers, and Identity Architects, the Microsoft Identity SME will ensure that all architectural recommendations, integration designs, provisioning workflows, and implementation roadmaps involving Microsoft platforms are technically accurate, aligned to current Microsoft Entra ID capabilities and product roadmap, and practically implementable within the DAF enterprise environment. The Microsoft Identity SME will contribute substantive Microsoft platform technical content to each study's Technical Study Report and will serve as the authoritative reference point for all Microsoft identity platform questions arising during the study period.
Principal responsibilities will include but are not limited to:
- Serve as the authoritative Microsoft identity platform technical reference across all three System Enhancement Studies, ensuring that all architectural recommendations and integration designs involving Microsoft technologies are grounded in current platform capabilities, current licensing structures, and near-term product roadmap inputs.
- Provide Microsoft identity platform guidance to the CDO-L Study Lead Engineer to support the architectural analysis of edge identity node deployment options, evaluating how Microsoft identity components interact with proposed edge identity broker architectures in disconnected and intermittently connected NIPRNet and SIPRNet environments.
- Assess and document the behavior of Microsoft Entra ID and Active Directory in degraded, limited bandwidth, and fully denied connectivity states, including cached credential validation behavior, Kerberos ticket lifetime management, and the interaction between on-premises Active Directory domain controllers and cloud-based Entra ID authentication flows during connectivity interruptions.
- Define the Microsoft platform configuration requirements necessary to support CDO-L edge identity caching and synchronization architectures, including Azure AD Connect configuration for hybrid identity synchronization, domain controller placement considerations for forward-deployed nodes, and Group Policy or Intune policy behavior during disconnected operations.
- Provide Microsoft identity platform guidance to the NPE Governance Study Lead Engineer to support the NPE discovery integration plan, specifically addressing Azure AD Connect inventory capabilities, Microsoft Entra ID service principal and managed identity discovery, Microsoft Intune device inventory integration, and Microsoft Graph API data exchange flows relevant to NPE catalog population.
- Define Microsoft Entra ID service principal, managed identity, and workload identity constructs relevant to NPE governance, documenting how these identity types align with the proposed Master Device/Entity Record attribute schema and SailPoint IGA governance workflows.
- Assess and document Microsoft Entra ID Workload Identity capabilities, including Federated Identity Credentials and Managed Identity lifecycle management, within the context of the proposed NPE Zero Trust Architecture and dynamic access control framework.
- Serve as the primary Microsoft platform technical authority for Study 3, providing deep expertise in support of the DAF365 JML Transformation Framework study across all five technical workstreams.
- Define the Microsoft Entra ID attribute schema relevant to DAF365 identity provisioning, documenting required directory attributes, accepted value formats, and source-of-record assignments that must be present in Entra ID to support correct DAF365 license assignment, group membership, mailbox configuration, and application access.
- Design the target-state technical architecture for direct Okta-to-Entra ID provisioning using SCIM and Microsoft Graph API, removing the dependency on legacy intermediary systems such as Area52 Active Directory, and documenting the specific Entra ID tenant structure, domain federation settings, and Okta application integration parameters required to support this architecture.
- Define the role of Okta on-premises provisioning agents as a bridging mechanism for environments where on-premises Active Directory dependencies remain for legacy application authentication, specifying configuration requirements and data flow architecture.
- Document the end-to-end Microsoft platform actions required for each JML event type within the DAF365 environment, including Entra ID user object creation, license tier assignment, mailbox provisioning, Microsoft Teams and SharePoint group membership management, and session token revocation for Leaver events.
- Specify Microsoft 365 license reclamation procedures, automated mailbox conversion or litigation hold configuration, and Entra ID session token revocation mechanisms within the Leaver revocation architecture, ensuring alignment with DoD data retention policy requirements.
- Define Mover event handling within Microsoft 365 and Entra ID, including removal from previous SharePoint sites and Microsoft Teams environments, provisioning of access to new unit collaboration spaces, and enforcement of temporary access expiration for TDY and deployment-based access grants.
- Assess and document the Microsoft Power Automate and Microsoft Graph API automation capabilities applicable to JML workflow execution, specifying which automation tooling executes each provisioning and revocation step and the expected execution latency for each action.
- Validate Microsoft licensing cost assumptions within the ROM cost estimates developed by the Pricing / Licensing Analyst, engaging Microsoft licensing specialists or enterprise agreement managers as needed to confirm current DAF enterprise license agreement coverage and identify components requiring separate procurement.
- Contribute Microsoft platform technical content to all three Technical Study Reports, ensuring architectural diagrams, integration specifications, and configuration requirement documentation accurately reflect current Microsoft platform capabilities.
- Advise the Program Manager and Study Lead Engineers on Microsoft product roadmap developments relevant to DAF ICAM study recommendations, including upcoming Entra ID feature releases, deprecated integration methods, and Microsoft licensing changes that may affect implementation planning.
- Support the preparation of draft Performance Work Statements for subsequent implementation Task Orders, providing Microsoft platform technical requirement language suitable for inclusion in Government acquisition documents.
Education and Experience:
Required:
- Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university.
- 7+ years of experience in Microsoft identity platform engineering, architecture, or administration in enterprise environments.
- Demonstrated hands-on experience with Microsoft Entra ID (formerly Azure Active Directory), including hybrid identity architecture, application integration, and enterprise provisioning.
- Experience designing or implementing identity provisioning integrations between Microsoft Entra ID and third-party identity platforms using SCIM, Microsoft Graph API, or related integration standards.
- Experience with Microsoft 365 identity and access management, including Exchange Online, SharePoint Online, Microsoft Teams, and license management.
- Active Secret security clearance (final adjudication required prior to assignment).
Preferred:
- Master's degree in a related technical field.
- 10+ years of experience in Microsoft identity platform engineering or architecture in Defense or Federal government environments.
- Experience supporting Microsoft identity architecture in DAF, Air Force, Space Force, or other DoD component enterprise environments.
- Direct experience with DAF365 or Air Force Microsoft 365 tenant architecture, federation configuration, or enterprise provisioning integrations.
- Experience integrating Microsoft Entra ID with Okta as a federated identity provider in a Defense or Federal enterprise environment.
Required Skills and Competencies:
- Deep technical knowledge of Microsoft Entra ID architecture, including hybrid identity synchronization via Azure AD Connect, domain federation, Conditional Access policies, application registration and service principal management, and Entra ID Workload Identity capabilities.
- Strong proficiency in Microsoft Graph API, including its application to identity provisioning, user and group lifecycle management, license assignment automation, and audit log retrieval.
- Experience designing and documenting SCIM-based provisioning integrations between Okta and Microsoft Entra ID, including attribute mapping, provisioning scope configuration, and error handling behavior.
- Knowledge of on-premises Active Directory architecture, including domain controller placement, Group Policy management, Kerberos authentication, and hybrid identity synchronization behavior during network connectivity interruptions.
- Strong understanding of Microsoft 365 workload identity and access management, including Exchange Online mailbox provisioning and lifecycle management, SharePoint Online and Microsoft Teams group membership management, and Microsoft 365 license assignment and reclamation.
- Familiarity with Microsoft Entra ID service principal, managed identity, and Federated Identity Credential constructs and their application to non-person entity governance and workload identity management.
- Knowledge of Microsoft Intune device management and its integration with Entra ID for device identity inventory and compliance policy enforcement.
- Experience documenting Microsoft platform configuration requirements, integration specifications, and architectural designs in formal technical reports suitable for Government review.
- Ability to validate Microsoft licensing structures, identify coverage gaps under existing enterprise agreements, and provide accurate per-component licensing cost inputs for ROM estimates.
- Familiarity with Okta platform architecture sufficient to engage productively with Okta-focused Study Lead Engineers and Identity Architects on cross-platform integration design.
- Strong technical writing skills with the ability to produce formal architectural documentation, integration specifications, and Microsoft platform technical content for Government study reports and draft Performance Work Statements.
- Ability to work collaboratively across cross-functional technical teams including study lead engineers, identity architects, security compliance SMEs, cost analysts, and program managers.
- Exceptional communication skills in English—both written and oral—with the ability to communicate complex Microsoft identity platform technical concepts clearly to both technical engineers and non-technical Government stakeholders.
Required Skills and Competencies:
- Deep technical knowledge of Microsoft Entra ID architecture, including hybrid identity synchronization via Azure AD Connect, domain federation, Conditional Access policies, application registration and service principal management, and Entra ID Workload Identity capabilities.
- Strong proficiency in Microsoft Graph API, including its application to identity provisioning, user and group lifecycle management, license assignment automation, and audit log retrieval.
- Experience designing and documenting SCIM-based provisioning integrations between Okta and Microsoft Entra ID, including attribute mapping, provisioning scope configuration, and error handling behavior.
- Knowledge of on-premises Active Directory architecture, including domain controller placement, Group Policy management, Kerberos authentication, and hybrid identity synchronization behavior during network connectivity interruptions.
- Strong understanding of Microsoft 365 workload identity and access management, including Exchange Online mailbox provisioning and lifecycle management, SharePoint Online and Microsoft Teams group membership management, and Microsoft 365 license assignment and reclamation.
- Familiarity with Microsoft Entra ID service principal, managed identity, and Federated Identity Credential constructs and their application to non-person entity governance and workload identity management.
- Knowledge of Microsoft Intune device management and its integration with Entra ID for device identity inventory and compliance policy enforcement.
- Experience documenting Microsoft platform configuration requirements, integration specifications, and architectural designs in formal technical reports suitable for Government review.
- Ability to validate Microsoft licensing structures, identify coverage gaps under existing enterprise agreements, and provide accurate per-component licensing cost inputs for ROM estimates.
- Familiarity with Okta platform architecture sufficient to engage productively with Okta-focused Study Lead Engineers and Identity Architects on cross-platform integration design.
- Strong technical writing skills with the ability to produce formal architectural documentation, integration specifications, and Microsoft platform technical content for Government study reports and draft Performance Work Statements.
- Ability to work collaboratively across cross-functional technical teams including study lead engineers, identity architects, security compliance SMEs, cost analysts, and program managers.
- Exceptional communication skills in English—both written and oral—with the ability to communicate complex Microsoft identity platform technical concepts clearly to both technical engineers and non-technical Government stakeholders.
- Ability to obtain and maintain a Secret security clearance.
Desired Skills and Competencies:
- Experience with Microsoft Entra ID Conditional Access policy design in Zero Trust architecture contexts, including device compliance integration, sign-in risk policy configuration, and continuous access evaluation.
- Familiarity with Microsoft Entra ID External Identities and B2B collaboration configuration relevant to contractor and mission partner identity federation scenarios.
- Experience with Microsoft Power Automate in identity lifecycle automation contexts, including integration with Microsoft Graph API for JML event-driven provisioning and revocation workflows.
- Knowledge of Microsoft Entra ID Privileged Identity Management (PIM) and its application to just-in-time access provisioning and elevated privilege governance for both person and non-person entity populations.
- Familiarity with Microsoft Defender for Identity and its integration with Entra ID for identity threat detection and security posture assessment.
- Experience with Microsoft Purview compliance solutions, including litigation hold configuration, data retention policy enforcement, and audit log management relevant to DoD data retention requirements.
- Knowledge of Microsoft Azure Government or Microsoft 365 Government (GCC High) environment architecture, licensing, and feature availability differences relevant to DAF IL5 and IL6 deployment requirements.
- Experience integrating Microsoft identity platforms with DoD PKI, Common Access Card (CAC) authentication, and certificate-based authentication configurations in classified Defense environments.
- Microsoft Certified: Identity and Access Administrator Associate certification.
- Microsoft Certified: Azure Solutions Architect Expert certification.
- Microsoft 365 Certified: Enterprise Administrator Expert certification.
- CISSP, CISM, or equivalent cybersecurity certification.
- Experience supporting DAF, Air Force, or Space Force Microsoft 365 or Entra ID enterprise programs.
- Familiarity with DISA STIGs applicable to Microsoft Azure Active Directory, Microsoft 365, and related Microsoft platform components deployed in classified Defense environments.
- Experience contributing Microsoft platform technical content to draft Performance Work Statements or other Government acquisition documents for Defense IT programs.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352