NPE Governance Study Lead Engineer (Study 2) (REMOTE)
KgsThis position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking a NPE Governance Study Lead Engineer (Study 2) with a Secret security clearance to support KITS and our government customer. The position is remote.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking an experienced NPE Governance Study Lead Engineer to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will lead a comprehensive technical study and engineering analysis effort under Task Order 0003, System Enhancement Studies, with a primary focus on establishing a scalable governance and management framework for Non-Person Entities (NPEs) across the DAF enterprise. The ideal candidate is a technically seasoned identity governance engineer and collaborative leader with deep experience in enterprise ICAM platforms, Zero Trust frameworks, and non-person entity lifecycle management who can translate complex operational requirements into actionable governance frameworks, technical architectures, and implementation roadmaps.
*Note: This contract is 120 days. All personnel assigned to NPE Governance study activities must hold a final Secret security clearance.
The NPE Governance Study Lead Engineer will serve as the primary technical authority for Study 2 of the DAF ICAM System Enhancement Studies effort, leading the analysis, governance framework design, architecture development, and documentation required to produce a decision-ready Technical Study Report within 60 calendar days of Task Order award. The Lead Engineer will coordinate closely with the Program Manager, Identity Architects, Licensing/Cost Analyst, and Government stakeholders to ensure all study outputs are technically sound, policy-compliant, and fully traceable to Performance Work Statement (PWS) Section 4.2 requirements. All work performed under this study will be strictly analytical and planning-focused; no software development, system configuration, or live deployment will be performed under this task.
Principal responsibilities will include but are not limited to:
- Lead the comprehensive review and analysis of all applicable Government-Furnished Information (GFI) and federal references, including the DAF ICAM Integrated NPE and API Management Plan, DAF ICAM NPE Strategy Overview, DAF ICAM NPE Solution Roadmap (CY26–CY27), DoD/DoW X.509 Certificate Policy, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and DAFGM2025-01.
- Design and define standardized attribute schemas required to establish a centralized Master Device/Entity Record within the Enterprise Identity Catalog, including standard claims, core NPE identity attributes, unique identifiers, accountability/ownership fields (including the "Babysitter" role), sponsoring organization, environment classification, security classification, lifecycle state, and associated application linkages.
- Define alignment between NPE attribute schemas and Okta's dual-server authentication architecture, covering the Standard NPE Authentication Server (npe_default / api://npe) and Custom Application Authentication Server schema structures.
- Develop and document structured naming conventions for NPE identities, coordinating with the DAF Chief Data and Artificial Intelligence Office (CDAO) to support the Master Device/Entity Record naming standard.
- Develop a detailed, actionable technical plan for discovering existing NPEs across the hybrid DAF enterprise environment and consolidating them into a unified catalog, coordinating with existing enterprise tools and data sources including Azure AD Connect, AWS IAM Inventory, Google Cloud/Cloud One registries, Tenable Nessus, ACAS, Microsoft InTune, ServiceNow CMDB, EITaaS CMDB, and the Service Account Manager listing.
- Define secure data exchange and synchronization flows with the Attribute Exchange Service (AXS), Active Directory (AREA52), AppGate, Xage, MuleSoft, AI Agent toolsets, UiPath, and the DoD Enterprise Credential Management System (ECMS)/NPE PKI.
- Define a process for system owners to manually validate automated discovery findings, resolve discrepancies, and enrich raw discovery data with ownership, classification, and environment details.
- Design proposed governance workflows to manage the full NPE lifecycle within the SailPoint IGA platform, covering all lifecycle states: Request → Approval → Provision → Certification → Deactivation/Revocation.
- Design accountability and "Babysitter" enforcement controls ensuring every active NPE is linked to an active, accountable personnel record or organizational owner responsible for the identity's activities.
- Formulate a recurring NPE access recertification process conducted at minimum annually, or at higher frequency based on risk and system owner requirements, directly tied to System Security Plan (SSP) and ATO maintenance.
- Design governance rules to enforce credential management policies, including transition from password-based to PKI certificate or token-based authentication, 90-day credential rotation enforcement, and storage of physical credentials in accredited enterprise secret vaults with explicit prohibition of hardcoded credentials.
- Develop a forward-looking, scalable target architecture to guide future NPE capability enhancements, addressing DoD Zero Trust Architecture (ZTA) integration, dynamic access control via Policy Decision Points (PDPs), continuous monitoring and audit compliance via SOC and ELICSAR integration, and User and Entity Behavior Analytics (UEBA)/AI-driven anomaly detection.
- Define a standardization and rationalization framework leveraging open standards including SPIFFE/SPIRE, OAuth 2.0, and Mutual TLS (mTLS) to eliminate fragmented vendor-specific patterns and facilitate cross-domain interoperability.
- Conduct a legacy rationalization assessment identifying legacy NPE authentication mechanisms such as static API keys, hardcoded service accounts, and unmanaged certificates requiring remediation.
- Extend Zero Trust architecture and governance models to emerging AI capabilities, defining specialized workload identities and dynamic access policies for AI Agents, RAG pipelines, and orchestration platforms operating under minimum viable privilege with full dynamic authorization and audit traceability.
- Synthesize study findings into a structured, phased implementation roadmap spanning near-term (Months 1–6), mid-term (Months 7–12), long-term (Months 10–22), and continuous optimization (CY27+) horizons.
- Coordinate with the Program Manager and Licensing/Cost Analyst to develop a detailed ROM cost estimate for development, configuration, and enterprise-wide deployment of the proposed roadmap.
- Consolidate all study outputs into the NPE Governance and Management Strategy Technical Study Report (CDRL B010), ensuring each section maps directly to PWS Section 4.2 requirements and includes an Executive Summary with leadership business case, NPE Attribute Schema and Naming Standards, Enterprise NPE Discovery and Integration Architecture, SailPoint IGA Lifecycle Governance and Workflow Designs, and a Target Architecture and Zero Trust Integration Map.
- Present study findings to the Government Program Manager and Contracting Officer's Representative (COR) as required throughout the study period.
- Verify that all assigned personnel hold the required security clearances prior to engagement and notify the Government immediately of any clearance status changes.
Education and Experience:
Required:
- Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university.
- 7+ years of experience in identity governance, enterprise architecture, or identity and access management within Defense or Federal government IT environments.
- Demonstrated experience designing or analyzing identity governance frameworks for non-person entities, service accounts, machine identities, or workload identities in enterprise environments.
- Experience with SailPoint IdentityIQ (IIQ) or SailPoint IdentityNow in an engineering, architecture, or governance design capacity.
- Experience with Okta platform components including Universal Directory, authentication server configuration, and application integration.
- Active Secret security clearance (final adjudication required prior to assignment).
Preferred:
- Master's degree in a related technical field.
- 10+ years of experience in Defense or Federal ICAM, identity governance and administration, or related cybersecurity engineering disciplines.
- Experience supporting DAF, Air Force, Space Force, or other DoD component ICAM or cybersecurity modernization programs.
- Direct experience with DoD PKI, DoD Enterprise Credential Management System (ECMS), or NPE PKI certificate lifecycle management.
Required Skills and Competencies:
- Deep technical knowledge of enterprise Identity Governance and Administration (IGA) platforms, with specific expertise in SailPoint IdentityIQ (IIQ), including lifecycle management workflow design, access certification, and provisioning architecture.
- Proficiency in Okta platform architecture, including Universal Directory schema design, authentication server configuration, and application integration for both person and non-person entity populations.
- Strong understanding of Non-Person Entity (NPE) identity types including service accounts, software bots, APIs, workload identities, and IoT devices, and the unique governance challenges associated with each.
- Knowledge of Zero Trust Architecture (ZTA) principles and their application to machine identities, workload identities, and NPE governance within DoD environments.
- Familiarity with DoD and DAF ICAM policy frameworks including NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and related mandates.
- Experience designing attribute schemas, naming conventions, and master record structures for enterprise identity catalogs.
- Knowledge of automated NPE discovery tools and enterprise data sources including Azure AD Connect, AWS IAM Inventory, Microsoft InTune, ServiceNow CMDB, Tenable Nessus, and ACAS.
- Understanding of PKI-based credential management, certificate lifecycle management, credential rotation policies, and enterprise secret vault architectures.
- Familiarity with open identity standards including SPIFFE/SPIRE, OAuth 2.0, mTLS, and their application to NPE and API security in DoD environments.
- Ability to perform structured governance workflow design, architecture tradeoff analysis, and legacy rationalization assessments.
- Experience developing phased implementation roadmaps with clearly defined entry/exit criteria, dependencies, and realistic Government review and accreditation timelines.
- Strong technical writing skills with the ability to produce formal study reports, governance framework documentation, architectural diagrams, and leadership-facing business cases suitable for Government use.
- Ability to work collaboratively across cross-functional technical teams including identity architects, engineers, cost analysts, and program managers.
- Exceptional communication skills in English—both written and oral—with the ability to present complex technical and governance findings clearly to both technical and senior non-technical Government stakeholders.
- Ability to obtain and maintain a Secret security clearance.
Desired Skills and Competencies:
- Experience integrating NPE or machine identity governance with Security Operations Center (SOC) environments and enterprise SIEM or log management platforms.
- Familiarity with User and Entity Behavior Analytics (UEBA) and AI-driven anomaly detection applied to non-person entity activity monitoring.
- Knowledge of the DoD Enterprise Credential Management System (ECMS) and NPE PKI certificate issuance and lifecycle processes.
- Experience with enterprise secret vault platforms such as HashiCorp Vault, CyberArk, or equivalent DoD-approved credential storage solutions.
- Familiarity with MuleSoft, AppGate, Xage, UiPath, or AI Agent orchestration platforms and their identity integration requirements.
- Experience designing Zero Trust governance models for emerging AI capabilities including AI Agents, RAG pipelines, and AI orchestration platforms.
- Experience conducting legacy rationalization assessments and developing technical debt remediation roadmaps for enterprise identity environments.
- Experience developing Rough Order of Magnitude (ROM) cost estimates for complex, multi-phase Defense IT governance and implementation programs.
- SailPoint Certified IdentityIQ Engineer or SailPoint Certified IdentityNow Engineer certification.
- Okta Certified Professional, Okta Certified Administrator, or Okta Certified Developer certification.
- CISSP, CISM, CDPSE, or equivalent cybersecurity or governance certification.
- Experience supporting DAF, Air Force, or Space Force IT modernization or ICAM programs.
- Familiarity with the DAF Chief Data and Artificial Intelligence Office (CDAO) data governance standards and enterprise naming convention frameworks.
- Familiarity with Agile development methodologies and their application within hybrid Agile/Waterfall Government program environments.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352