Scan your resume against ATS criteria for this CDO-L Study Lead Engineer (REMOTE) role at CANDIDATEPORTAL.
This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking a CDO-L Study Lead Engineer with a Secret security clearance to support KITS and our government customer. The position is remote.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
Koniag IT Systems, LLC a Koniag Government Services company, is seeking an experienced CDO-L Study Lead Engineer to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will lead a focused, technically grounded study effort under Task Order 0003, System Enhancement Studies, with a primary focus on extending secure ICAM capabilities into Contested, Degraded, and Operationally Limited (CDO-L) environments. The ideal candidate is a technically seasoned engineer and collaborative leader with deep experience in Defense ICAM architectures, Zero Trust frameworks, and disconnected/edge identity solutions who can translate complex operational requirements into actionable architectures and implementation roadmaps.
*This study will run 120 days. All personnel assigned to CDO-L study activities must hold a final Secret security clearance.
The CDO-L Study Lead Engineer will serve as the primary technical authority for Study 1 of the DAF ICAM System Enhancement Studies effort, leading the analysis, architecture development, and documentation required to produce a decision-ready Technical Study Report within 45 calendar days of Task Order award. The Lead Engineer will coordinate closely with the Program Manager, Systems Architecture Team, Licensing/Cost Analyst, and Government stakeholders to ensure all study outputs are technically sound, operationally grounded, and fully traceable to Performance Work Statement (PWS) Section 4.1 requirements.
Principal responsibilities will include but are not limited to:
Lead the structured review of Government-provided CDO-L requirements published at the DoD Enterprise ICAM IL5 and IL6 DDIL reference site, cataloging each requirement by operational condition (denied, degraded, intermittent, and limited bandwidth) and mapping them against existing DAF ICAM solution components including Okta Universal Directory (UD), Okta Identity Provider (IdP), and SailPoint IdentityIQ (IIQ).
Conduct a gap analysis between current DAF ICAM capabilities and CDO-L operational demands to serve as the foundation for all architectural recommendations.
Evaluate existing approved ICAM solutions across comparable Federal Defense programs and assess their applicability to DAF CDO-L requirements, prioritizing solutions that extend existing approved capabilities rather than introducing net-new vendor stacks.
Lead the architectural analysis of options for on-premises replication or caching of identity and access data at disconnected nodes, evaluating a tiered edge identity broker model across three operational states: Connected, Degraded/Limited Bandwidth, and Denied.
Assess and document synchronization schedules, minimum connectivity requirements, degraded-mode operating parameters, and cache staleness thresholds for each operational state.
Evaluate specific DAF ICAM-aligned edge components including Okta Access Gateway (OAG) and Tactical Identity Bridge Appliance (TIBA) for their suitability in extending ICAM operations to the tactical edge.
Assess how existing SailPoint IIQ governance workflows can be mirrored at the edge to maintain entitlement integrity during disconnected operations.
Document tradeoffs between full replication, selective caching, and read-only policy mirroring, and provide a recommended approach with clear technical rationale grounded in DAF operational requirements.
Develop recommendations for emergency "break-glass" access provisioning in fully offline or denied-state conditions, including governance controls, immutable local audit logging, and automated revocation and re-synchronization workflows.
Evaluate approaches for PKI certificate validation in CDO-L conditions, including Certificate Revocation List (CRL) caching and local Certificate Status Protocol (OCSP) stapling at edge nodes to sustain Common Access Card (CAC)-based authentication.
Analyze how endpoint security telemetry collected locally during a disconnected period integrates with the identity layer and how the edge identity broker can autonomously enforce access revocation when device security posture degrades.
Develop a formal methodology for attribute transfer and synchronization between enterprise NIPRNet and SIPRNet environments and disconnected nodes upon reconnection, addressing conflict resolution, synchronization priorities, audit log consolidation, reconciliation validation, and failure/fallback procedures.
Coordinate with the Licensing/Cost Analyst to produce a structured identification of all software components required for the recommended CDO-L architecture, including licensing structure, edge deployment constraints, classified-network restrictions, and interoperability considerations.
Coordinate with the Program Manager and Licensing/Cost Analyst to develop a detailed, phased implementation roadmap and ROM cost estimate covering development, licensing, hardware, integration, testing, and deployment.
Consolidate all study outputs into the CDO-L Technical Study Report (CDRL B010), ensuring each section maps directly to a PWS Section 4.1 requirement and includes a draft Performance Work Statement suitable for a subsequent implementation Task Order.
Verify that all assigned personnel hold the required security clearances prior to engagement and notify the Government immediately of any clearance status changes.
Present study findings to Government Program Manager and Contracting Officer's Representative (COR) as required throughout the study period
Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, or a related technical field from an accredited college or university.
7+ years of experience in systems engineering, enterprise architecture, or identity and access management within Defense or Federal government IT environments.
Demonstrated experience designing or analyzing identity and access management architectures in disconnected, air-gapped, or operationally constrained network environments.
Experience with the DoD Authority to Operate (ATO) process and security accreditation requirements for Defense information systems.
Active Secret security clearance (final adjudication required prior to assignment)
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at [email protected] or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
How to apply for CDO-L Study Lead Engineer (REMOTE) at CANDIDATEPORTAL?
Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.
What is the salary for this role?
Salary details will be discussed during the interview.
What experience is required?
7+ years of experience is required.
Is this position still open?
Yes, currently active and accepting applications.
Explore related active roles in management
CDO-L Study Lead Engineer (REMOTE)
CANDIDATEPORTAL · India