Koniag Government Services logo
Koniag Government Services
Posted 24 days agoVerified live 6h ago

Migration Engineer (REMOTE)

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
4 H-1B approvalsDept. of Labor
Clearance requiredU.S. government
Identity and Access Management (IAM)OktaSailPoint IdentityIQ (IIQ)SAML, OAuth 2.0, OIDC, and SCIMSingle Sign-On (SSO) IntegrationCustom Integration DevelopmentUser Acceptance Testing (UAT)DoD Cybersecurity RequirementsZero Trust Architecture (ZTA)Secret Security ClearanceCompTIA Security+

About the company

Koniag Government Services logo
Koniag Government Serviceskoniag-gs.com

Koniag Government Services is a Professional Services and Operational Management to Federal Government.

Visa sponsorship history

1 year sponsoring, last filed FY2023

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
4H-1B approved
100%approval rate
3new H-1B hires
$140,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20234
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
Top sponsored roles
Senior Salesforce Developer

Job description

Summary

Koniag IT Systems, LLC, a Koniag Government Services company, supports government customers with enterprise IT and cybersecurity solutions. The Migration Engineer will integrate NIPRNet applications into a centralized ICAM platform using Okta and SailPoint IdentityIQ, while working with application owners to configure, troubleshoot, test, document, and validate secure integrations.

Responsibilities

  • Execute the technical integration of assigned NIPRNet applications into the ICAM technical stack, establishing logical network connections that route 100% of user authentication requests through the Okta IdP and 100% of user access management through SailPoint IGA in production environments
  • Conduct thorough technical triage of assigned applications, assessing each application's current identity state, identifying integration gaps, documenting risks, and determining the appropriate enablement pathway—self-service, automated, or dedicated white glove support
  • Configure and implement identity federation and SSO integrations using industry-standard protocols including SAML, OAuth 2.0, OIDC, and SCIM, leveraging existing Okta and SailPoint connectors where available
  • Engineer, develop, and deploy custom tools, scripts, connectors, and middleware solutions to facilitate the integration of legacy applications that cannot natively support modern identity protocols
  • Provide technical advisement and architectural guidance to Application Owners on configuring their applications to use the ICAM platform for authentication and authorization, including recommendations for implementing Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC)
  • Assist Application Owners throughout the full enablement lifecycle, including application registration, credential issuance, non-PKI credential configuration, enrollment workflow setup, and access control module redesign
  • Support Application Owners through the User Acceptance Testing (UAT) process, including providing sample code for common integration patterns, reusable libraries or middleware, troubleshooting integration defects, and assisting with defect resolution activities
  • Accurately document all triage findings, integration configurations, risk items, engagement activities, and application status updates in the Enablement Tracking Database, ensuring real-time accuracy and completeness
  • Follow and execute the Application Owner Escalation Matrix, documenting all engagement attempts with application owners and escalating stalled or non-responsive cases to the Migration Team Lead per established timelines and protocols
  • Collaborate with internal engineers, integration specialists, and the Migration Team Lead to resolve complex technical challenges and share reusable integration solutions across the application portfolio
  • Contribute to the development and continuous refinement of enablement playbooks, integration guides, standard operating procedures, and technical documentation to support consistent and repeatable onboarding processes
  • Generate and maintain technical documentation describing integration solutions, configurations, and architectural decisions for each assigned application
  • Support the testing program by assisting in the development of test plans, executing integration testing, and preparing software test reports and observations for UAT events
  • Ensure all integration activities and developed solutions comply with applicable DoD security requirements, including CUI handling, OPSEC, Section 508 accessibility standards, and DoD cybersecurity certification requirements
  • Maintain awareness of evolving ICAM platform capabilities, identity protocols, and Zero Trust requirements, continuously applying updated knowledge to improve integration quality and program outcomes

Skills

  • • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university
  • • Minimum of 4 years of hands-on experience in information technology, with at least 2 years of direct experience in identity and access management, enterprise application integration, or related cybersecurity disciplines
  • • Demonstrated experience configuring and troubleshooting SSO integrations using SAML, OAuth 2.0, or OIDC in an enterprise environment
  • • Experience working with Identity Provider (IdP) or Identity Governance and Administration (IGA) platforms in a technical integration capacity
  • • Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification
  • • Secret clearance
  • • Strong technical communication skills in English—both written and oral—with the ability to clearly explain complex integration concepts to both technical engineers and non-technical application owners
  • • Hands-on experience configuring Okta for SSO, MFA, and application integration, including working with Okta application integrations, Universal Directory, and identity federation
  • • Hands-on experience with SailPoint IdentityIQ (IIQ), including connector configuration, automated provisioning and deprovisioning workflows, entitlement management, and access certification
  • • Working knowledge and practical implementation experience with SAML, OAuth 2.0, OIDC, and SCIM identity protocols
  • • Experience developing custom integration solutions including scripts, connectors, APIs, or middleware to bridge legacy applications with modern identity platforms
  • • Familiarity with Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) design and implementation principles
  • • Experience supporting or conducting User Acceptance Testing (UAT), including test case development, defect tracking, and resolution support
  • • Ability to accurately assess application integration readiness, identify technical gaps, and document findings in a structured and auditable manner
  • • Strong attention to detail with the ability to maintain accurate, real-time documentation across multiple concurrent application enablement efforts
  • • Familiarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, and DoDM 8140.03 cybersecurity certification requirements
  • • Ability to work effectively both independently and as part of a collaborative cross-functional team under the direction of a technical lead
  • • Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams
  • • Ability to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent)
  • • Prior experience supporting DoD IT programs, particularly within an ICAM or Zero Trust context
  • • Experience working in a federal government IT contracting environment
  • • Hands-on experience with Okta and/or SailPoint IdentityIQ (IIQ) in a production enterprise environment
  • • Okta Certified Professional, Okta Certified Administrator, or equivalent Okta platform certification
  • • SailPoint IdentityIQ (IIQ) certification or demonstrated advanced proficiency with the SailPoint platform
  • • Experience implementing Segregation of Duties (SOD) enforcement and audit reporting within an IGA platform
  • • Knowledge of Single Sign-On (SSO) troubleshooting methodologies, including the ability to interpret SAML assertions, OAuth token flows, and OIDC authentication responses
  • • Experience developing and maintaining technical documentation including integration guides, architecture diagrams, and standard operating procedures in a federal contracting environment
  • • Familiarity with Zero Trust Architecture (ZTA) principles and their application to identity and access management within a DoD context
  • • Experience with enterprise application portfolio migrations or large-scale IT modernization efforts
  • • Knowledge of automated provisioning workflows and SCIM-based directory synchronization in an enterprise environment
  • • Certified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification
  • • Familiarity with Section 508 compliance requirements for electronic and information technology
  • • Experience with CDRL deliverable development and contribution in a federal contracting environment
  • • Familiarity with Agile and/or hybrid Agile-Waterfall program execution methodologies
  • • Experience providing white glove technical support to non-technical end users or application owners navigating complex IT integration processes

Qualifications

Must Haves

  • • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university
  • • Minimum of 4 years of hands-on experience in information technology, with at least 2 years of direct experience in identity and access management, enterprise application integration, or related cybersecurity disciplines
  • • Demonstrated experience configuring and troubleshooting SSO integrations using SAML, OAuth 2.0, or OIDC in an enterprise environment
  • • Experience working with Identity Provider (IdP) or Identity Governance and Administration (IGA) platforms in a technical integration capacity
  • • Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification
  • • Secret clearance
  • • Strong technical communication skills in English—both written and oral—with the ability to clearly explain complex integration concepts to both technical engineers and non-technical application owners
  • • Hands-on experience configuring Okta for SSO, MFA, and application integration, including working with Okta application integrations, Universal Directory, and identity federation
  • • Hands-on experience with SailPoint IdentityIQ (IIQ), including connector configuration, automated provisioning and deprovisioning workflows, entitlement management, and access certification
  • • Working knowledge and practical implementation experience with SAML, OAuth 2.0, OIDC, and SCIM identity protocols
  • • Experience developing custom integration solutions including scripts, connectors, APIs, or middleware to bridge legacy applications with modern identity platforms
  • • Familiarity with Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) design and implementation principles
  • • Experience supporting or conducting User Acceptance Testing (UAT), including test case development, defect tracking, and resolution support
  • • Ability to accurately assess application integration readiness, identify technical gaps, and document findings in a structured and auditable manner
  • • Strong attention to detail with the ability to maintain accurate, real-time documentation across multiple concurrent application enablement efforts
  • • Familiarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, and DoDM 8140.03 cybersecurity certification requirements
  • • Ability to work effectively both independently and as part of a collaborative cross-functional team under the direction of a technical lead
  • • Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams
  • • Ability to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent)

Nice to Haves

  • • Prior experience supporting DoD IT programs, particularly within an ICAM or Zero Trust context
  • • Experience working in a federal government IT contracting environment
  • • Hands-on experience with Okta and/or SailPoint IdentityIQ (IIQ) in a production enterprise environment
  • • Okta Certified Professional, Okta Certified Administrator, or equivalent Okta platform certification
  • • SailPoint IdentityIQ (IIQ) certification or demonstrated advanced proficiency with the SailPoint platform
  • • Experience implementing Segregation of Duties (SOD) enforcement and audit reporting within an IGA platform
  • • Knowledge of Single Sign-On (SSO) troubleshooting methodologies, including the ability to interpret SAML assertions, OAuth token flows, and OIDC authentication responses
  • • Experience developing and maintaining technical documentation including integration guides, architecture diagrams, and standard operating procedures in a federal contracting environment
  • • Familiarity with Zero Trust Architecture (ZTA) principles and their application to identity and access management within a DoD context
  • • Experience with enterprise application portfolio migrations or large-scale IT modernization efforts
  • • Knowledge of automated provisioning workflows and SCIM-based directory synchronization in an enterprise environment
  • • Certified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification
  • • Familiarity with Section 508 compliance requirements for electronic and information technology
  • • Experience with CDRL deliverable development and contribution in a federal contracting environment
  • • Familiarity with Agile and/or hybrid Agile-Waterfall program execution methodologies
  • • Experience providing white glove technical support to non-technical end users or application owners navigating complex IT integration processes

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k) retirement plan
  • Paid time off
  • Paid parental leave
  • Life insurance
  • Disability insurance
  • Flexible spending accounts
  • Commuter benefits
  • Tuition reimbursement
  • Remote work

More jobs like this