Zero Trust Security Engineer - Okta
Position Description
ASRC Federal is actively hiring an Intermediate Okta Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico, VA. We are seeking a skilled and highly motivated Identity and Access Management (IAM) professional to join our dynamic cybersecurity team.
Minimum Requirements
- Minimum of 5 years of hands-on experience administering, configuring, and supporting the Okta Identity Cloud platform in an enterprise or federal environment.
- IAM Expertise: Strong understanding of identity-centric security, directory services (Active Directory, LDAP), and modern federation protocols (SAML 2.0, OIDC, OAuth 2.0).
- Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
- Must meet 8570 certification requirements at the time of hire. IAT Level II (e.g., Security+ CE, CCNA Security, CySA+, GICSP, GSEC, SCCP or higher tiered 8570 certification).
- Bachelor’s Degree, in Cybersecurity, Information Systems Management or a related field or an equivalent combination of military service and/or at least five (5) years of significant, relevant work experience.
- Desired Certifications: Official Okta certifications are highly desired: Okta Certified Professional, Okta Certified Administrator, Okta Certified Consultant or Okta Certified Developer (plus).
Responsibilities
- Solution Administration and Configuration
- Manage, configure, and maintain the daily operations of the Okta Identity Cloud platform, including Universal Directory, Single Sign-On (SSO), and Multi-Factor Authentication (MFA).
- Develop, implement, and enforce granular sign-on policies, adaptive MFA, and application-level access controls.
- Lifecycle Management & Automation
- Design, implement, and troubleshoot automated provisioning, deprovisioning, and user lifecycle workflows (Lifecycle Management) across various target applications.
- Utilize and configure Okta Workflows or scripting (e.g., PowerShell, Python) to automate manual IAM tasks and onboarding processes.
- Directory & Application Integration
- Connect and integrate Okta with authoritative source directories (Active Directory, LDAP, HR systems) and cloud environments (AWS, Azure AD).
- Onboard and integrate SaaS, web-based, and legacy on-premise applications using SAML, OIDC, WS-Fed, and SCIM protocols.
- Security & Compliance Integration
- Collaborate with cybersecurity teams to integrate Okta system logs with Security Information and Event Management (SIEM) tools (e.g., Splunk) for security monitoring and audit reporting.
- Support the implementation of Zero Trust architecture by aligning Okta authentication policies with endpoint posture assessment tools (e.g., Palo Alto GlobalProtect, crowd-sourced agents).
- Troubleshooting and Support
- Serve as the Tier-2/Tier-3 Subject Matter Expert (SME) for Okta-related issues, troubleshooting authentication failures, provisioning errors, federation mismatches, and user access issues.
- Documentation and Training
- Create and update high-quality engineering runbooks, standard operating procedures (SOPs), architecture diagrams, and user guides.
- Train and mentor junior support technicians and help desk staff on basic Okta troubleshooting and identity lifecycle actions.
Work Environment And Physical Demands
- This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA.
- Additional onsite time may be required during initial onboarding and program integration.
- If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection.
- Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form.
Benefits
- We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages.
- Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.
Salary Range
The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
EEO Statement
ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.