{"schemaVersion":"jobsearcher.job.v1","id":"4bc467da9e2bee81eed2df26","url":"https://jobsearcher.com/jobs/4bc467da9e2bee81eed2df26","canonicalUrl":"https://jobsearcher.com/jobs/4bc467da9e2bee81eed2df26","title":"Migration Engineer (REMOTE)","description":"Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Migration Engineer with a Secret security clearance to support KITS and our government customer. The position is remote.\n\nWe offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.\n\nKoniag IT Systems, a Koniag Government Services company, is seeking an experienced Migration Engineer to support a critical Government Identity, Credential, and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Migration Engineer will serve as a hands-on technical contributor responsible for executing the integration and onboarding of NIPRNet applications onto a centralized ICAM technical stack—leveraging Okta for Identity Provider (IdP) services and SailPoint IdentityIQ (IIQ) for Identity Governance and Administration (IGA)—in direct support of the Department of Defense (DoD) Zero Trust Execution Roadmap.\n\nThe ideal candidate is a technically skilled engineer with practical experience in identity and access management technologies, application integration, and enterprise security protocols. This individual must be comfortable working directly with application owners, troubleshooting complex integration challenges, and delivering high-quality technical solutions in a fast-paced federal IT environment.\n\nThis position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed remotely.\n\nThe Migration Engineer will serve as a primary technical contributor on the enablement team, responsible for the hands-on execution of application integration activities across the full enablement lifecycle. This individual will work directly with application owners and internal technical teams to assess, configure, troubleshoot, and validate the integration of assigned applications into the Government ICAM ecosystem. The Migration Engineer is expected to deliver technically sound, secure, and compliant integration solutions while maintaining accurate documentation and status reporting throughout the enablement process.\n\nPrincipal responsibilities will include but are not limited to:\n\nExecute the technical integration of assigned NIPRNet applications into the ICAM technical stack, establishing logical network connections that route 100% of user authentication requests through the Okta IdP and 100% of user access management through SailPoint IGA in production environments.\nConduct thorough technical triage of assigned applications, assessing each application's current identity state, identifying integration gaps, documenting risks, and determining the appropriate enablement pathway—self-service, automated, or dedicated white glove support.\nConfigure and implement identity federation and SSO integrations using industry-standard protocols including SAML, OAuth 2.0, OIDC, and SCIM, leveraging existing Okta and SailPoint connectors where available.\nEngineer, develop, and deploy custom tools, scripts, connectors, and middleware solutions to facilitate the integration of legacy applications that cannot natively support modern identity protocols.\nProvide technical advisement and architectural guidance to Application Owners on configuring their applications to use the ICAM platform for authentication and authorization, including recommendations for implementing Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC).\nAssist Application Owners throughout the full enablement lifecycle, including application registration, credential issuance, non-PKI credential configuration, enrollment workflow setup, and access control module redesign.\nSupport Application Owners through the User Acceptance Testing (UAT) process, including providing sample code for common integration patterns, reusable libraries or middleware, troubleshooting integration defects, and assisting with defect resolution activities.\nAccurately document all triage findings, integration configurations, risk items, engagement activities, and application status updates in the Enablement Tracking Database, ensuring real-time accuracy and completeness.\nFollow and execute the Application Owner Escalation Matrix, documenting all engagement attempts with application owners and escalating stalled or non-responsive cases to the Migration Team Lead per established timelines and protocols.\nCollaborate with internal engineers, integration specialists, and the Migration Team Lead to resolve complex technical challenges and share reusable integration solutions across the application portfolio.\nContribute to the development and continuous refinement of enablement playbooks, integration guides, standard operating procedures, and technical documentation to support consistent and repeatable onboarding processes.\nGenerate and maintain technical documentation describing integration solutions, configurations, and architectural decisions for each assigned application.\nSupport the testing program by assisting in the development of test plans, executing integration testing, and preparing software test reports and observations for UAT events.\nEnsure all integration activities and developed solutions comply with applicable DoD security requirements, including CUI handling, OPSEC, Section 508 accessibility standards, and DoD cybersecurity certification requirements.\nMaintain awareness of evolving ICAM platform capabilities, identity protocols, and Zero Trust requirements, continuously applying updated knowledge to improve integration quality and program outcomes.\nEducation and Experience:Required:\n\nBachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university.\nMinimum of 4 years of hands-on experience in information technology, with at least 2 years of direct experience in identity and access management, enterprise application integration, or related cybersecurity disciplines.\nDemonstrated experience configuring and troubleshooting SSO integrations using SAML, OAuth 2.0, or OIDC in an enterprise environment.\nExperience working with Identity Provider (IdP) or Identity Governance and Administration (IGA) platforms in a technical integration capacity.\nActive Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.\nClearance Requirement:\n\nSecret clearance\nPreferred:\n\nPrior experience supporting DoD IT programs, particularly within an ICAM or Zero Trust context.\nExperience working in a federal government IT contracting environment.\nHands-on experience with Okta and/or SailPoint IdentityIQ (IIQ) in a production enterprise environment.\nRequired Skills and Competencies:\n\nStrong technical communication skills in English—both written and oral—with the ability to clearly explain complex integration concepts to both technical engineers and non-technical application owners.\nHands-on experience configuring Okta for SSO, MFA, and application integration, including working with Okta application integrations, Universal Directory, and identity federation.\nHands-on experience with SailPoint IdentityIQ (IIQ), including connector configuration, automated provisioning and deprovisioning workflows, entitlement management, and access certification.\nWorking knowledge and practical implementation experience with SAML, OAuth 2.0, OIDC, and SCIM identity protocols.\nExperience developing custom integration solutions including scripts, connectors, APIs, or middleware to bridge legacy applications with modern identity platforms.\nFamiliarity with Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) design and implementation principles.\nExperience supporting or conducting User Acceptance Testing (UAT), including test case development, defect tracking, and resolution support.\nAbility to accurately assess application integration readiness, identify technical gaps, and document findings in a structured and auditable manner.\nStrong attention to detail with the ability to maintain accurate, real-time documentation across multiple concurrent application enablement efforts.\nFamiliarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, and DoDM 8140.03 cybersecurity certification requirements.\nAbility to work effectively both independently and as part of a collaborative cross-functional team under the direction of a technical lead.\nProficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.\nAbility to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent).\nDesired Skills and Competencies:\n\nOkta Certified Professional, Okta Certified Administrator, or equivalent Okta platform certification.\nSailPoint IdentityIQ (IIQ) certification or demonstrated advanced proficiency with the SailPoint platform.\nExperience implementing Segregation of Duties (SOD) enforcement and audit reporting within an IGA platform.\nKnowledge of Single Sign-On (SSO) troubleshooting methodologies, including the ability to interpret SAML assertions, OAuth token flows, and OIDC authentication responses.\nExperience developing and maintaining technical documentation including integration guides, architecture diagrams, and standard operating procedures in a federal contracting environment.\nFamiliarity with Zero Trust Architecture (ZTA) principles and their application to identity and access management within a DoD context.\nExperience with enterprise application portfolio migrations or large-scale IT modernization efforts.\nKnowledge of automated provisioning workflows and SCIM-based directory synchronization in an enterprise environment.\nCertified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification.\nFamiliarity with Section 508 compliance requirements for electronic and information technology.\nExperience with CDRL deliverable development and contribution in a federal contracting environment.\nFamiliarity with Agile and/or hybrid Agile-Waterfall program execution methodologies.\nExperience providing white glove technical support to non-technical end users or application owners navigating complex IT integration processes.\nOur Equal Employment Opportunity Policy\nThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.\nThe company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.\n\nKoniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.\n\nEqual Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352","company":"Koniag Government Services","rawCompany":"koniag government services","isRemote":true,"isActive":false,"createdAt":"2026-08-15T13:19:43.645Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Migration Engineer (REMOTE)","description":"Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Migration Engineer with a Secret security clearance to support KITS and our government customer. The position is remote.\n\nWe offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.\n\nKoniag IT Systems, a Koniag Government Services company, is seeking an experienced Migration Engineer to support a critical Government Identity, Credential, and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Migration Engineer will serve as a hands-on technical contributor responsible for executing the integration and onboarding of NIPRNet applications onto a centralized ICAM technical stack—leveraging Okta for Identity Provider (IdP) services and SailPoint IdentityIQ (IIQ) for Identity Governance and Administration (IGA)—in direct support of the Department of Defense (DoD) Zero Trust Execution Roadmap.\n\nThe ideal candidate is a technically skilled engineer with practical experience in identity and access management technologies, application integration, and enterprise security protocols. This individual must be comfortable working directly with application owners, troubleshooting complex integration challenges, and delivering high-quality technical solutions in a fast-paced federal IT environment.\n\nThis position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed remotely.\n\nThe Migration Engineer will serve as a primary technical contributor on the enablement team, responsible for the hands-on execution of application integration activities across the full enablement lifecycle. This individual will work directly with application owners and internal technical teams to assess, configure, troubleshoot, and validate the integration of assigned applications into the Government ICAM ecosystem. The Migration Engineer is expected to deliver technically sound, secure, and compliant integration solutions while maintaining accurate documentation and status reporting throughout the enablement process.\n\nPrincipal responsibilities will include but are not limited to:\n\nExecute the technical integration of assigned NIPRNet applications into the ICAM technical stack, establishing logical network connections that route 100% of user authentication requests through the Okta IdP and 100% of user access management through SailPoint IGA in production environments.\nConduct thorough technical triage of assigned applications, assessing each application's current identity state, identifying integration gaps, documenting risks, and determining the appropriate enablement pathway—self-service, automated, or dedicated white glove support.\nConfigure and implement identity federation and SSO integrations using industry-standard protocols including SAML, OAuth 2.0, OIDC, and SCIM, leveraging existing Okta and SailPoint connectors where available.\nEngineer, develop, and deploy custom tools, scripts, connectors, and middleware solutions to facilitate the integration of legacy applications that cannot natively support modern identity protocols.\nProvide technical advisement and architectural guidance to Application Owners on configuring their applications to use the ICAM platform for authentication and authorization, including recommendations for implementing Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC).\nAssist Application Owners throughout the full enablement lifecycle, including application registration, credential issuance, non-PKI credential configuration, enrollment workflow setup, and access control module redesign.\nSupport Application Owners through the User Acceptance Testing (UAT) process, including providing sample code for common integration patterns, reusable libraries or middleware, troubleshooting integration defects, and assisting with defect resolution activities.\nAccurately document all triage findings, integration configurations, risk items, engagement activities, and application status updates in the Enablement Tracking Database, ensuring real-time accuracy and completeness.\nFollow and execute the Application Owner Escalation Matrix, documenting all engagement attempts with application owners and escalating stalled or non-responsive cases to the Migration Team Lead per established timelines and protocols.\nCollaborate with internal engineers, integration specialists, and the Migration Team Lead to resolve complex technical challenges and share reusable integration solutions across the application portfolio.\nContribute to the development and continuous refinement of enablement playbooks, integration guides, standard operating procedures, and technical documentation to support consistent and repeatable onboarding processes.\nGenerate and maintain technical documentation describing integration solutions, configurations, and architectural decisions for each assigned application.\nSupport the testing program by assisting in the development of test plans, executing integration testing, and preparing software test reports and observations for UAT events.\nEnsure all integration activities and developed solutions comply with applicable DoD security requirements, including CUI handling, OPSEC, Section 508 accessibility standards, and DoD cybersecurity certification requirements.\nMaintain awareness of evolving ICAM platform capabilities, identity protocols, and Zero Trust requirements, continuously applying updated knowledge to improve integration quality and program outcomes.\nEducation and Experience:Required:\n\nBachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university.\nMinimum of 4 years of hands-on experience in information technology, with at least 2 years of direct experience in identity and access management, enterprise application integration, or related cybersecurity disciplines.\nDemonstrated experience configuring and troubleshooting SSO integrations using SAML, OAuth 2.0, or OIDC in an enterprise environment.\nExperience working with Identity Provider (IdP) or Identity Governance and Administration (IGA) platforms in a technical integration capacity.\nActive Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.\nClearance Requirement:\n\nSecret clearance\nPreferred:\n\nPrior experience supporting DoD IT programs, particularly within an ICAM or Zero Trust context.\nExperience working in a federal government IT contracting environment.\nHands-on experience with Okta and/or SailPoint IdentityIQ (IIQ) in a production enterprise environment.\nRequired Skills and Competencies:\n\nStrong technical communication skills in English—both written and oral—with the ability to clearly explain complex integration concepts to both technical engineers and non-technical application owners.\nHands-on experience configuring Okta for SSO, MFA, and application integration, including working with Okta application integrations, Universal Directory, and identity federation.\nHands-on experience with SailPoint IdentityIQ (IIQ), including connector configuration, automated provisioning and deprovisioning workflows, entitlement management, and access certification.\nWorking knowledge and practical implementation experience with SAML, OAuth 2.0, OIDC, and SCIM identity protocols.\nExperience developing custom integration solutions including scripts, connectors, APIs, or middleware to bridge legacy applications with modern identity platforms.\nFamiliarity with Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) design and implementation principles.\nExperience supporting or conducting User Acceptance Testing (UAT), including test case development, defect tracking, and resolution support.\nAbility to accurately assess application integration readiness, identify technical gaps, and document findings in a structured and auditable manner.\nStrong attention to detail with the ability to maintain accurate, real-time documentation across multiple concurrent application enablement efforts.\nFamiliarity with DoD security requirements, including CUI handling, OPSEC, DFARS 252.204-7012, and DoDM 8140.03 cybersecurity certification requirements.\nAbility to work effectively both independently and as part of a collaborative cross-functional team under the direction of a technical lead.\nProficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.\nAbility to obtain and maintain required DoD cybersecurity certifications per DoDM 8140.03 (e.g., Security+ for IAT II or equivalent).\nDesired Skills and Competencies:\n\nOkta Certified Professional, Okta Certified Administrator, or equivalent Okta platform certification.\nSailPoint IdentityIQ (IIQ) certification or demonstrated advanced proficiency with the SailPoint platform.\nExperience implementing Segregation of Duties (SOD) enforcement and audit reporting within an IGA platform.\nKnowledge of Single Sign-On (SSO) troubleshooting methodologies, including the ability to interpret SAML assertions, OAuth token flows, and OIDC authentication responses.\nExperience developing and maintaining technical documentation including integration guides, architecture diagrams, and standard operating procedures in a federal contracting environment.\nFamiliarity with Zero Trust Architecture (ZTA) principles and their application to identity and access management within a DoD context.\nExperience with enterprise application portfolio migrations or large-scale IT modernization efforts.\nKnowledge of automated provisioning workflows and SCIM-based directory synchronization in an enterprise environment.\nCertified Information Systems Security Professional (CISSP), CompTIA Security+, or related cybersecurity certification.\nFamiliarity with Section 508 compliance requirements for electronic and information technology.\nExperience with CDRL deliverable development and contribution in a federal contracting environment.\nFamiliarity with Agile and/or hybrid Agile-Waterfall program execution methodologies.\nExperience providing white glove technical support to non-technical end users or application owners navigating complex IT integration processes.\nOur Equal Employment Opportunity Policy\nThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.\nThe company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.\n\nKoniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.\n\nEqual Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352","datePosted":"2026-08-15T13:19:43.645Z","dateModified":"2026-08-15T13:19:43.645Z","hiringOrganization":{"@type":"Organization","name":"Koniag Government Services","sameAs":"https://jobsearcher.com"},"jobLocationType":"TELECOMMUTE","applicantLocationRequirements":{"@type":"Country","name":"US"},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"4bc467da9e2bee81eed2df26"},"url":"https://jobsearcher.com/jobs/4bc467da9e2bee81eed2df26"}}