Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Amatriot Group, LLC is seeking a Zero Trust Security Engineer focused on Okta to support the DCSA program in Quantico, VA. The role administers Okta Identity Cloud, implements SSO and MFA, and aligns authentication policies with zero trust and endpoint posture tools.
The position is primarily telework with on-site presence two days weekly and requires an active TS or higher clearance. Preferred candidates hold Okta certifications and have enterprise federal experience.
Location Quantico Va Hybrid 2 days onsite Security Clearance Active TS or higher Required Job Type Full Time Target Salary Range 120000 145000 This represents the potential salary range for this position depending on education level years of experience andor certifications in addition to other position specific requirements which may impact salary
Amatriot is hiring a Zero Trust Security Engineer Okta to support its Defense Counterintelligence and Security Agency DCSA program in Quantico VA 22134 USA The role administers configures maintains and integrates the Okta Identity Cloud platform to ensure secure seamless and compliant access to DCSA applications and resources It uses Single Sign On SSO Multi Factor Authentication MFA Lifecycle Management LCM Universal Directory and Okta Workflows to support Zero Trust architecture and secure the hybrid workforce
Platform Administration and ConfigurationManage configure and maintain daily operations of Okta Identity Cloud including Universal Directory SSO and MFADevelop implement and enforce granular sign on policies adaptive MFA and application level access controlsLifecycle Management and AutomationDesign implement and troubleshoot automated provisioning deprovisioning and user lifecycle workflows across target applicationsConfigure Okta Workflows or use scripting tools such as PowerShell and Python to automate manual IAM tasks and onboarding processes Directory and Application IntegrationIntegrate Okta with authoritative source directories including Active Directory LDAP and HR systems and cloud environments such as AWS and Azure ADOnboard and integrate SaaS web based and legacy on premises applications using SAML OIDC WS Fed and SCIM protocolsSecurity and Compliance IntegrationCollaborate with cybersecurity teams to integrate Okta system logs with SIEM tools such as Splunk for security monitoring and audit reporting Support Zero Trust implementation by aligning Okta authentication policies with endpoint posture assessment tools including Palo Alto GlobalProtect and crowd sourced agentsTroubleshooting and SupportServe as the Tier 2Tier 3 subject matter expert for Okta issues troubleshooting authentication failures provisioning errors federation mismatches and user access problemsDocumentation and TrainingCreate and maintain engineering runbooks standard operating procedures SOPs architecture diagrams and user guides Train and mentor junior support technicians and help desk staff on basic Okta troubleshooting and identity lifecycle actions
EducationBachelors degree in Cybersecurity Information Systems Management or a related field or an equivalent combination of military service andor at least five 5 years of significant relevant work experience Required ExperienceMinimum of 5 years of hands on experience administering configuring and supporting Okta Identity Cloud in an enterprise or federal environment Required SkillsStrong understanding of identity centric security directory services such as Active Directory and LDAP and modern federation protocols including SAML 20 OIDC and OAuth 20 Required Ability to communicate complex technical ideas to a diverse customer base verbally and in writing Required CertificationsMeet 8570 IAT Level II certification requirements at the time of hire such as Security CE CCNA Security CySA GICSP GSEC SCCP or a higher tier 8570 certification Required ClearanceActive Top Secret clearance and eligibility for an upgrade to TSSCI Required Working ConditionsPrimarily a telework position with a requirement to be onsite at least two 2 days a week or as needed at Quantico Marine Corps Base VA Additional onsite time may be required during initial onboarding and program integration Required If the alternate worksite is outside DCSA facilities or corporate office space reliable voice communication capability and a stable capable internet connection are required Required Preferred QualificationsCertificationsOfficial Okta certifications are highly desired Okta Certified Professional Okta Certified Administrator Okta Certified Developer Alternate Worksite CommunicationCell phone for voice communication when working outside DCSA facilities or corporate office space