About this opportunity
Amatriot Group, LLC lists this Zero Trust Security Engineer - Okta opportunity in quantico base, Virginia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Career Opportunities with Amatriot Group, LLC
A great place to work.
Are you ready for new challenges and new opportunities?
Join our team!
Current job opportunities are posted here as they become available.
Location: Quantico, Va. Hybrid 2 days onsite.
Security Clearance: Active TS or higher (Required)
Job Type: Full-Time
Target Salary Range*: $120,000 - $145,000
*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
Position Overview
Amatriot is hiring a Zero Trust Security Engineer – Okta to support its Defense Counterintelligence and Security Agency (DCSA) program in Quantico, VA 22134, USA.
The role administers, configures, maintains, and integrates the Okta Identity Cloud platform to ensure secure, seamless, and compliant access to DCSA applications and resources. It uses Single Sign-On (SSO), Multi-Factor Authentication (MFA), Lifecycle Management (LCM), Universal Directory, and Okta Workflows to support Zero Trust architecture and secure the hybrid workforce.
Key Responsibilities
Platform Administration and Configuration
Manage, configure, and maintain daily operations of Okta Identity Cloud, including Universal Directory, SSO, and MFA.
Develop, implement, and enforce granular sign-on policies, adaptive MFA, and application-level access controls.
Lifecycle Management and Automation
Design, implement, and troubleshoot automated provisioning, deprovisioning, and user lifecycle workflows across target applications.
Configure Okta Workflows or use scripting tools such as PowerShell and Python to automate manual IAM tasks and onboarding processes.
Directory and Application Integration
Integrate Okta with authoritative source directories, including Active Directory, LDAP, and HR systems, and cloud environments such as AWS and Azure AD.
Onboard and integrate SaaS, web-based, and legacy on-premises applications using SAML, OIDC, WS-Fed, and SCIM protocols.
Security and Compliance Integration
Collaborate with cybersecurity teams to integrate Okta system logs with SIEM tools such as Splunk for security monitoring and audit reporting.
Support Zero Trust implementation by aligning Okta authentication policies with endpoint posture assessment tools, including Palo Alto GlobalProtect and crowd-sourced agents.
Troubleshooting and Support
Serve as the Tier 2/Tier 3 subject matter expert for Okta issues, troubleshooting authentication failures, provisioning errors, federation mismatches, and user access problems.
Documentation and Training
Create and maintain engineering runbooks, standard operating procedures (SOPs), architecture diagrams, and user guides.
Train and mentor junior support technicians and help desk staff on basic Okta troubleshooting and identity lifecycle actions.
Qualifications
Education
Bachelor’s degree in Cybersecurity, Information Systems Management, or a related field, or an equivalent combination of military service and/or at least five (5) years of significant, relevant work experience. (Required)
Experience
Minimum of 5 years of hands‑on experience administering, configuring, and supporting Okta Identity Cloud in an enterprise or federal environment. (Required)
Skills
Strong understanding of identity‑centric security, directory services such as Active Directory and LDAP, and modern federation protocols, including SAML 2.0, OIDC, and OAuth 2.0. (Required)
Ability to communicate complex technical ideas to a diverse customer base verbally and in writing. (Required)
Certifications
Meet 8570 IAT Level II certification requirements at the time of hire, such as Security+ CE, CCNA Security, CySA+, GICSP, GSEC, SCCP, or a higher‑tier 8570 certification. (Required)
Clearance
Active Top Secret clearance and eligibility for an upgrade to TS/SCI. (Required)
Working Conditions
Primarily a telework position, with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base, VA. Additional onsite time may be required during initial onboarding and program integration. (Required)
If the alternate worksite is outside DCSA facilities or corporate office space, reliable voice communication capability and a stable, capable internet connection are required. (Required)
Preferred Qualifications
Certifications
Official Okta certifications are highly desired:
Okta Certified Professional.
Okta Certified Administrator.
Okta Certified Consultant or Okta Certified Developer.
Cell phone for voice communication when working outside DCSA facilities or corporate office space.
#J-18808-Ljbffr
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.