Principal Classified Systems Architect, Okta Federal

Okta Okta · Enterprise · Washington, DC · BT Operations-165

Okta Federal is seeking a Principal Classified Systems Architect to design, develop, and evolve a "High Side" developer platform for US Classified environments. This role focuses on building a compliant and scalable platform for product teams to deliver identity capabilities to the U.S. Government, bridging DoD compliance with DevOps velocity in air-gapped, classified settings.

What you'd actually do

  1. Act as the central point for defining and evolving the architecture of Okta Federal’s SIPR/JWICS environments, ensuring alignment with DoD reference designs while tailoring them to Okta’s specific product needs.
  2. Design resilient, scalable infrastructure-as-code (IaC) and blueprints for air-gapped environments, solving unique challenges related to disconnected operations, cross-domain solutions (CDS), and "sneaker-net" patch management.
  3. Collaborate closely with Product Engineering (ORD), Site Reliability Engineers (SREs), Business Application teams, Collaboration Engineering teams, and Security teams to translate complex compliance controls (DISA STIGs, RMF) into automated technical implementations that minimize friction for developers.
  4. Guide the selection and integration of "High Side" tools and technologies, prioritizing compliant, maintainable, and low-vulnerability solutions (e.g., utilizing Iron Bank hardened containers) that deliver a superior user experience for internal engineering teams.
  5. Review and approve architectural changes and major system upgrades across the classified boundary, ensuring that operational drift does not introduce security risks or break compliance postures.

Skills

Required

  • 12+ years of experience in systems architecture, DevSecOps engineering, or a similar role
  • 5 years focused on DoD Classified environments (IL6/Secret or higher)
  • Deep expertise in the DoD software ecosystem, specifically with Platform One/Cloud One, Big Bang, and Iron Bank
  • Strong understanding of Kubernetes (EKS/RKE2) and container orchestration in air-gapped setups
  • Demonstrated hands-on experience architecting solutions that meet strict federal compliance frameworks, specifically DoD CC SRG IL6, NIST 800-53, and FIPS 140-3 cryptography standards
  • Proven experience working with Cross Domain Solutions (CDS) and architecting secure data transfer workflows between Low Side (IL5) and High Side (SIPR/JWICS) networks
  • Experience implementing Zero Trust Architecture (ZTA) principles in legacy or restrictive network environments
  • Excellent collaboration and communication skills

Nice to have

  • ability to solve complex "air gap" challenges outside the box

What the JD emphasized

  • DoD Classified environments (IL6/Secret or higher)
  • Platform One/Cloud One, Big Bang, and Iron Bank
  • DoD CC SRG IL6, NIST 800-53, and FIPS 140-3
  • Cross Domain Solutions (CDS)
  • U.S. security clearance (Secret or Top Secret)