Principal Classified Systems Architect, Okta Federal
Leads architecture of air-gapped classified (SIPR/JWICS) developer platforms for DoD compliance, designs IaC for disconnected ops, integrates hardened tools like Big Bang/Iron Bank, and ensures secure, scalable Kubernetes infrastructure. Requires 12+ years experience with 5+ in classified DoD environments.
About the job
What you’ll be doing
- Act as the central point for defining and evolving the architecture of Okta Federal’s SIPR/JWICS environments, ensuring alignment with DoD reference designs while tailoring them to Okta’s specific product needs.
- Design resilient, scalable infrastructure-as-code (IaC) and blueprints for air-gapped environments, solving unique challenges related to disconnected operations, cross-domain solutions (CDS), and "sneaker-net" patch management.
- Collaborate closely with Product Engineering (ORD), Site Reliability Engineers (SREs), Business Application teams, Collaboration Engineering teams, and Security teams to translate complex compliance controls (DISA STIGs, RMF) into automated technical implementations that minimize friction for developers.
- Guide the selection and integration of "High Side" tools and technologies, prioritizing compliant, maintainable, and low-vulnerability solutions (e.g., utilizing Iron Bank hardened containers) that deliver a superior user experience for internal engineering teams.
- Review and approve architectural changes and major system upgrades across the classified boundary, ensuring that operational drift does not introduce security risks or break compliance postures.
- Measure success through a combination of quantitative metrics (platform uptime, ATO velocity, patch latency, vulnerability resolution time) and qualitative feedback (developer satisfaction, ease of deployment).
- Establish the technical strategy for "High Side" observability and continuous monitoring, designing architectures that satisfy strict auditing requirements without sacrificing operational visibility.
What you’ll bring to the role
- 12+ years of experience in systems architecture, DevSecOps engineering, or a similar role, with at least 5 years focused on DoD Classified environments (IL6/Secret or higher).
- Deep expertise in the DoD software ecosystem, specifically with Platform One/Cloud One, Big Bang, and Iron Bank. You should understand how to deploy, configure, and maintain these platforms in disconnected environments.
- Strong understanding of Kubernetes (EKS/RKE2) and container orchestration in air-gapped setups, including the nuances of managing container registries, Helm charts, and sidecars without internet access.
- Demonstrated hands-on experience architecting solutions that meet strict federal compliance frameworks, specifically DoD CC SRG IL6, NIST 800-53, and FIPS 140-3 cryptography standards.
- Proven experience working with Cross Domain Solutions (CDS) and architecting secure data transfer workflows between Low Side (IL5) and High Side (SIPR/JWICS) networks.
- Experience implementing Zero Trust Architecture (ZTA) principles in legacy or restrictive network environments.
- Excellent collaboration and communication skills, with the ability to summarize and explain complex "High Side" constraints to uncleared Commercial stakeholders and influence decision-making across various business units.
Skills
Kubernetes, EKS, Rke2, Big Bang, Iron Bank, Platform One, Cloud One, Iac, Helm, Zero Trust Architecture, Nist 800-53, Disa Stigs, Rmf, Cross Domain Solutions
Similar jobs
DevOps / SRE jobsBuild and operate AI-powered developer tools, internal MCP integrations, and platform capabilities across the engineering organization. The role requires strong coding and debugging skills, Kubernetes operations experience, and the ability to lead projects, improve developer experience, and mentor teammates.
This principal-level role owns operational excellence for a hyperscale AI data center network fleet, leading readiness, high-risk changes, audits, and incident resolution across sites. It requires extensive mission-critical network operations experience, routing and optical networking expertise, and 50–75% travel.
Leads Snowflake’s cloud infrastructure performance strategy by evaluating new hardware, building benchmark and validation systems, and translating performance data into pricing, capacity, and rollout decisions. Requires 12+ years in performance, systems, or infrastructure engineering and deep cloud hardware expertise.
As a Principal Operations Engineer, Mechanical, you will be the senior technical authority for mechanical and cooling infrastructure across hyperscale AI data centers. You will lead site assessments, drive operational readiness, review designs, and ensure precision execution of critical systems.
Own and scale secure cloud infrastructure, deployments, observability, compliance, and incident response for a hardware collaboration platform. The role requires substantial cloud or security engineering experience, AWS and Linux expertise, and the ability to lead cross-functional infrastructure initiatives.