Skip to content

Principal Classified Systems Architect, Okta Federal

Leads architecture of air-gapped classified (SIPR/JWICS) developer platforms for DoD compliance, designs IaC for disconnected ops, integrates hardened tools like Big Bang/Iron Bank, and ensures secure, scalable Kubernetes infrastructure. Requires 12+ years experience with 5+ in classified DoD environments.

224k – 308kWashington, DCDevOps / SREOnsite12+ YOE

About the role

What you’ll be doing

  • Act as the central point for defining and evolving the architecture of Okta Federal’s SIPR/JWICS environments, ensuring alignment with DoD reference designs while tailoring them to Okta’s specific product needs.
  • Design resilient, scalable infrastructure-as-code (IaC) and blueprints for air-gapped environments, solving unique challenges related to disconnected operations, cross-domain solutions (CDS), and "sneaker-net" patch management.
  • Collaborate closely with Product Engineering (ORD), Site Reliability Engineers (SREs), Business Application teams, Collaboration Engineering teams, and Security teams to translate complex compliance controls (DISA STIGs, RMF) into automated technical implementations that minimize friction for developers.
  • Guide the selection and integration of "High Side" tools and technologies, prioritizing compliant, maintainable, and low-vulnerability solutions (e.g., utilizing Iron Bank hardened containers) that deliver a superior user experience for internal engineering teams.
  • Review and approve architectural changes and major system upgrades across the classified boundary, ensuring that operational drift does not introduce security risks or break compliance postures.
  • Measure success through a combination of quantitative metrics (platform uptime, ATO velocity, patch latency, vulnerability resolution time) and qualitative feedback (developer satisfaction, ease of deployment).
  • Establish the technical strategy for "High Side" observability and continuous monitoring, designing architectures that satisfy strict auditing requirements without sacrificing operational visibility.

What you’ll bring to the role

  • 12+ years of experience in systems architecture, DevSecOps engineering, or a similar role, with at least 5 years focused on DoD Classified environments (IL6/Secret or higher).
  • Deep expertise in the DoD software ecosystem, specifically with Platform One/Cloud One, Big Bang, and Iron Bank. You should understand how to deploy, configure, and maintain these platforms in disconnected environments.
  • Strong understanding of Kubernetes (EKS/RKE2) and container orchestration in air-gapped setups, including the nuances of managing container registries, Helm charts, and sidecars without internet access.
  • Demonstrated hands-on experience architecting solutions that meet strict federal compliance frameworks, specifically DoD CC SRG IL6, NIST 800-53, and FIPS 140-3 cryptography standards.
  • Proven experience working with Cross Domain Solutions (CDS) and architecting secure data transfer workflows between Low Side (IL5) and High Side (SIPR/JWICS) networks.
  • Experience implementing Zero Trust Architecture (ZTA) principles in legacy or restrictive network environments.
  • Excellent collaboration and communication skills, with the ability to summarize and explain complex "High Side" constraints to uncleared Commercial stakeholders and influence decision-making across various business units.

Skills

KubernetesEKSRke2Big BangIron BankPlatform OneCloud OneIacHelmZero Trust ArchitectureNist 800-53Disa StigsRmfCross Domain Solutions

Similar roles

DevOps / SRE jobs

Software Architect, Reliability Engineering

Drives technical strategy and vision for Twilio's Reliability Engineering, leading scalable solutions for global product reliability using Kubernetes, AWS, and observability tools. Requires 15+ years in SRE/DevOps with principal-level experience.

228k – 335kUnited StatesDevOps / SRERemote15+ YOEGoAWS

Principal Infrastructure Engineer

Principal Infrastructure Engineer building and operating secure cloud-native and edge platforms for military collaboration software. Requires 8+ years production infrastructure experience, deep Kubernetes expertise, and ability to obtain SECRET clearance.

235k – 275kUnited StatesDevOps / SRERemote8+ YOEGoAWS

Principal Software Engineer, SDN Networking

Leads development of Software Defined Networking strategy using kernel bypass technologies like XDP/EBPF, DPDK, and SmartNICs. Guides team on architecture, Linux kernel development, and production-scale network infrastructure for AI cloud workloads. Requires 10+ years experience in systems programming with C/C++/Rust.

238k – 298kSan Francisco, CA +1DevOps / SREOn-site10+ YOECC++

Principal/Staff HPC Network Engineer

Designs, deploys, and maintains high-performance networks for large-scale GPU clusters in HPC environments. Requires 10+ years experience with InfiniBand/RoCEv2 in CLOS topologies, automation, and hybrid work in San Francisco.

250k – 325kSan Francisco, CADevOps / SREHybrid10+ YOEKvmClos

Senior Principal Software Engineer, Infrastructure

Technical visionary architecting Docker's foundational platform for accounts, billing, data, governance, and infrastructure. Drives cross-company strategy enabling enterprise growth, requiring 12+ years experience in large-scale distributed systems.

251k – 352kSeattle, WADevOps / SRERemote12+ YOEAWSGCP