Identity Access Management (IAM) Platform Lead

Commonwealth of Virginia
  • Fairfax, VA
    2 days ago

    Job Description

    Department: Information Technology

    Classification: Info Technology Spec 3

    Job Category: Classified Staff

    Job Type: Full-Time

    Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)

    Location: Fairfax, VA

    Workplace Type: On Site Required

    Sponsorship Eligibility: Not eligible for visa sponsorship

    Pay Band: 06

    Salary: Salary commensurate with education and experience

    Criminal Background Check: Yes

    About the Department:

    Information Technology Services (ITS) provides technology and collaborative solutions that contribute to and facilitate innovative teaching and learning opportunities for students and faculty of the George Mason University community. ITS works transparently to drive excellence in teaching, research, and administrative operations.

    About the Position:

    The IAM Platform Lead serves as the enterprise IAM design authority for the university's identity target state. The position defines identity architecture, standards, source-of-authority decisions, lifecycle models, federation strategy, authorization patterns, application onboarding standards, and Zero Trust-aligned policy guardrails for Microsoft Entra ID, Active Directory, Shibboleth/InCommon/eduGAIN, and related identity services.

    The position also holds technical stewardship over legacy Linux-hosted IAM core services, providing subject-matter expertise in legacy technologies and leading troubleshooting efforts across the team. This role guides and sustains these services through a multi-year modernization program, ensuring continuity of critical identity functions throughout each transition phase.

    Responsibilities:

    • Defines and maintains the enterprise IAM reference architecture, target-state roadmap, design principles, standards, and decision framework for Microsoft Entra ID, Active Directory, hybrid identity, federation, identity governance, and Zero Trust identity controls;
    • Owns source-of-authority, attributes governance, lifecycle architecture, and authorization model decisions across workforce, student, research, affiliate, alumni, contractor, and external collaborator identity populations;
    • Establishes reusable application onboarding, federation, Single Sign-On (SSO), claims, group, role, entitlement, provisioning, and audit-evidence standards for enterprise applications and distributed campus systems;
    • Partners with cybersecurity, infrastructure, enterprise applications, human resources, student systems, research administration, distributed IT, governance bodies, and application owners to review designs, resolve identity architecture decisions, and approve exceptions;
    • Provides architectural consultation for complex IAM incidents, audit findings, modernization initiatives, platform selections, migration planning, and identity-related risk decisions; and
    • Contributes to special initiatives, cross-functional projects, and emerging priorities as the IAM program evolves, including availability outside standard business hours when operational or project demands require.

    Required Qualifications:

    • Bachelor's degree in related field or the equivalent combination of education and experience;
    • Significant experience designing, implementing, or governing enterprise identity and access management capabilities, including Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, lifecycle management, authorization models, identity governance, Conditional Access, Multi-Factor Authentication (MFA), and enterprise application onboarding;
    • Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, Conditional Access, MFA, passwordless authentication, lifecycle management, identity governance, and Zero Trust identity control patterns;
    • Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns;
    • Skill in developing enterprise architecture, standards, decision records, roadmaps, source-of-authority models, authorization models, and reusable application onboarding patterns;
    • Ability to translate complex identity architecture into clear business, technical, risk, and governance recommendations;
    • Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, distributed IT, and application-owner communities;
    • Ability to provide technical leadership and troubleshooting guidance for legacy Linux-hosted IAM services within a multi-year modernization program;
    • Must maintain confidentiality of sensitive identity, access, employee, student, and institutional data. May be required to participate in urgent response activities for significant identity platform incidents or security events;
    • Must be eligible to work in secure computing environments including International Traffic in Arms Regulations (ITAR) and Controlled Unclassified Information (CUI); and
    • Must be a citizen of the United States, or a person who is a lawful permanent resident of the United States (a "Green Card" holder), or a person who formally has been granted asylum by the United States (a "protected individual" as defined by US law), or a person whose permanent address is in the United States and who is not a national (including dual-national) of any country which is subject to a US arms embargo.

    Preferred Qualifications:

    • Master's degree in related field;
    • Relevant Microsoft identity, cybersecurity, cloud, enterprise architecture, or identity governance certifications preferred;
    • Red Hat system administration or engineering certifications (e.g., RHCSA, RHCE) are a plus;
    • Extensive experience in higher education, research-intensive, decentralized, or similarly complex identity environments;
    • Preferred experience includes InCommon/eduGAIN/Shibboleth federation, Microsoft-centric IAM modernization, access governance, PAM/IGA integration, Zero Trust identity policy design, Python or PowerShell automation, Linux-hosted identity services, and cross-functional architecture governance;
    • Hands-on experience migrating off legacy Linux-hosted IAM platforms to a modern IAM solution is highly valued;
    • Knowledge of higher-education IAM complexity, including student, faculty, staff, researcher, affiliate, alumni, contractor, and external collaborator populations;
    • Knowledge of InCommon, eduGAIN, Shibboleth, research federation, distributed campus governance, access governance, RBAC, ABAC, delegated administration, and entitlement catalog design;
    • Knowledge of Red Hat Enterprise Linux administration, Java programming, Apache Foundation integration technologies, Oracle Directory Services and Kerberos service operations;
    • Skill with Python, PowerShell, APIs, automation design, data analysis, and identity policy modeling;
    • Demonstrated ability to plan and execute incremental migration to modern cloud or SaaS-based alternatives;
    • Ability to reason about Linux-hosted identity components, certificates, reverse proxies, LDAP services, and Java-based enterprise application integration patterns; and
    • Ability to assess legacy IAM platform risk, sustain service continuity, and guide incremental migration toward modern SaaS and cloud-native identity solutions.

    Instructions to Applicants:

    For full consideration, applicants must apply for the Identity Access Management (IAM) Platform Lead at https://jobs.gmu.edu/. Complete and submit the online application to include three professional references with contact information, and provide a cover letter and resume for review.

    Posting Open Date: October 2, 2026

    For Full Consideration, Apply by: October 16, 2026

    Open Until Filled: Yes

    Numbers & Facts

    LocationFairfax, VA

    Skills

    • Apacheunmatched
    • Application Programming Interface (API)unmatched
    • Architectural Servicesunmatched
    • Authenticationunmatched
    • Automationunmatched
    • Background Investigationunmatched
    • Business Operationsunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Computer Securityunmatched
    • Computer Systemsunmatched
    • Cross-Functionalunmatched
    • Data Analysisunmatched
    • Distributed Applicationsunmatched
    • Enterprise Application Integration (EAI)unmatched
    • Enterprise Applicationsunmatched
    • Enterprise Architectureunmatched
    • Higher Educationunmatched
    • Human Resourcesunmatched
    • IT Governanceunmatched
    • Identify Issuesunmatched
    • Identity Data Managementunmatched
    • Identity Federationunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Javaunmatched
    • Java Platform Enterprise Edition (Java EE/J2EE)unmatched
    • Kerberosunmatched
    • LDAP (Lightweight Directory Access Protocol)unmatched
    • Legalunmatched
    • Linux Administrationunmatched
    • Linux Operating Systemunmatched
    • Management Strategyunmatched
    • Microsoft Access Databaseunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • OAuthunmatched
    • Onboardingunmatched
    • OpenIDunmatched
    • Operations Researchunmatched
    • Oracleunmatched
    • Python Programming/Scripting Languageunmatched
    • Red Hat Linux Operating Systemunmatched
    • Regulationsunmatched
    • Research Administrationunmatched
    • Research Skillsunmatched
    • Riskunmatched
    • Security Assertion Markup Language (SAML)unmatched
    • Security Attacksunmatched
    • Single Sign-On (SSO)unmatched
    • Software as a Service (SaaS)unmatched
    • Stewardshipunmatched
    • System Migrationunmatched
    • Systems Administration/Managementunmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • Training/Teachingunmatched
    • United States Citizenunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder