Department: Information Technology
Classification: Info Technology Spec 3
Job Category: Classified Staff
Job Type: Full-Time
Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)
Location: Fairfax, VA
Workplace Type: On Site Required
Sponsorship Eligibility: Not eligible for visasponsorship
Pay Band: 06
Salary: Salary commensurate with education andexperience
Criminal Background Check: Yes
About the Department:
Information Technology Services (ITS) provides technology andcollaborative solutions that contribute to and facilitateinnovative teaching and learning opportunities for students andfaculty of the George Mason University community. ITS workstransparently to drive excellence in teaching, research, andadministrative operations.
About the Position:
The IAM Platform Lead serves as the enterprise IAM design authority for the university’s identity target state. The position defines identity architecture, standards, source-of-authority decisions, lifecycle models, federation strategy, authorization patterns, application onboarding standards, and Zero Trust-aligned policy guardrails for Microsoft Entra ID, Active Directory, Shibboleth/InCommon/eduGAIN, and related identity services.
The position also holds technical stewardship over legacy Linux-hosted IAM core services, providing subject-matter expertise in legacy technologies and leading troubleshooting efforts across the team. This role guides and sustains these services through a multi-year modernization program, ensuring continuity of critical identity functions throughout each transition phase.
Responsibilities:
- Defines and maintains the enterprise IAM referencearchitecture, target-state roadmap, design principles, standards,and decision framework for Microsoft Entra ID, Active Directory,hybrid identity, federation, identity governance, and Zero Trustidentity controls;
- Owns source-of-authority, attributes governance, lifecyclearchitecture, and authorization model decisions across workforce,student, research, affiliate, alumni, contractor, and externalcollaborator identity populations;
- Establishes reusable application onboarding, federation, SingleSign-On (SSO), claims, group, role, entitlement, provisioning, andaudit-evidence standards for enterprise applications anddistributed campus systems;
- Partners with cybersecurity, infrastructure, enterpriseapplications, human resources, student systems, research administration, distributed IT, governance bodies, and applicationowners to review designs, resolve identity architecture decisions,and approve exceptions;
- Provides architectural consultation for complex IAM incidents,audit findings, modernization initiatives, platform selections, migration planning, and identity-related risk decisions; and
- Contributes to special initiatives, cross-functional projects,and emerging priorities as the IAM program evolves, includingavailability outside standard business hours when operational orproject demands require.
Required Qualifications:
- Bachelor’s degree in related field or the equivalentcombination of education and experience;
- Significant experience designing, implementing, or governingenterprise identity and access management capabilities, includingMicrosoft Entra ID, Active Directory, hybrid identity, federation,SSO, lifecycle management, authorization models, identity governance, Conditional Access, Multi-Factor Authentication (MFA), and enterprise application onboarding;
- Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, Conditional Access, MFA, passwordlessauthentication, lifecycle management, identity governance, and Zero Trust identity control patterns;
- Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns;
- Skill in developing enterprise architecture, standards, decision records, roadmaps, source-of-authority models, authorization models, and reusable application onboarding patterns;
- Ability to translate complex identity architecture into clearbusiness, technical, risk, and governance recommendations;
- Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, distributed IT, and application-owner communities;
- Ability to provide technical leadership and troubleshootingguidance for legacy Linux-hosted IAM services within a multi-year modernization program;
- Must maintain confidentiality of sensitive identity, access,employee, student, and institutional data. May be required toparticipate in urgent response activities for significant identityplatform incidents or security events;
- Must be eligible to work in secure computing environments including International Traffic in Arms Regulations (ITAR) and Controlled Unclassified Information (CUI); and
- Must be a citizen of the United States, or a person who is a lawful permanent resident of the United States (a “Green Card”holder), or a person who formally has been granted asylum by the United States (a “protected individual” as defined by US law), or a person whose permanent address is in the United States and who is not a national (including dual-national) of any country which is subject to a US arms embargo.
Preferred Qualifications:
- Master’s degree in related field;
- Relevant Microsoft identity, cybersecurity, cloud, enterprisearchitecture, or identity governance certifications preferred;
- Red Hat system administration or engineering certifications(e.g., RHCSA, RHCE) are a plus;
- Extensive experience in higher education, research-intensive, decentralized, or similarly complex identity environments;
- Preferred experience includes InCommon/eduGAIN/Shibbolethfederation, Microsoft-centric IAM modernization, access governance,PAM/IGA integration, Zero Trust identity policy design, Python orPowerShell automation, Linux-hosted identity services, andcross-functional architecture governance;
- Hands-on experience migrating off legacy Linux-hosted IAMplatforms to a modern IAM solution is highly valued;
- Knowledge of higher-education IAM complexity, includingstudent, faculty, staff, researcher, affiliate, alumni, contractor,and external collaborator populations;
- Knowledge of InCommon, eduGAIN, Shibboleth, researchfederation, distributed campus governance, access governance, RBAC,ABAC, delegated administration, and entitlement catalogdesign;
- Knowledge of Red Hat Enterprise Linux administration, Javaprogramming, Apache Foundation integration technologies, OracleDirectory Services and Kerberos service operations;
- Skill with Python, PowerShell, APIs, automation design, dataanalysis, and identity policy modeling;
- Demonstrated ability to plan and execute incremental migrationto modern cloud or SaaS-based alternatives;
- Ability to reason about Linux-hosted identity components, certificates, reverse proxies, LDAP services, and Java-basedenterprise application integration patterns; and
- Ability to assess legacy IAM platform risk, sustain servicecontinuity, and guide incremental migration toward modern SaaS andcloud-native identity solutions.
Posting Open Date:
October 2, 2026
For Full Consideration, Apply by:
October 16, 2026
Open Until Filled:
Yes
Mason Ad Statement
George Mason University is a nationally ranked R1 research university committed to creating a more just, free, and prosperous world. With 40,000 enrolled students, George Mason is the largest and most diverse public research university in Virginia, offering degree programs at the master's, doctoral, and professional level, along with certificates and credentials.
George Mason fosters an All Together Different environment for students, faculty, and staff, driven by our core beliefs. Webelieve in inclusivity over exclusivity; we believe in advancing our mission by being willing to take risks, not avoiding them; and we believe our best work is possible when we apply our diversity of origin, identity, circumstance, and thought.
Equity Statement
George Mason University is an equal opportunity/affirmative action employer, committed to promoting inclusion and equity in its community. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any characteristic protected by law.
Campus Safety Information
Mason’s Annual Security and Fire Safety Report is available at http://police.gmu.edu/annual-security-report/.