Identity Access Management (IAM) Platform Lead

George Mason University

Fairfax (VA)

On-site

USD 120,000 - 160,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

George Mason University is seeking an Identity Access Management (IAM) Platform Lead to define the enterprise IAM reference architecture and target-state roadmap. You will own authority decisions across identity populations, lifecycle models, and federation strategies, while guiding modernization of Linux-hosted IAM services.

The role requires deep expertise in Entra ID, AD, SSO, MFA, and identity governance, with strong collaboration across cybersecurity, HR, student systems, and governance

Qualifications

  • Bachelor's degree or equivalent education/experience.
  • Significant enterprise IAM design/implementation experience.
  • Knowledge of Entra ID, AD, hybrid identity, SSO, MFA, and IAM governance.
  • Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy patterns.
  • Ability to translate complex IAM architecture to business/risk guidance.
  • Collaboration across cybersecurity, infra, HR, student systems, and governance bodies.

Responsibilities

  • Define enterprise IAM reference architecture and target-state roadmap.
  • Owns authority decisions across identity populations and lifecycle models.
  • Establishes onboarding, federation, SSO, and audit-evidence standards for apps.
  • Partner with cybersecurity, infrastructure, apps, HR, and governance bodies.
  • Provide architectural guidance for IAM incidents and modernization efforts.
  • Support cross-functional projects and off-hours availability as needed.

Skills

Microsoft Entra ID
Active Directory
Hybrid identity
SSO
MFA
Identity governance
Conditional Access
Zero Trust
LDAP
Linux
Python
Automation
SAML
OAuth
OIDC

Education

Bachelor's degree or equivalent

Tools

Red Hat Linux
Java
PowerShell
Shibboleth
eduGAIN

Job description

Identity Access Management (IAM) Platform Lead

Job Number: 10004603

Location: Fairfax, VA

Job Category: Classified Staff

Opening Date: Oct 2 2026

Department: Information Technology

Classification: Info Technology Spec 3

Job Category: Classified Staff

Job Type: Full-Time

Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)

Location: Fairfax, VA

Workplace Type: On Site Required

Sponsorship Eligibility: Not eligible for visa sponsorship

Pay Band: 06

Salary: Salary commensurate with education and experience

Criminal Background Check: Yes

About the Department:

Information Technology Services (ITS) provides technology and collaborative solutions that contribute to and facilitate innovative teaching and learning opportunities for students and faculty of the George Mason University community. ITS works transparently to drive excellence in teaching, research, and administrative operations.

About the Position:

The IAM Platform Lead serves as the enterprise IAM design authority for the university's identity target state. The position defines identity architecture, standards, source-of-authority decisions, lifecycle models, federation strategy, authorization patterns, application onboarding standards, and Zero Trust-aligned policy guardrails for Microsoft Entra ID, Active Directory, Shibboleth/InCommon/eduGAIN, and related identity services. The position also holds technical stewardship over legacy Linux-hosted IAM core services, providing subject-matter expertise in legacy technologies and leading troubleshooting efforts across the team. This role guides and sustains these services through a multi-year modernization program, ensuring continuity of critical identity functions throughout each transition phase.

Responsibilities
  • Defines and maintains the enterprise IAM reference architecture, target-state roadmap, design principles, standards, and decision framework for Microsoft Entra ID, Active Directory, hybrid identity, federation, identity governance, and Zero Trust identity controls;
  • Owns source-of-authority, attributes governance, lifecycle architecture, and authorization model decisions across workforce, student, research, affiliate, alumni, contractor, and external collaborator identity populations;
  • Establishes reusable application onboarding, federation, Single Sign-On (SSO), claims, group, role, entitlement, provisioning, and audit-evidence standards for enterprise applications and distributed campus systems;
  • Partners with cybersecurity, infrastructure, enterprise applications, human resources, student systems, research administration, distributed IT, governance bodies, and application owners to review designs, resolve identity architecture decisions, and approve exceptions;
  • Provides architectural consultation for complex IAM incidents, audit findings, modernization initiatives, platform selections, migration planning, and identity-related risk decisions; and
  • Contributes to special initiatives, cross-functional projects, and emerging priorities as the IAM program evolves, including availability outside standard business hours when operational or project demands require.
Required Qualifications
  • Bachelor's degree in related field or the equivalent combination of education and experience;
  • Significant experience designing, implementing, or governing enterprise identity and access management capabilities, including Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, lifecycle management, authorization models, identity governance, Conditional Access, Multi-Factor Authentication (MFA), and enterprise application onboarding;
  • Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, Conditional Access, MFA, passwordless authentication, lifecycle management, identity governance, and Zero Trust identity control patterns;
  • Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns;
  • Skill in developing enterprise architecture, standards, decision records, roadmaps, source-of-authority models, authorization models, and reusable application onboarding patterns;
  • Ability to translate complex identity architecture into clear business, technical, risk, and governance recommendations;
  • Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, distributed IT, and application-owner communities;
  • Ability to provide technical leadership and troubleshooting guidance for legacy Linux-hosted IAM services within a multi-year modernization program;
  • Must maintain confidentiality of sensitive identity, access, employee, student, and institutional data. May be required to participate in urgent response activities for significant identity platform incidents or security events;
  • Must be eligible to work in secure computing environments including International Traffic in Arms Regulations (ITAR) and Controlled Unclassified Information (CUI); and
  • Must be a citizen of the United States, or a person who is a lawful permanent resident of the United States (a "Green Card" holder), or a person who formally has been granted asylum by the United States (a "protected individual" as defined by US law), or a person whose permanent address is in the United States and who is not a national (including dual-national) of any country which is subject to a US arms embargo.
Preferred Qualifications
  • Master's degree in related field;
  • Relevant Microsoft identity, cybersecurity, cloud, enterprise architecture, or identity governance certifications preferred;
  • Red Hat system administration or engineering certifications (e.g., RHCSA, RHCE) are a plus;
  • Extensive experience in higher education, research-intensive, decentralized, or similarly complex identity environments;
  • Preferred experience includes InCommon/eduGAIN/Shibboleth federation, Microsoft-centric IAM modernization, access governance, PAM/IGA integration, Zero Trust identity policy design, Python or PowerShell automation, Linux-hosted identity services, and cross-functional architecture governance;
  • Hands-on experience migrating off legacy Linux-hosted IAM platforms to a modern IAM solution is highly valued;
  • Knowledge of higher-education IAM complexity, including student, faculty, staff, researcher, affiliate, alumni, contractor, and external collaborator populations;
  • Knowledge of InCommon, eduGAIN, Shibboleth, research federation, distributed campus governance, access governance, RBAC, ABAC, delegated administration, and entitlement catalog design;
  • Knowledge of Red Hat Enterprise Linux administration, Java programming, Apache Foundation integration technologies, Oracle Directory Services and Kerberos service operations;
  • Skill with Python, PowerShell, APIs, automation design, data analysis, and identity policy modeling;
  • Demonstrated ability to plan and execute incremental migration to modern cloud or SaaS-based alternatives;
  • Ability to reason about Linux-hosted identity components, certificates, reverse proxies, LDAP services, and Java-based enterprise application integration patterns; and
  • Ability to assess legacy IAM platform risk, sustain service continuity, and guide incremental migration toward modern SaaS and cloud-native identity solutions.

Posting Open Date: October 2, 2026

Open Until Filled: Yes

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

Commonwealth of VA Careers • Virginia (MN)

On-site
USD 120,000 - 160,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

Cooperative Education • Fairfax (VA)

On-site
USD 110,000 - 150,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

George Mason University • Chantilly (VA)

On-site
USD 120,000 - 160,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

Administration & Operations • Fairfax (VA), Virginia (MN)

On-site
USD 140,000 - 190,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Enterprise IAM Platform Lead | Identity Architect (On-Site)
Enterprise IAM Platform Lead | Identity Architect (On-Site)

Commonwealth of VA Careers • Virginia (MN)

On-site
USD 120,000 - 160,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Senior IT Security Analyst
Senior IT Security Analyst

Cybersecurity Jobs • Denver (CO)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) match
Paid time off
+1
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Systems Engineer I - IAM
Systems Engineer I - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 104,500 - 112,750
Health, Dental, Vision, Life Insurance
Paid Time Off
401(k) and Profit-Sharing Plans