Identity Access Management (IAM) Platform Lead

Commonwealth of VA Careers

Virginia (MN)

On-site

USD 120,000 - 160,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

George Mason University Information Technology Services seeks an IAM Platform Lead to serve as the enterprise IAM design authority. This role defines identity architecture, standards, federation strategy, and Zero Trust policy guardrails for Entra ID, AD, Shibboleth, and related services.

The position also maintains legacy Linux IAM services and guides a multi-year modernization program to ensure continuity of critical identity functions during transitions.

Qualifications

  • Bachelor’s degree or equivalent experience.
  • Significant experience designing, implementing, or governing enterprise IAM capabilities.
  • Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, MFA, and identity governance.
  • Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns.
  • Ability to translate complex identity architecture into clear business, technical, risk, and governance recommendations.
  • Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, and distributed IT teams.
  • Ability to provide technical leadership for legacy Linux-hosted IAM services within a modernization program.
  • Must be eligible to work in secure computing environments (ITAR/CUI) and a U.S. citizen or approved immigrant.

Responsibilities

  • Defines and maintains the enterprise IAM reference architecture and target-state roadmap.
  • Owns governance of source-of-authority, attributes, lifecycle, and authorization models.
  • Establishes onboarding, federation, SSO, claims, group, role, and provisioning standards for enterprise apps.
  • Partners with cybersecurity, infra, HR, student systems, and governance bodies to review designs and approve exceptions.
  • Provides architectural consultation for IAM incidents, audits, and modernization efforts.
  • Contributes to cross-functional initiatives and supports after-hours needs as required.

Skills

Enterprise IAM
Microsoft Entra ID
Active Directory
Federation
SSO
MFA
Zero Trust
Lifecycle management
Policy governance
Cross-functional collaboration

Education

Bachelor’s degree
Master’s degree preferred

Tools

Shibboleth
LDAP
OAuth
OIDC

Job description

Department: Information Technology

Classification: Info Technology Spec 3

Job Category: Classified Staff

Job Type: Full-Time

Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)

Location: Fairfax, VA

Workplace Type: On Site Required

Sponsorship Eligibility: Not eligible for visa sponsorship

Pay Band: 06

Salary: Salary commensurate with education and experience

Criminal Background Check: Yes

About the Department:

Information Technology Services (ITS) provides technology and collaborative solutions that contribute to and facilitate innovative teaching and learning opportunities for students and faculty of the George Mason University community. ITS works transparently to drive excellence in teaching, research, and administrative operations.

About the Position:

The IAM Platform Lead serves as the enterprise IAM design authority for the university’s identity target state. The position defines identity architecture, standards, source-of-authority decisions, lifecycle models, federation strategy, authorization patterns, application onboarding standards, and Zero Trust-aligned policy guardrails for Microsoft Entra ID, Active Directory, Shibboleth/InCommon/eduGAIN, and related identity services.

The position also holds technical stewardship over legacy Linux-hosted IAM core services, providing subject-matter expertise in legacy technologies and leading troubleshooting efforts across the team. This role guides and sustains these services through a multi-year modernization program, ensuring continuity of critical identity functions throughout each transition phase.

Responsibilities:
  • Defines and maintains the enterprise IAM reference architecture, target-state roadmap, design principles, standards, and decision framework for Microsoft Entra ID, Active Directory, hybrid identity, federation, identity governance, and Zero Trust identity controls;
  • Owns source-of-authority, attributes governance, lifecycle architecture, and authorization model decisions across workforce, student, research, affiliate, alumni, contractor, and external collaborator identity populations;
  • Establishes reusable application onboarding, federation, Single Sign-On (SSO), claims, group, role, entitlement, provisioning, and audit-evidence standards for enterprise applications and distributed campus systems;
  • Partners with cybersecurity, infrastructure, enterprise applications, human resources, student systems, research administration, distributed IT, governance bodies, and application owners to review designs, resolve identity architecture decisions, and approve exceptions;
  • Provides architectural consultation for complex IAM incidents, audit findings, modernization initiatives, platform selections, migration planning, and identity-related risk decisions; and
  • Contributes to special initiatives, cross-functional projects, and emerging priorities as the IAM program evolves, including availability outside standard business hours when operational or project demands require.
Required Qualifications:
  • Bachelor’s degree in related field or the equivalent combination of education and experience;
  • Significant experience designing, implementing, or governing enterprise identity and access management capabilities, including Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, lifecycle management, authorization models, identity governance, Conditional Access, Multi-Factor Authentication (MFA), and enterprise application onboarding;
  • Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, Conditional Access, MFA, passwordless authentication, lifecycle management, identity governance, and Zero Trust identity control patterns;
  • Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns;
  • Skill in developing enterprise architecture, standards, decision records, roadmaps, source-of-authority models, authorization models, and reusable application onboarding patterns;
  • Ability to translate complex identity architecture into clear business, technical, risk, and governance recommendations;
  • Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, distributed IT, and application-owner communities;
  • Ability to provide technical leadership and troubleshooting guidance for legacy Linux-hosted IAM services within a multi-year modernization program;
  • Must maintain confidentiality of sensitive identity, access, employee, student, and institutional data. May be required to participate in urgent response activities for significant identity platform incidents or security events;
  • Must be eligible to work in secure computing environments including International Traffic in Arms Regulations (ITAR) and Controlled Unclassified Information (CUI); and
  • Must be a citizen of the United States, or a person who is a lawful permanent resident of the United States (a “Green Card” holder), or a person who formally has been granted asylum by the United States (a “protected individual” as defined by US law), or a person whose permanent address is in the United States and who is not a national (including dual-national) of any country which is subject to a US arms embargo.
Preferred Qualifications:
  • Master’s degree in related field;
  • Relevant Microsoft identity, cybersecurity, cloud, enterprise architecture, or identity governance certifications preferred;
  • Red Hat system administration or engineering certifications (e.g., RHCSA, RHCE) are a plus;
  • Extensive experience in higher education, research-intensive, decentralized, or similarly complex identity environments;
  • Preferred experience includes InCommon/eduGAIN/Shibboleth federation, Microsoft-centric IAM modernization, access governance, PAM/IGA integration, Zero Trust identity policy design, Python or PowerShell automation, Linux-hosted identity services, and cross-functional architecture governance;
  • Hands-on experience migrating off legacy Linux-hosted IAM platforms to a modern IAM solution is highly valued;
  • Knowledge of higher-education IAM complexity, including student, faculty, staff, researcher, affiliate, alumni, contractor, and external collaborator populations;
  • Knowledge of InCommon, eduGAIN, Shibboleth, research federation, distributed campus governance, access governance, RBAC, ABAC, delegated administration, and entitlement catalog design;
  • Knowledge of Red Hat Enterprise Linux administration, Java programming, Apache Foundation integration technologies, Oracle Directory Services and Kerberos service operations;
  • Skill with Python, PowerShell, APIs, automation design, data analysis, and identity policy modeling;
  • Demonstrated ability to plan and execute incremental migration to modern cloud or SaaS-based alternatives;
  • Ability to reason about Linux-hosted identity components, certificates, reverse proxies, LDAP services, and Java-based enterprise application integration patterns; and
  • Ability to assess legacy IAM platform risk, sustain service continuity, and guide incremental migration toward modern SaaS and cloud-native identity solutions.

Posting Open Date: October 2, 2026

For Full Consideration, Apply by: October 16, 2026

Open Until Filled: Yes

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

Cooperative Education • Fairfax (VA)

On-site
USD 110,000 - 150,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

George Mason University • Fairfax (VA)

On-site
USD 120,000 - 160,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

George Mason University • Chantilly (VA)

On-site
USD 120,000 - 160,000
Identity Access Management (IAM) Platform Lead
Identity Access Management (IAM) Platform Lead

Administration & Operations • Fairfax (VA), Virginia (MN)

On-site
USD 140,000 - 190,000
Senior IT Security Analyst
Senior IT Security Analyst

Cybersecurity Jobs • Denver (CO)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) match
Paid time off
+1
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
IAM Platform Lead: Enterprise Identity Architect (On-Site)
IAM Platform Lead: Enterprise Identity Architect (On-Site)

George Mason University • Chantilly (VA)

On-site
USD 120,000 - 160,000
IAM Platform Lead & Enterprise Identity Architect
IAM Platform Lead & Enterprise Identity Architect

Cooperative Education • Fairfax (VA)

On-site
USD 110,000 - 150,000
IAM Platform Lead: Enterprise Identity & Modernization
IAM Platform Lead: Enterprise Identity & Modernization

Administration & Operations • Fairfax (VA), Virginia (MN)

On-site
USD 140,000 - 190,000
Enterprise IAM Platform Lead | Identity Architect (On-Site)
Enterprise IAM Platform Lead | Identity Architect (On-Site)

Commonwealth of VA Careers • Virginia (MN)

On-site
USD 120,000 - 160,000