Ideal Candidate Summary
The ideal candidate is a true IAM Architect with 8+ years of enterprise Identity & Access Management experience who specializes in identity provisioning and lifecycle automation.
They have designed enterprise IAM environments from the ground up and understand how identities flow from HR systems through Active Directory, Entra ID, and downstream applications.
This person should have experience assessing existing IAM environments, identifying weaknesses, and building practical modernization roadmaps that improve automation, security, and governance without disrupting production.
They should also be highly technical—someone who can review configurations, analyze provisioning failures, troubleshoot synchronization issues, and guide engineers through implementation.
Experience supporting complex identity scenarios (employees, students, dual identities, rehires, role changes, duplicate identities, etc.) is highly desirable.
Job Description
A local university is looking for a Senior Identity & Access Management (IAM) Architect to modernize their enterprise identity provisioning environment.
This person will evaluate the current IAM landscape, design a future-state architecture, and lead improvements across identity lifecycle management, provisioning automation, and access governance.
The ideal candidate is equally comfortable creating architecture roadmaps for leadership and diving into technical configurations to troubleshoot provisioning issues and guide implementation.
This is a highly technical IAM architecture role focused on identity provisioning—not just authentication or access management.
Required Technical Skills
- Identity & Access Management
- Enterprise IAM Architecture
- Identity Lifecycle Management (Joiner / Mover / Leaver)
- User Provisioning
- Identity Governance
- Access Reviews
- Least Privilege Design
- Microsoft Identity
- Microsoft Entra ID (Azure AD)
- Active Directory
- Entra Connect
- Cloud Sync
- Cross-Tenant Synchronization
- Identity Integrations
- Workday
- Banner ERP / SIS
- SCIM
- Microsoft Graph API
- REST APIs
- PowerShell
- SQL
- LDAP
- SAML
- OAuth / OpenID Connect
- Kerberos
- Automation
- Identity automation
- Provisioning workflows
- Attribute mapping
- Role-based access
- Group-based provisioning
- Error handling
- Reconciliation
- Monitoring & Alerting
What This Person Will Be Doing
- Assess the current IAM and user provisioning environment
- Design the future-state IAM architecture and modernization roadmap
- Improve and automate Joiner / Mover / Leaver (JML) processes
- Establish authoritative identity sources across HR, Student Information Systems, and Active Directory
- Design provisioning workflows between Workday, Banner, Active Directory, Entra ID, OneLogin, and downstream applications
- Troubleshoot provisioning failures and synchronization issues
- Improve identity governance, monitoring, reconciliation, and deprovisioning safeguards
- Create architecture diagrams, identity flows, attribute mappings, and standards
- Guide implementation while mentoring internal technical teams