Job Description
Department: Information Technology
Classification: Info Technology Spec 3
Job Category: Classified Staff
Job Type: Full-Time
Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)
Location: Fairfax, VA
Workplace Type: On Site Required
Sponsorship Eligibility: Not eligible for visa sponsorship
Pay Band: 06
Salary: Salary commensurate with education and experience
Criminal Background Check: Yes
About the Department:
Information Technology Services (ITS) provides technology and collaborative solutions that contribute to and facilitate innovative teaching and learning opportunities for students and faculty of the George Mason University community. ITS works transparently to drive excellence in teaching, research, and administrative operations.
About the Position:
The IAM Platform Lead serves as the enterprise IAM design authority for the university’s identity target state. The position defines identity architecture, standards, source-of-authority decisions, lifecycle models, federation strategy, authorization patterns, application onboarding standards, and Zero Trust-aligned policy guardrails for Microsoft Entra ID, Active Directory, Shibboleth/InCommon/eduGAIN, and related identity services.
The position also holds technical stewardship over legacy Linux-hosted IAM core services, providing subject-matter expertise in legacy technologies and leading troubleshooting efforts across the team. This role guides and sustains these services through a multi-year modernization program, ensuring continuity of critical identity functions throughout each transition phase.
Responsibilities:
- Defines and maintains the enterprise IAM reference architecture, target-state roadmap, design principles, standards, and decision framework for Microsoft Entra ID, Active Directory, hybrid identity, federation, identity governance, and Zero Trust identity controls;
- Owns source-of-authority, attributes governance, lifecycle architecture, and authorization model decisions across workforce, student, research, affiliate, alumni, contractor, and external collaborator identity populations;
- Establishes reusable application onboarding, federation, Single Sign-On (SSO), claims, group, role, entitlement, provisioning, and audit-evidence standards for enterprise applications and distributed campus systems;
- Partners with cybersecurity, infrastructure, enterprise applications, human resources, student systems, research administration, distributed IT, governance bodies, and application owners to review designs, resolve identity architecture decisions, and approve exceptions;
- Provides architectural consultation for complex IAM incidents, audit findings, modernization initiatives, platform selections, migration planning, and identity-related risk decisions; and
- Contributes to special initiatives, cross-functional projects, and emerging priorities as the IAM program evolves, including availability outside standard business hours when operational or project demands require.
Required Qualifications:
- Bachelor’s degree in related field or the equivalent combination of education and experience;
- Significant experience designing, implementing, or governing enterprise identity and access management capabilities, including Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, lifecycle management, authorization models, identity governance, Conditional Access, Multi-Factor Authentication (MFA), and enterprise application onboarding;
- Knowledge of Microsoft Entra ID, Active Directory, hybrid identity, federation, SSO, Conditional Access, MFA, passwordless authentication, lifecycle management, identity governance, and Zero Trust identity control patterns;
- Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy identity integration patterns;
- Skill in developing enterprise architecture, standards, decision records, roadmaps, source-of-authority models, authorization models, and reusable application onboarding patterns;
- Ability to translate complex identity architecture into clear business, technical, risk, and governance recommendations;
- Ability to collaborate across cybersecurity, infrastructure, enterprise applications, HR, student systems, research administration, distributed IT, and application-owner communities;
- Ability to provide technical leadership and troubleshooting guidance for legacy Linux-hosted IAM services within a multi-year modernization program;
- Must maintain confidentiality of sensitive identity, access, employee, student, and institutional data. May be required to participate in urgent response activities for significant identity platform incidents or security events;
- Must be eligible to work in secure computing environments including International Traffic in Arms Regulations (ITAR) and Controlled Unclassified Information (CUI); and
- Must be a citizen of the United States, or a person who is a lawful permanent resident of the United States (a “Green Card” holder), or a person who formally has been granted asylum by the United States (a “protected individual” as defined by US law), or a person whose permanent address is in the United States and who is not a national (including dual-national) of any country which is subject to a US arms embargo.
Preferred Qualifications:
- Master’s degree in related field;
- Relevant Microsoft identity, cybersecurity, cloud, enterprise architecture, or identity governance certifications preferred;
- Red Hat system administration or engineering certifications (e.g., RHCSA, RHCE) are a plus;
- Extensive experience in higher education, research-intensive, decentralized, or similarly complex identity environments;
- Preferred experience includes InCommon/eduGAIN/Shibboleth federation, Microsoft-centric IAM modernization, access governance, PAM/IGA integration, Zero Trust identity policy design, Python or PowerShell automation, Linux-hosted identity services, and cross-functional architecture governance;
- Hands-on experience migrating off legacy Linux-hosted IAM platforms to a modern IAM solution is highly valued;
- Knowledge of higher-education IAM complexity, including student, faculty, staff, researcher, affiliate, alumni, contractor, and external collaborator populations;
- Knowledge of InCommon, eduGAIN, Shibboleth, research federation, distributed campus governance, access governance, RBAC, ABAC, delegated administration, and entitlement catalog design;
- Knowledge of Red Hat Enterprise Linux administration, Java programming, Apache Foundation integration technologies, Oracle Directory Services and Kerberos service operations;
- Skill with Python, PowerShell, APIs, automation design, data analysis, and identity policy modeling;
- Demonstrated ability to plan and execute incremental migration to modern cloud or SaaS-based alternatives;
- Ability to reason about Linux-hosted identity components, certificates, reverse proxies, LDAP services, and Java-based enterprise application integration patterns; and
- Ability to assess legacy IAM platform risk, sustain service continuity, and guide incremental migration toward modern SaaS and cloud-native identity solutions.
Instructions to Applicants:
For full consideration, applicants must apply for the Identity Access Management (IAM) Platform Lead at https://jobs.gmu.edu/. Complete and submit the online application to include three professional references with contact information, and provide a cover letter and resume for review.
Posting Open Date: October 2, 2026
For Full Consideration, Apply by: October 16, 2026
Open Until Filled: Yes