Owns source-of-authority, attributes governance, lifecycle
architecture, and authorization model decisions across workforce,
student, research, affiliate, alumni, contractor, and external
collaborator identity populations;
Establishes reusable application onboarding, federation, Single
Sign-On (SSO), claims, group, role, entitlement, provisioning, and
audit-evidence standards for enterprise applications and
distributed campus systems;
Partners with cybersecurity, infrastructure, enterprise
applications, human resources, student systems, research
administration, distributed IT, governance bodies, and application
owners to review designs, resolve identity architecture decisions,
and approve exceptions;
Provides architectural consultation for complex IAM incidents,
audit findings, modernization initiatives, platform selections,
migration planning, and identity-related risk decisions; and
Contributes to special initiatives, cross-functional projects,
and emerging priorities as the IAM program evolves, including
availability outside standard business hours when operational or
project demands require.
Required Qualifications:
- Bachelor’s degree in related field or the equivalent
combination of education and experience;
- Significant experience designing, implementing, or governing
enterprise identity and access management capabilities, including
Microsoft Entra ID, Active Directory, hybrid identity, federation,
SSO, lifecycle management, authorization models, identity
governance, Conditional Access, Multi-Factor Authentication (MFA),
and enterprise application onboarding;
- Knowledge of Microsoft Entra ID, Active Directory, hybrid
identity, federation, SSO, Conditional Access, MFA, passwordless
authentication, lifecycle management, identity governance, and Zero
Trust identity control patterns;
- Knowledge of SAML, OAuth, OpenID Connect, LDAP, and legacy
identity integration patterns;
- Skill in developing enterprise architecture, standards,
decision records, roadmaps, source-of-authority models,
authorization models, and reusable application onboarding
patterns;
- Ability to translate complex identity architecture into clear
business, technical, risk, and governance recommendations;
- Ability to collaborate across cybersecurity, infrastructure,
enterprise applications, HR, student systems, research
administration, distributed IT, and application-owner
communities;
- Ability to provide technical leadership and troubleshooting
guidance for legacy Linux-hosted IAM services within a multi-year
modernization program;
- Must maintain confidentiality of sensitive identity, access,
employee, student, and institutional data. May be required to
participate in urgent response activities for significant identity
platform incidents or security events;
- Must be eligible to work in secure computing environments
including International Traffic in Arms Regulations (ITAR) and
Controlled Unclassified Information (CUI); and
- Must be a citizen of the United States, or a person who is a
lawful permanent resident of the United States (a “Green Card”
holder), or a person who formally has been granted asylum by the
United States (a “protected individual” as defined by US law), or a
person whose permanent address is in the United States and who is
not a national (including dual-national) of any country which is
subject to a US arms embargo.
Preferred Qualifications:
- Master’s degree in related field;
- Relevant Microsoft identity, cybersecurity, cloud, enterprise
architecture, or identity governance certifications preferred;
- Red Hat system administration or engineering certifications
(e.g., RHCSA, RHCE) are a plus;
- Extensive experience in higher education, research-intensive,
decentralized, or similarly complex identity environments;
- Preferred experience includes InCommon/eduGAIN/Shibboleth
federation, Microsoft-centric IAM modernization, access governance,
PAM/IGA integration, Zero Trust identity policy design, Python or
PowerShell automation, Linux-hosted identity services, and
cross-functional architecture governance;
- Hands-on experience migrating off legacy Linux-hosted IAM
platforms to a modern IAM solution is highly valued;
- Knowledge of higher-education IAM complexity, including
student, faculty, staff, researcher, affiliate, alumni, contractor,
and external collaborator populations;
- Knowledge of InCommon, eduGAIN, Shibboleth, research
federation, distributed campus governance, access governance, RBAC,
ABAC, delegated administration, and entitlement catalog
design;
- Knowledge of Red Hat Enterprise Linux administration, Java
programming, Apache Foundation integration technologies, Oracle
Directory Services and Kerberos service operations;
- Skill with Python, PowerShell, APIs, automation design, data
analysis, and identity policy modeling;
- Demonstrated ability to plan and execute incremental migration
to modern cloud or SaaS-based alternatives;
- Ability to reason about Linux-hosted identity components,
certificates, reverse proxies, LDAP services, and Java-based
enterprise application integration patterns; and
- Ability to assess legacy IAM platform risk, sustain service
continuity, and guide incremental migration toward modern SaaS and
cloud-native identity solutions.
Instructions to Applicants:
For full consideration, applicants must apply for the
Identity Access Management (IAM) Platform Lead at
https://jobs.gmu.edu/. Complete and submit the
online application to include three professional references with
contact information, and provide a cover letter and resume for
review.
Posting Open Date: October 2, 2026
For Full Consideration, Apply by: October 16, 2026
Open Until Filled: Yes
Mason Ad Statement
George Mason University is a nationally ranked R1 research
university committed to creating a more just, free, and prosperous
world. With 40,000 enrolled students, George Mason is the largest
and most diverse public research university in Virginia, offering
degree programs at the master's, doctoral, and professional level,
along with certificates and credentials.
George Mason fosters an All Together Different environment for
students, faculty, and staff, driven by our core beliefs. We
believe in inclusivity over exclusivity; we believe in advancing
our mission by being willing to take risks, not avoiding them; and
we believe our best work is possible when we apply our diversity of
origin, identity, circumstance, and thought.
Equity Statement
George Mason University is an equal opportunity/affirmative action
employer, committed to promoting inclusion and equity in its
community. All qualified applicants will receive consideration for
employment without regard to race, color, religion, sex, sexual
orientation, gender identity, national origin, age, disability or
veteran status, or any characteristic protected by law.
Campus Safety Information
Mason’s Annual Security and Fire Safety Report is available at
http://police.gmu.edu/annual-security-report/