Experience with enterprise identity and access management (IAM) architecture and user-provisioning design (8+ years); • Experience with assessing legacy IAM environments, designing modern target-state architectures, and producing phased modernization roadmaps, including identity-flow diagrams, source-of-authority matrices, and attribute mappings; • Experience with end-to-end identity lifecycle management, including joiner, mover, leaver, rehire, and deprovisioning processes, and complex identity scenarios such as employee/student dual affiliations and duplicate identities; • Experience integrating HRIS/SIS/ERP platforms (e.g., Workday, Banner) with identity management systems and establishing authoritative identity sources; • Experience with Microsoft Entra ID, Active Directory, Entra Connect, Cloud Sync, and cross-tenant synchronization; • Experience with automated provisioning using SCIM, APIs, Microsoft Graph, PowerShell, SQL, file-based integrations, and middleware; • Experience implementing provisioning safeguards and monitoring, including reconciliation, validation, approval gates, error handling, rollback, alerting for failed provisioning or stale accounts, and hands-on troubleshooting of provisioning failures; • Experience defining access-assignment models using roles, groups, attributes, and access packages based on least-privilege principles; • Experience with identity governance, including access reviews, privileged access, and service-account governance; • Expertise with SAML, OIDC/OAuth, SCIM, LDAP, and Kerberos; Responsibilities include but are not limited to the following: • Assess the current identity and access management environment and design a modern, scalable target-state IAM architecture; • Design secure identity lifecycle processes across Workday, Banner, Active Directory, Microsoft Entra ID, OneLogin, and downstream applications; • Establish authoritative identity sources and ownership rules for critical identity attributes; • Automate joiner, mover, leaver, rehire, and deprovisioning processes, including support for complex identity scenarios such as employee/student dual affiliations; • Implement monitoring, reconciliation, error handling, and deprovisioning safeguards to ensure identity data integrity; • Develop a prioritized, phased modernization roadmap that can be implemented without disrupting production; • Guide implementation of IAM initiatives in alignment with modern security, governance, and least-privilege practices;