Senior Identity and Access Management Architect
Indexed description
Requirements
- 8+ years of enterprise IAM experience, with significant responsibility for identity architecture and user-provisioning design
- Proven ability to assess an existing provisioning environment and design a modern, scalable target-state architecture
- Expert knowledge of end-to-end user provisioning across HR/SIS systems, identity platforms, directories, and downstream applications
- Experience designing joiner, mover, leaver, rehire, return, and deprovisioning processes
- Experience handling complex identity scenarios, including employee/student dual affiliations, duplicate identities, role changes, and multiple source records
- Experience establishing authoritative identity sources and ownership rules for critical identity attributes
- Strong experience integrating Workday, Banner, or comparable HRIS, SIS, and ERP platforms with IAM systems
- Expert knowledge of Microsoft Entra ID, Active Directory, Entra Connect, Cloud Sync, and cross-tenant synchronization
- Experience designing automated provisioning using SCIM, APIs, Microsoft Graph, PowerShell, SQL, file-based integrations, and middleware
- Experience implementing provisioning safeguards, including reconciliation, validation, approval gates, retry processing, error handling, rollback, and mass-deletion protection
- Ability to design monitoring and alerting for failed provisioning, synchronization issues, duplicate identifiers, stale accounts, and incomplete lifecycle events
- Experience defining modern access-assignment models using roles, groups, attributes, access packages, and least-privilege principles
- Strong understanding of authentication, provisioning, authorization, and identity governance as separate but connected functions
- Expertise with SAML, OIDC/OAuth, SCIM, LDAP, and Kerberos
- Experience modernizing legacy IAM platforms, custom scripts, databases, manual workflows, and duplicated provisioning logic
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search