26 sep
|
InfiCare Staffing
|
México
26 sep
InfiCare Staffing
México
AD Identity Separation Lead
Location: Mexico
Job Type: Contract
Experience: 8+ Years
Role: AD Identity Separation Lead
Job Summary
We are looking for a highly experienced AD Identity Separation Lead to lead the separation of an identity environment from its legacy/parent organization and establish a clean identity landing within the new enterprise environment.
This is a senior IAM leadership role responsible for defining the identity separation strategy, architecture, sequencing, governance, coexistence, cutover, and TSA exit. The candidate will work closely with Identity, Network, M365, Security, Application, and business teams to drive the separation program from strategy through execution.
Key Responsibilities
- Lead the end-to-end identity separation strategy for an M&A;/carve-out environment.
- Design and manage Active Directory forest/domain trust architecture , including trust creation, coexistence, and eventual trust teardown.
- Develop the identity separation roadmap, migration approach, sequencing, dependencies, and governance model.
- Define and execute Microsoft Entra ID tenant strategy , including Conditional Access, application registrations, federation, and SSO re-pointing.
- Identify and document application dependencies on Active Directory and Entra ID .
- Develop remediation and migration plans for identity-dependent applications.
- Plan and manage identity coexistence between the legacy/parent environment and the target environment.
- Define cutover, rollback, contingency, and TSA-exit criteria .
- Partner with Network, Microsoft 365, Cybersecurity, Application, and Infrastructure teams to resolve technical dependencies.
- Coordinate with business and technical stakeholders to drive decisions and maintain project timelines.
- Identify and communicate technical risks, dependencies, and mitigation plans to senior leadership.
- Provide technical leadership throughout migration,
cutover, stabilization, and TSA exit.
- Ensure appropriate documentation of architecture, migration plans, dependencies, risks, and operational procedures.
Required Skills & Experience
- 10+ years of Identity & Access Management (IAM) experience .
- Proven experience leading at least one complete identity separation, M&A; carve-out, or TSA-exit project .
- Strong experience with Active Directory architecture and administration .
- Hands-on experience with AD forest/domain trusts, trust design, coexistence, and trust teardown .
- Strong expertise in Microsoft Entra ID (Azure AD) .
- Experience with Entra ID tenant strategy and identity migration/separation.
- Strong knowledge of Conditional Access, application registrations, federation, Enterprise Applications, and SSO .
- Experience discovering and managing application identity dependencies .
- Strong understanding of identity migration, authentication, authorization, and directory services.
- Experience developing cutover, rollback, contingency, and TSA-exit plans .
- Proven ability to lead cross-functional technical workstreams.
- Strong stakeholder management and communication skills.
- Ability to present technical risks, dependencies, and recommendations to senior leadership.
Nice to Have
- Experience with CyberArk or Delinea .
- Experience with SailPoint or Saviynt .
- Healthcare industry experience and knowledge of HIPAA requirements.
- Previous consulting or partner-side delivery leadership experience.
- Experience with large-scale enterprise M&A; integration/separation programs .
Ideal Candidate The idóneo candidate is a senior IAM / Identity Architect / Identity Separation Lead who has successfully led identity separation during an M&A; or carve-out. The candidate should be equally comfortable with AD forest/trust architecture, Entra ID, application dependencies, migration planning, and executive-level stakeholder management .
📌 Identity & Access Management Lead (México)
🏢 InfiCare Staffing
📍 México