AD Identity Separation Lead
AD Identity Separation Lead
**Job Title: AD Identity Separation Lead** **Job Description:** Leads the separation of identity from its legacy/parent environment and its clean landing in the new environment — focusing on strategy, sequencing, and governance above the hands-on migration work. This is a senior role and should be filled first. **Must Have:** - 10+ years of experience in identity and access management, including at least one full carve-out or TSA-exit identity separation. - Experience owning identity separation strategy end-to-end: forest trust design, trust teardown, and coexistence period planning. - Strong knowledge of Entra ID: tenant strategy, conditional access, app registrations, federation, and SSO re-pointing. - Experience in application dependency discovery and remediation planning for identity-bound applications. - Ability to coordinate across network, M365, security, and application teams; capable of running workstreams and driving decisions with stakeholders. - Documented cutover, contingency, and TSA-exit criteria; comfortable presenting risk to senior leadership. **Nice to Have:** - Experience with privileged access tools (CyberArk, Delinea). - Knowledge of identity governance (SailPoint, Saviynt). - Familiarity with healthcare regulatory context (HIPAA). - Prior experience as a partner-side delivery lead.