What are the responsibilities and job description for the IAM Architect | Onsite | W2 Profile position at Trebecon LLC?
Title: Senior Identity and Access Management Architect
Location: Fort Lauderdale, FL - Onsite
- 8 years of enterprise IAM experience, with significant responsibility for identity architecture and user-provisioning design.
- Proven ability to assess an existing provisioning environment and design a modern, scalable target-state architecture.
- Expert knowledge of end-to-end user provisioning across HR/SIS systems, identity platforms, directories, and downstream applications.
- Experience designing joiner, mover, leaver, rehire, return, and deprovisioning processes.
- Experience handling complex identity scenarios, including employee/student dual affiliations, duplicate identities, role changes, and multiple source records.
- Experience establishing authoritative identity sources and ownership rules for critical identity attributes.
- Strong experience integrating Workday, Banner, or comparable HRIS, SIS, and ERP platforms with IAM systems.
- Expert knowledge of Microsoft Entra ID, Active Directory, Entra Connect, Cloud Sync, and cross-tenant synchronization.
- Experience designing automated provisioning using SCIM, APIs, Microsoft Graph, PowerShell, SQL, file-based integrations, and middleware.
- Experience implementing provisioning safeguards, including reconciliation, validation, approval gates, retry processing, error handling, rollback, and mass-deletion protection.
- Ability to design monitoring and alerting for failed provisioning, synchronization issues, duplicate identifiers, stale accounts, and incomplete lifecycle events.
- Experience defining modern access-assignment models using roles, groups, attributes, access packages, and least-privilege principles.
- Strong understanding of authentication, provisioning, authorization, and identity governance as separate but connected functions.
- Expertise with SAML, OIDC/OAuth, SCIM, LDAP, and Kerberos.
- Experience modernizing legacy IAM platforms, custom scripts, databases, manual workflows, and duplicated provisioning logic.
- Ability to define the appropriate long-term roles of on-premises AD, Entra ID, multiple tenants, and legacy identity platforms.
- Experience designing identity governance, access reviews, privileged access, service-account governance, and timely access removal.
- Ability to create current-state and target-state architecture, identity-flow diagrams, source-of-authority matrices, attribute mappings, and lifecycle standards.
- Ability to produce a prioritized, phased modernization roadmap that can be realistically implemented without disrupting production.
- Hands-on technical ability to review configurations and code, analyze identity data, troubleshoot provisioning failures, lead proofs of concept, and guide implementation.
- Strong communication and knowledge-transfer skills for working with technical teams, business owners, leadership, and vendors.