Haystack
← Back to Jobs
Technology
AI

Active Directory Identity Seperation Lead

Acunor InfotechUnited States🇺🇸United StatesPosted Oct 2, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
4 days ago
SSOActive DirectoryAzureHIPAA

Job Description

AD Identity Separation Lead

Location: Remote Canada
Engagement: Contract

Position Overview

We are seeking an experienced Active Directory (AD) Identity Separation Lead to lead the separation of an enterprise identity environment from its legacy/parent organization and ensure a clean transition into the target environment.

This is a senior-level strategy, architecture, sequencing, and governance role overseeing the identity separation program above the hands-on migration activities. The consultant will own the overall identity separation approach, coordinate cross-functional workstreams, manage dependencies and risks, and drive the program through successful TSA exit.

Key Responsibilities
  • Own the end-to-end identity separation strategy for a complex enterprise carve-out/divestiture.
  • Define the approach and sequencing for Active Directory forest trusts, coexistence, and trust teardown.
  • Develop the Microsoft Entra ID tenant and identity transition strategy.
  • Lead application dependency discovery and remediation planning for identity-bound applications.
  • Coordinate identity-related activities across Network, Microsoft 365, Security, and Application teams.
  • Drive technical and program decisions across multiple stakeholder groups.
  • Define and document cutover plans, contingency/rollback procedures, dependencies, risks, and mitigation strategies.
  • Establish clear TSA-exit criteria and ensure identity-related dependencies are addressed before separation.
  • Present technical risks, architecture decisions, dependencies, and recommendations to senior leadership.
  • Provide governance and leadership across identity migration workstreams while hands-on teams execute migration activities.
Required Qualifications
  • 10+ years of Identity & Access Management (IAM) experience.
  • Experience completing at least one full carve-out, divestiture, or TSA-exit identity separation.
  • Proven ownership of an end-to-end identity separation strategy.
  • Strong Microsoft Active Directory expertise, including:
    • Forest trust design
    • Trust teardown
    • Domain/forest coexistence planning
  • Strong Microsoft Entra ID (Azure AD) expertise, including:
    • Tenant strategy
    • Conditional Access
    • App registrations
    • Federation
    • SSO re-pointing
  • Experience with application dependency discovery and remediation planning for identity-bound applications.
  • Experience coordinating across Network, Microsoft 365, Security, and Application teams.
  • Strong workstream/program leadership with the ability to drive decisions across business and technology stakeholders.
  • Experience developing:
    • Cutover strategies and plans
    • Contingency and rollback plans
    • TSA-exit criteria
    • Risk, dependency, and mitigation plans
  • Strong communication skills with experience presenting technical risks and recommendations to senior leadership.
Nice to Have
  • Privileged Access Management experience with CyberArk or Delinea.
  • Identity Governance experience with SailPoint or Saviynt.
  • Healthcare regulatory experience, including HIPAA.
  • Previous partner-side or consulting delivery leadership experience.

Similar jobs