Haystack
← Back to Jobs
Other

IT/OT Identity Separation Lead (Only Visa Independent Candidate/W2)

SumasEdge CorporationUnited States🇺🇸United StatesPosted 30 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Title:- IT/OT Identity Separation Lead
Location:- Remote
Duration:- Contract
 

Job Overview:
We are seeking a highly experienced IT/OT Identity Separation Lead with proven, hands-on experience delivering large-scale identity separation and carve-out initiatives across complex enterprise environments. The ideal candidate has successfully led both greenfield and brownfield IT/OT identity separation projects, integrating cybersecurity, identity governance, and operational technology while minimizing business disruption.

 

Responsibilities:

  • Lead enterprise-scale IT/OT identity separation programs supporting mergers, acquisitions, divestitures, and organizational transformations.
  • Design and implement identity architectures for both greenfield and brownfield environments.
  • Assess current-state identity ecosystems and develop future-state architectures supporting independent IT and OT operations.
  • Lead identity separation initiatives involving:
    • Microsoft Active Directory
    • Microsoft Entra ID (Azure AD)
    • OT Active Directory Domains
    • Privileged Access Management (CyberArk, BeyondTrust, Delinea)
    • Identity Governance & Administration (SailPoint, Saviynt, etc.)
    • Multi-Factor Authentication (MFA)
    • PKI & Certificate Services
    • Service Accounts & Non-Human Identities
  • Coordinate identity migrations across enterprise applications, manufacturing systems, ICS, SCADA, MES, PLC, and OT environments.
  • Develop migration waves, cutover plans, rollback strategies, and risk mitigation plans.
  • Work closely with cybersecurity, infrastructure, networking, manufacturing engineering, application owners, and business stakeholders.
  • Identify dependencies across identity services, networking, DNS, PKI, ERP, MES, SCADA, historians, and manufacturing applications.
  • Ensure alignment with NIST CSF, IEC 62443, ISA/IEC standards, and Zero Trust principles.
  • Provide hands-on technical leadership throughout architecture, implementation, troubleshooting, and delivery.

 

Required Skills:

  • 10+ years of enterprise Identity & Access Management (IAM) experience.
  • Proven success leading large-scale IT/OT identity separation or enterprise carve-out initiatives.
  • Hands-on experience delivering both greenfield identity implementations and brownfield modernization/separation projects.
  • Strong expertise with:
    • Microsoft Active Directory
    • Microsoft Entra ID (Azure AD)
    • Identity Governance (SailPoint, Saviynt, etc.)
    • Privileged Access Management (CyberArk, BeyondTrust, Delinea)
    • MFA & Conditional Access
    • DNS, DHCP, PKI, Group Policy, Kerberos, LDAP
  • Deep understanding of Operational Technology (OT), including:
    • Industrial Control Systems (ICS)
    • SCADA
    • Manufacturing Execution Systems (MES)
    • PLC environments
  • Experience supporting mergers, acquisitions, divestitures, or enterprise carve-outs.
  • Strong understanding of identity migration strategies, directory synchronization, coexistence models, and trust relationships.
  • Excellent communication and stakeholder management skills

 

Preferred Qualifications:

  • Experience within pharmaceutical, manufacturing, energy, utilities, or other critical infrastructure environments.
  • Knowledge of Zero Trust architecture and OT cybersecurity.
  • Experience with hybrid and cloud identity modernization.
  • Certifications such as CISSP, GIAC, Microsoft Identity, CyberArk, SailPoint, or IEC 62443 are highly preferred.

Skills

MFA
Active Directory
Azure
ERP
DNS
SCADA
LDAP
PKI
Stakeholder Management
Zero Trust

Similar jobs