AD Identity Separation Lead – Contract
? Location: Remote – Canada
? Engagement: Contract
About the Role
We are seeking a senior AD Identity Separation Lead to lead an enterprise identity separation program involving the transition of an Active Directory and Microsoft Entra ID environment from a legacy/parent organization into a new client environment.
This is a strategy, sequencing, governance, and workstream leadership role rather than a hands-on migration position. The successful candidate will own the overall identity separation approach, coordinate cross-functional teams, manage dependencies and risks, and drive the program through TSA exit .
Key Responsibilities
- Lead the overall Identity & Access Management separation strategy and execution roadmap.
- Define sequencing and governance for identity separation activities.
- Lead Active Directory forest trust design, coexistence planning, and trust teardown .
- Develop and execute Microsoft Entra ID tenant and identity separation strategies .
- Oversee Conditional Access, application registrations, federation, and SSO re-pointing activities.
- Coordinate application dependency discovery and identity-bound application remediation.
- Partner with Network, Microsoft 365, Security, and Application teams to manage cross-functional dependencies.
- Drive decisions and alignment across multiple stakeholder groups.
- Define cutover strategies, contingency plans, rollback plans, and TSA-exit criteria .
- Track risks, dependencies, issues, and mitigation plans through program completion.
- Present technical risks, recommendations, and key decisions to senior leadership.
Required Qualifications
- 10+ years of Identity & Access Management (IAM) experience .
- Proven experience completing at least one carve-out, divestiture, or TSA-exit identity separation .
- Strong experience owning an end-to-end identity separation strategy .
- Hands-on knowledge of:
- Active Directory forest trusts
- Trust teardown
- AD coexistence strategies
- Microsoft Entra ID
- Conditional Access
- App registrations
- Federation
- SSO re-pointing
- Experience with application dependency discovery and remediation planning .
- Strong cross-functional leadership across Network, Microsoft 365, Security, and Application teams.
- Experience developing cutover, rollback, contingency, and TSA-exit plans.
- Robust stakeholder management and senior leadership communication skills.
- Ability to operate at both strategic and technical levels within complex enterprise environments.
📌 AD Identity Separation Lead (Canada)
🏢 Acunor
📍 Canada