AD Identity Separation Lead (x1)
Leads the separation of RCA identity from its legacy/parent environment and its clean landing in Cencora - the strategy, sequencing, and governance role above the hands-on migration work. This is the senior of the three and should be filled first.
Must have:
·10+ years identity and access management, including at least one full carve-out or TSA-exit identity separation
·Owned identity separation strategy end-to-end: forest trust design, trust teardown, and coexistence period planning
·Strong Entra ID: tenant strategy, conditional access, app registrations, federation and SSO re-pointing
·Application dependency discovery and remediation planning for identity-bound applications
·Coordination across network, M365, security, and application teams; able to run workstreams and drive decisions with Cencora and RCA stakeholders
·Documented cutover, contingency, and TSA-exit criteria; comfortable presenting risk to senior leadership
Nice to have: Privileged access (CyberArk, Delinea), identity governance (SailPoint, Saviynt), healthcare regulatory context (HIPAA), prior partner-side delivery lead experience.