Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Consultant - Identity & Access Management

Duke Clinical Research Institute

At Duke Health, we're driven by a commitment to compassionate care that changes the lives of patients, their loved ones, and the greater community. No matter where your talents lie, join us and discover how we can advance health together.

About Duke Health Technology Solutions

Pursue your passion for caring and innovation with Duke Heath Technology Solutions, which is dedicated to the transformation, development, and management of enterprise information technology solutions across Duke Health.By harnessing the power of innovative technologies like cloud computing and artificial intelligence - and pairing them with a forward-thinking approach - Duke Health Technology Solutions is revolutionizing the future of health care at Duke Health and beyond.

IT Consultant

Strategic Activities:

  • IAM Strategy & Roadmap: Support a long-term IAM strategy, aligning identity/access management initiatives with business goals and security best practices. Define the IAM architecture (covering identity lifecycle, authentication/authorization models, and governance policies) and collaborate to create a roadmap for implementing new IAM technologies and processes.
  • Governance & Compliance: Participate in establishing and enforcing IAM policies and standards (e.g., access control policies, password/MFA requirements, role-based access models) to ensure compliance with relevant regulations and internal security requirements. Advise senior leadership on IAM risk and governance matters, integrating IAM considerations into broader IT and security strategies (e.g., Zero Trust, least privilege).
  • Cross-Functional Collaboration: Work closely with IT, security, and business units to incorporate IAM into projects and operations. Coordinate identity integration during organizational changes (such as mergers or restructuring of departments), including merging directory or domain infrastructures when necessary. Serve as an IAM subject matter expert in committees and planning groups, ensuring alignment across the organization.

Tactical Activities:

  • Implementation of IAM Solutions: Collaborate with stakeholders on the configuration of IAM technologies. This includes setting up and managing Single Sign-On (SSO) and Multi-Factor Authentication (MFA) solutions, configuring identity federation with external/internal systems, and implementing privileged access management tools. Customize IAM platforms or scripts to automate provisioning, deprovisioning, and access reviews.
  • User Lifecycle & Access Management: Represent Duke Health in end-to-end user identity lifecycle processes. Ensure timely provisioning of accounts and access for new hires, role changes, and terminations in all relevant systems. Maintain role-based access control (RBAC) frameworks and group management, verifying that users have appropriate access privileges. Regularly perform access recertification and audits, and remediate any discrepancies in permissions.
  • Security Monitoring & Issue Resolution: Represent Duke Health in defining the strategy for monitoring IAM systems (logs, alerts, etc.) for unusual access patterns or security events, and respond to identity-related security incidents (such as account compromises or unauthorized access). Troubleshoot and resolve IAM-related technical issues, including login/authentication failures, authorization errors, and directory synchronization problems. Provide support and guidance to IT support teams for complex access requests or issues, and create documentation/KB articles for common procedures.
  • Continuous Improvement & Integration: Stay up-to-date with evolving IAM best practices and emerging technologies. Recommend and implement improvements to enhance security, user experience, and efficiency (for example, introducing passwordless authentication options or improving self-service access request workflows). Work on integrating new applications and services into the existing IAM framework, ensuring any new technology (cloud service, enterprise app, etc.) uses centralized identity and access management for consistency and security.
Education/Training:
  • Bachelor's Degree: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field or equivalent work experience.
Required Experience:
  • Identity & Access Management: 5+ years of experience in IT with significant focus on Identity and Access Management. This should include hands-on responsibility for implementing or managing IAM solutions (such as directories, SSO/MFA, identity governance, or privileged access management) in a complex enterprise environment.
  • Azure AD/Entra & Active Directory Expertise: Strong experience with Microsoft Active Directory (on-premises) and Azure Active Directory/Microsoft Entra ID in a hybrid environment is required . Candidate should have been involved in projects synchronizing AD with Azure AD and ideally have led or contributed to migrating on-prem AD infrastructure to Azure cloud services. Familiarity with tools like Azure AD Connect or Entra Cloud Sync, and resolving issues in hybrid identity setups, is expected.
  • Technology Implementation Track Record: Demonstrated ability to design and implement IAM technologies and processes. Examples include deploying an enterprise SSO solution, rolling out MFA to a large user base, implementing an identity governance platform, or establishing a privileged account management process. The candidate should be able to point to specific IAM projects or improvements they were responsible for and the outcomes achieved.
  • Project Leadership: Experience leading or significantly contributing to the execution of IT security or IAM projects. This includes coordinating across different teams or departments, managing timelines and deliverables, and possibly working with vendors or external consultants. The role requires the ability to take ownership of IAM initiatives and drive them to completion, so project management skills in an IAM context are important.
  • Security & Compliance Experience: Background in environments with rigorous security or compliance requirements. The candidate should understand how IAM supports compliance standards (such as SOX user access controls, HIPAA for healthcare data security, or GDPR for personal data protection) and have experience passing security audits or assessments related to access management. Experience implementing controls to meet regulatory or policy requirements (for instance, enforcing MFA, performing quarterly access reviews, or implementing least-privilege models) is required.
Preferred Experience:
  • Sector Experience (Healthcare/Education): Prior experience in an academic medical center, university, or healthcare environment is strongly preferred . Such experience means the candidate is familiar with the unique IAM challenges of these settings - for example, managing identities across both university and healthcare systems, dealing with research collaborators or medical staff rotations, and ensuring compliance with healthcare regulations.
  • Mergers & Identity Consolidation: Experience with merging or consolidating identity systems (such as during mergers, acquisitions, or organization-wide IT integrations) is a plus. This could involve consolidating multiple Active Directory domains/forests, integrating separate user databases, or migrating users into a single directory service. Experience in this area indicates the ability to navigate complex technical and organizational challenges while unifying identity platforms.
  • Cloud IAM & Digital Transformation: Involvement in large-scale cloud adoption projects, specifically handling the IAM portion of such projects, is preferred. For instance, having guided an organization's shift from on-prem IAM to cloud-based IAM services, or implementing modern authentication and authorization solutions for cloud applications (like adapting legacy apps to use SAML/OAuth with Azure AD). This shows readiness to handle the cloud-centric IAM strategy the role demands.
Required Skills:
  • IAM Domain Knowledge: Deep understanding of identity and access management concepts, protocols, and best practices. Must be well-versed in authentication technologies (LDAP, Kerberos, SAML, OAuth 2.0/OIDC, etc.), authorization models (RBAC, ABAC), and identity lifecycle processes. Ability to design secure and efficient access models (e.g., applying least privilege, implementing role-based access controls) is essential.
  • Microsoft Identity & Cloud Skills: Expert skills in administering Active Directory and Azure Active Directory (Entra) . This includes user and group management, group policy creation, managing AD forests/domains, setting up and troubleshooting Azure AD Connect, and configuring Conditional Access policies. Comfort with PowerShell or similar for automating IAM tasks is expected. Additionally, familiarity with related Microsoft security features (Azure MFA, Identity Protection, Privileged Identity Management) is important.
  • Security Mindset: Strong security and risk management mindset as it relates to IAM. The consultant should be adept at identifying potential vulnerabilities in identity systems (like password policies, service account misuse, inactive accounts) and implementing measures to mitigate them. Must understand concepts like Zero Trust security and how robust IAM controls (MFA, device compliance, just-in-time access) contribute to overall cybersecurity.
  • Analytical Problem-Solving: Excellent problem-solving skills to diagnose and resolve complex identity/access issues. Whether it's a user having inconsistent access across systems or a synchronization conflict between directories, the consultant should systematically troubleshoot and resolve the problem. Attention to detail is key, as IAM issues often involve subtle configuration settings or data inconsistencies.
  • Communication & Documentation: Clear communication skills, both written and verbal. Able to explain IAM concepts and changes to non-technical stakeholders (for instance, explaining the need for MFA to end-users or outlining an IAM roadmap to executives). Should be skilled at writing documentation-such as IAM policies, how-to guides for users, and runbooks for IT teams-and at training technical staff on new IAM tools or processes.
  • Collaboration & Teamwork: A collaborative approach to work with various teams. The IAM consultant will engage a variety of teams across both Duke Health and Duke University. Being able to gather requirements, incorporate feedback, and work together to implement identity solutions is crucial. Strong interpersonal skills will help drive user adoption of IAM initiatives and ensure alignment across different stakeholders.
Preferred Skills:
  • Certifications: Professional certifications related to security and IAM are a plus. These include certifications like CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or Microsoft Certified: Azure Solutions Architect / Identity and Access Administrator . Such certifications demonstrate validated expertise and a commitment to staying current in the field.
  • Additional IAM Tools & Technologies: Experience with a range of IAM and security tools beyond the core Microsoft suite is beneficial. For example, familiarity with identity governance products (e.g., SailPoint), cloud SSO platforms (e.g., Okta), or privileged access management solutions (e.g., CyberArk). Knowledge of multi-cloud IAM (such as AWS IAM) can also be an advantage, indicating versatility across different environments.
  • Industry-Specific IAM Knowledge: Understanding of identity management needs and solutions specific to healthcare or higher education is desirable. For instance, awareness of clinical single sign-on systems or hospital badge access solutions, or knowledge of academic federated identity frameworks and student access systems. Likewise, familiarity with regulations like HIPAA or FERPA and how they impact IAM policies would be valuable.
  • Change Management & User Education: Skill in driving user adoption of new IAM solutions. This includes experience in change management activities like creating user communication plans, training sessions, and support resources when rolling out new authentication methods or IAM tools. An ability to make the transition to new processes smooth for users (minimizing resistance and confusion) is a strong plus.
  • Leadership & Mentoring: The ability to lead and mentor others in the realm of IAM. Whether it's guiding junior IT staff on IAM best practices, or leading an internal IAM workgroup, leadership skills help in championing the IAM program. A candidate who can foster knowledge sharing and elevate the overall IAM competence of the team will be highly regarded.

Duke is an Equal Opportunity Employer committed to providing employment opportunity without regard to an individual's age, color, disability, gender, gender expression, gender identity, genetic information, national origin, race, religion, sex (including pregnancy and pregnancy related conditions), sexual orientation or military status.

Duke aspires to create a community built on collaboration, innovation, creativity, and belonging. Our collective success depends on the robust exchange of ideas-an exchange that is best when the rich diversity of our perspectives, backgrounds, and experiences flourishes. To achieve this exchange, it is essential that all members of the community feel secure and welcome, that the contributions of all individuals are respected, and that all voices are heard. All members of our community have a responsibility to uphold these values.

Essential Physical Job Functions:

Certain jobs at Duke University and Duke University Health System may include essential job functions that require specific physic

Required
Preferred
Job Industries
  • Other
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Consultant - Identity & Access Management in Durham, NC vacancy
  • $161k - $242k

     ...highly skilled cybersecurity engineer with a passion for securing access to critical systems, applications, and data at scale. You bring deep hands-on expertise in identity security, secrets management, and privileged access, with strong skills supporting HashiCorp Vault... 
    Suggested
    Remote work

    Synopsys

    Morrisville, NC
    2 days ago
  •  ...transformation, development, and management of enterprise information...  ...Application Support team to manage user access to Maestro Care OpTime and...  .... DHTS Team Lead, DHTS IT Manager Level 1 Analyst will...  ..., gender expression, gender identity, genetic information, national... 
    Suggested
    Remote work

    Duke Clinical Research Institute

    Durham, NC
    1 day ago
  • $59.83k - $104.55k

     ...Summary The Computerized Maintenance Management System(CMMS) Analyst will provide a wide...  ...inboxes in the CMMS to provide easy-to-access status updates on key information for...  ...disability, gender, gender expression, gender identity, genetic information, national origin,... 
    Suggested
    Work experience placement

    Duke Clinical Research Institute

    Durham, NC
    1 day ago
  •  ...a 72-hour period after submitting the profile when the hiring managers could potentially reach to them. PROFILES WITHOUT THE REQUIRED...  ...DETAILS and TIME SLOTS will be REJECTED. Job title: SAP EWM Consultant Work Location: Durham, NC 27703 Vendor Rate: XXX/Hour... 
    Suggested
    Work at office
    Immediate start
    Remote work
    Relocation

    Spruce Infotech

    Durham, NC
    4 days ago
  • $84.63k - $112.84k

     ...The Role The Senior Technical Project Manager within the GCO Front Door is...  ...age, gender, sexual orientation, gender identity, gender expression, marital status, family...  ..., as well as how individuals may request access to or deletion of their personal data.... 
    Suggested
    Full time
    Contract work
    Temporary work
    Remote work

    Lumen

    Durham, NC
    2 hours ago
  •  ...research pursuits by providing accessible, reliable, efficient,...  ...the University’s foundational IT services remain reliable, secure...  ...organizations; minimum 5 years managing managers and multi-disciplinary...  ..., gender expression, gender identity, genetic information,... 
    Full time
    Live in
    Work at office
    Local area
    Remote work

    University of North Carolina

    Chapel Hill, NC
    2 days ago
  •  ...to the transformation, development, and management of enterprise information technology solutions...  ...care at Duke Health. Reports To: IT Manager Work Performed Level 1 Obtain additional...  ..., gender, gender expression, gender identity, genetic information, national origin,... 
    Work at office
    Night shift

    Direct Jobs

    Durham, NC
    1 day ago
  •  ...Remote Syntax is a leading Managed Cloud Provider for Mission Critical...  ...technical and functional consulting services, and world‑class...  ...availability, replication, archiving, access, and security. Develops new...  ..., religion, gender, gender identity or expression, sexual... 
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Home office
    Flexible hours
    Shift work
    Weekend work

    Syntax

    Morrisville, NC
    1 day ago
  • $107.9k - $172.64k

     ...requisition id: RQ0017858**Job Description**The Configuration Manager supports the delivery of IT services by ensuring the Configuration Management...  ...patterns, data models, CI relationships, service mapping, and access controls.* Integrate patching and vulnerability data (e.... 
    Local area
    Remote work
    Flexible hours

    Blue Cross and Blue Shield of North Carolina

    Durham, NC
    2 days ago
  •  ...that the University’s foundational IT services remain reliable, secure, modern, accessible, and responsive to the needs of...  .... The Senior Associate CIO will manage a division of approximately 230 employees...  ..., gender expression, gender identity, genetic information, national... 

    Koitecc Solutions

    Chapel Hill, NC
    1 day ago
  •  ...to the transformation, development, and management of enterprise information technology...  ...discovery sessions; advanced technical consultation and support; ability to design complex...  ...disability, gender, gender expression, gender identity, genetic information, national origin,... 
    Contract work
    Work at office

    Direct Jobs

    Durham, NC
    2 days ago
  • $140.5k - $391.2k

     ...multiple studies to accelerate patient access* **Cross-Functional Leadership**: Lead integrated...  ..., visibility and proactive risk management across the portfolio* **Client & Partnership...  ..., sex, sexual orientation, gender identity, national origin, disability, status as... 
    Full time
    Part time
    Immediate start
    Worldwide

    IQVIA LLC

    Durham, NC
    1 day ago
  •  ...database development and data enablement for institutional wealth management services. The role focuses on systems analysis, requirements...  ...requirements and support data integration for entitlement and access management on a large platform. Onsite in Durham, NC Responsibilities... 

    Eliassen Group

    Durham, NC
    4 days ago
  •  ...work on a variety of project types, from identity design to ongoing strategy, but the...  ...Role Description The Digital Project Manager will oversee and manage the planning, execution...  ...one. Internal expertise on SEO, accessibility, and more. You should already have... 
    Agency work
    Full time
    Freelance
    Work at office
    Remote work
    Flexible hours

    New Media Campaigns

    Chapel Hill, NC
    1 day ago
  • $135k - $145.5k

     ...currently seeking a Technical Project Manager (TPM) to deliver Corporate Real Estate...  ...relationships with key stakeholders, bringing a consultative approach, and sharing information around...  ...Time Off and Company Holidays ~ Early access to earned wages through Daily Pay... 
    Daily paid
    Work at office
    Local area
    2 days per week
    3 days per week

    Jones Lang LaSalle IP, Inc.

    Durham, NC
    1 day ago
  •  ...related background. Recommendations to management and initiate implementation of new...  ...management reporting using MS Excel, MS Access, and other office software. Collaborate...  ...partnership status, sexual orientation, gender identity, gender expression, personal appearance,... 
    Temporary work
    Casual work
    Internship
    Local area
    Remote work
    Work from home
    Monday to Friday
    Flexible hours

    Personal Genome Diagnostics

    Durham, NC
    3 days ago
  •  ...delivery performance, executive engagement, and proactive risk management. Provide executive-level oversight and governance of...  ...individual's age, color, disability, gender, gender expression, gender identity, genetic information, national origin, race, religion, sex (... 
    Contract work
    Remote work

    Duke Clinical Research Institute

    Durham, NC
    1 day ago
  • $100k

     ...seeking an experienced Technical Project Manager to lead complex technology initiatives supporting...  ...leave, - Holistic Wellness Support - Access resources for physical, emotional, and...  ...infrastructure solutions. Interface with IT Resources, Management Teams, and other... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work
    Shift work

    Maximus

    Durham, NC
    1 day ago
  •  ...development and implementation of North Carolina Families Accessing Services through Technology (NC FAST) case management projects. This Agile Team Lead must be very well...  ...activities. Duties include serving as an IT management liaison to the business client(s), leading... 
    Contract work

    Cardinal Integrated

    Durham, NC
    2 days ago
  •  ...Description Job Summary: The primary duties of a Technical Project Manager III are to oversee the technical aspects of projects and be...  ...status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law. This position... 
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours

    Southern Company

    Durham, NC
    3 days ago
  • $146k - $220k

    IT, Director job at Synopsys. Morrisville, NC. Senior Manager, Infrastructure Engineering 48755BR Locations: USA - California (Mountain View/Sunnyvale), USA -...  ...national origin, gender, sexual orientation, gender identity, age, military veteran status, or disability. #J... 

    Downtown Boulder Partnership

    Morrisville, NC
    1 day ago
  • Reporting to the Manager - Oracle MS Operations, Syntax is currently seeking a Senior Oracle Apps DBA who will work remotely or in office...  ...without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability... 
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    Home office
    Flexible hours
    Shift work
    Weekend work

    Syntax México

    Morrisville, NC
    14 hours ago
  • $153k - $211k

     ...responsible for the optimization and life-cycle management of Sobi's clinical and commercial...  ...treatments, we help make medicine more accessible and open up more possibilities for...  ...HIV Status, sexual orientation, gender identity, protected veterans and/or expression,... 
    Contract work
    Temporary work

    Sobi

    Morrisville, NC
    1 day ago
  •  ...platforms, including: Agent lifecycle management Agent release processes Platform governance...  .... Strong understanding of modern IT service management practices and enterprise...  ...orchestration Networking, storage, and identity/access management Configuration, incident,... 

    Habitat For Humanity Of Durham

    Durham, NC
    1 day ago
  • $79.6k - $306.4k

     ...and compliant execution. Oversee multiple delivery workstreams, managing priorities, resources, and interdependencies to meet client and...  ...to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or... 
    Full time
    Part time
    Immediate start
    Worldwide

    IQVIA Argentina

    Durham, NC
    5 days ago
  •  ...market segments and leveraging AI technologies to advance the value of the company's solutions. The role also involves creating and managing a research agenda that aligns with market needs and serves as a key expert in psychometrics and educational assessment. Applicants... 

    Confidential

    Durham, NC
    4 days ago
  •  ...functional specifications. Liaise between business units and IT teams to ensure alignment and clarity on project objectives....  ...deployment of new systems or enhancements. Support project management activities, including planning, tracking, and reporting on project... 

    Sparktek

    Durham, NC
    4 days ago
  • $68.97k - $127.01k

     ...integrated systems such as Slate, Canvas, Perceptive Content, or identity management systems Other Requirements: Ability to work...  ...and reasonable accommodation(s) can be requested with Duke Access and Accommodations Services (email: ****@*****.***; phone: 91... 
    Work experience placement
    Remote work

    Duke University

    Durham, NC
    4 days ago
  •  ...core. In this hands-on role, you will provide helpdesk support, manage access requests, coordinate system enhancements, and ensure quality...  ...to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are... 
    Work at office
    3 days per week

    Cypress Creek Renewables

    Durham, NC
    2 days ago
  •  ...status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status,...  ...transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants... 
    Work at office
    Local area
    Relocation package

    Vaco

    Durham, NC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Consultant - Identity & Access Management. Be the first to apply!