Lead IAM Engineer

Reuters

Toronto

Hybrid

CAD 140,000 - 190,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Vacation & benefits
Headspace access
Retirement savings
Tuition reimbursement
Volunteer days

Job summary

Reuters is seeking a Lead IAM Engineer to design, implement, and support enterprise identity infrastructure across on‑prem and cloud environments. The role emphasizes Active Directory, Entra ID, federation, and MFA.

You will lead design, implement secure identity solutions, and collaborate with security teams on compliance, incident response, and modernization efforts. Hybrid work is offered with strong benefits and career growth opportunities.

Qualifications

  • Bachelor’s degree or equivalent work experience in a related field.
  • 10+ years of hands-on engineering and administration of Microsoft Active Directory in large enterprises.
  • Strong multi-domain/forest AD experience, DNS, GPO, replication, and authentication protocols.
  • Expertise in identity synchronization, federation, and PowerShell automation.
  • Security-focused with knowledge of modern IAM practices.

Responsibilities

  • Design, implement, administer, and support AD across multiple domains/forests.
  • Lead identity federation services design and operations (ADFS, Entra ID Federation).
  • Manage Entra ID and hybrid identity solutions, including sync health and troubleshooting.
  • Support MFA, CA integrations, and secure authentication workflows.
  • Develop scalable identity architectures to support growth and mergers.
  • Partner with IAM/security teams for compliance, audits, and incident response.
  • Provide guidance to junior engineers and drive operational maturity.

Skills

Leadership
Architecture design
Troubleshooting
Communication
Identity security

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

ADFS
Entra ID/Entra ID Connect
PowerShell
Kerberos/NTLM

Job description

Overview

We are seeking a highly skilled and experienced Lead IAM Engineer to design, implement, administer, optimize, and support complex enterprise identity infrastructure across on‑premises and cloud environments. The role focuses on Microsoft Active Directory, Microsoft Entra ID, Entra ID Connect, identity federation, and multi‑factor authentication.

Responsibilities
  • Design, implement, administer, and support enterprise Active Directory environments across multiple on‑premises domains and forests.
  • Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation.
  • Administer and support Entra ID, hybrid identity solutions, and Entra ID Connect—including sync configuration, health monitoring, and troubleshooting.
  • Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows.
  • Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives.
  • Evaluate current‑state identity platforms and recommend improvements.
  • Contribute to roadmap planning for IAM and directory services modernization.
  • Implement identity security best practices for Active Directory and hybrid identity environments, including hardening, least privilege, privileged access controls, and secure administrative models.
  • Partner with IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts.
  • Review and improve controls related to authentication, access governance, and privileged access.
  • Serve as a senior escalation point for complex directory services, federation, and authentication issues; troubleshoot issues involving AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures.
  • Perform root cause analysis and implement long‑term corrective actions.
  • Ensure high availability and disaster recovery readiness for identity systems.
  • Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using PowerShell and relevant tools.
  • Create and maintain technical documentation, engineering standards, runbooks, and design artifacts.
  • Support operational maturity through process improvement and standardization.
  • Work closely with architecture teams on enterprise identity initiatives.
  • Provide technical guidance to junior engineers and operations team.
  • Participate in project planning, implementation, and change management activities.
  • Support acquisitions, divestitures, or business transformations involving identity integration and migration.
Qualifications
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience.
  • 10+ years of hands‑on experience in engineering and administration of Microsoft Active Directory in large enterprise environments.
  • Strong experience with multi‑domain and multi‑forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols.
  • Expertise in identity synchronization and federation troubleshooting.
  • Proficiency in PowerShell scripting and automation.
  • Experience designing and implementing secure identity solutions in enterprise environments.
  • Strong problem‑solving, troubleshooting, and root cause analysis skills.
  • Familiarity with security frameworks and best practices for identity infrastructure.
  • Excellent written and verbal communication skills.
  • Experience with enterprise IAM strategy and modernization.
  • Experience with mergers, acquisitions, divestitures, or domain consolidations.
  • Experience with Conditional Access and passwordless authentication.
  • Experience with privileged access management.
  • Experience with identity governance and access lifecycle processes.
Success Metrics
  • Active Directory and hybrid identity services are well‑architected and operationally mature.
  • Authentication, federation, and synchronization issues are proactively identified and resolved.
  • Security risks are reduced through improved configuration, hardening, and access controls.
  • Automation, documentation, and standardization improve team efficiency and reliability.
  • Identity platforms are secure, stable, and highly available.
  • The engineer serves as a trusted technical expert and strategic partner across IAM and infrastructure initiatives.
Benefits
  • Hybrid work model: flexible 2–3 days per week in office with the option to work from anywhere up to 8 weeks per year.
  • Competitive benefits package including vacation, mental health days, access to Headspace, retirement savings, and tuition reimbursement.
  • Paid volunteer days and ESG initiatives.

We are an Equal Employment Opportunity Employer and provide reasonable accommodations for qualified individuals with disabilities in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IAM Administrator
Senior IAM Administrator

Power Staffing Solutions • Toronto

On-site
CAD 90,000 - 120,000
Lead IAM Engineer — Hybrid Identity & AD Security
Lead IAM Engineer — Hybrid Identity & AD Security

Reuters • Toronto

Hybrid
CAD 140,000 - 190,000
Hybrid work model
Vacation & benefits
Headspace access
+3
Identity and Access Manager Engineer - Windows IAM
Identity and Access Manager Engineer - Windows IAM

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

On-site
CAD 90,000 - 120,000
Windows Active Directory L3 Support Engineer
Windows Active Directory L3 Support Engineer

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

Hybrid
CAD 110,000 - 150,000
Cyber Security Engineer / IAM Specialist
Cyber Security Engineer / IAM Specialist

Sunrise Farms • Surrey

On-site
CAD 110,000 - 130,000
Director of IAM Directory Services Operations
Director of IAM Directory Services Operations

Scotiabank • Toronto

On-site
CAD 120,000 - 150,000
Diversity, Equity, Inclusion & Allyship
Online courses and tuition assistance
Flexible vacation and benefits from day one
+1
Senior Identity & Access Management
Senior Identity & Access Management

TEEMA • Brampton

On-site
CAD 90,000 - 125,000
IT Administrator
IT Administrator

OTT Financial Group • Toronto

On-site
CAD 65,000 - 90,000
IAM Solution Architect / Technical Lead
IAM Solution Architect / Technical Lead

Alquemy • Ottawa

On-site
CAD 140,000 - 170,000
Senior IAM Engineer
Senior IAM Engineer

EPAM Systems • Toronto

On-site
CAD 140,000 - 155,000
Extended Healthcare
Life & AD&D Insurance
Employee Assistance Program
+10