CareerRiver

Lead IAM Engineer

THOMSON REUTERS CORP /CAN/

via workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to THOMSON REUTERS CORP /CAN/.
We are seeking a highly skilled and experienced Lead IAM Engineer to join our team. This role will be responsible for the design, implementation, administration, optimization, and support of complex enterprise identity infrastructure across both on-premises and cloud-integrated environments. The ideal candidate will have deep technical expertise in Microsoft Active Directory Domain Services (AD DS), Microsoft Entra ID, Entra ID Connect, identity federation, and multi-factor authentication (MFA). This individual will serve as a senior technical resource for identity architecture, security hardening, operational excellence, modernization initiatives, and escalated engineering support. This is a critical role for someone who thrives in a highly available, security-focused enterprise environment and has a strong track record of managing identity platforms at scale. About the role: Design, implement, administer, and support enterprise Active Directory environments across multiple on-premises domains and forests. Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation. Administer and support Entra ID and hybrid identity solutions. Manage and maintain Entra ID Connect, including sync configuration, health monitoring, and troubleshooting. Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows. Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives. Evaluate current-state identity platforms and recommend improvements. Design and implement hybrid identity and federation solutions for enterprise applications and services. Contribute to roadmap planning for IAM and directory services modernization. Implement identity security best practices for Active Directory and hybrid identity environments. Strengthen AD security posture through hardening, least privilege, privileged access controls, and secure administrative models. Partner with other IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts. Review and improve controls related to authentication, access governance and privileged access Serve as a senior escalation point for complex directory services, federation, and authentication issues. Troubleshoot and resolve issues involving: AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures Perform root cause analysis and implement long-term corrective actions. Ensure high availability and disaster recovery readiness for identity systems. Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using  PowerShell  and other relevant tools. Create and maintain technical documentation, engineering standards, runbooks, and design artifacts. Support operational maturity through process improvement and standardization. Work closely with the architecture teams on enterprise identity initiatives. Provide technical guidance to junior engineers and operations team. Participate in project planning, implementation, and change management activities. Support acquisitions, divestitures, or business transformations involving identity integration and migration. About You Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience. 10+ years of hands-on experience in engineering and administration of Microsoft Active Directory in large enterprise environments. Strong experience with multi-domain and multi-forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols, Identity synchronization and federation troubleshooting, PowerShell scripting and automation Experience designing and implementing secure identity solutions in enterprise environments. Strong problem-solving, troubleshooting, and root cause analysis skills. Familiarity with security frameworks and best practices for identity infrastructure. Excellent written and verbal communication skills. Experience with:  Enterprise IAM strategy and modernization Mergers, acquisitions, divestitures, or domain consolidations Conditional Access and Passwordless authentication Privileged Access Management Identity governance and access lifecycle processes What Success Looks Like in This Role Active Directory and hybrid identity services are well-architected and operationally mature. Authentication, federation, and synchronization issues are proactively identified and resolved. Security risks are reduced through improved configuration, hardening, and access controls. Automation, documentation, and standardization improve team efficiency and reliability. Identity platforms are secure, stable, and highly available. The engineer serves as a trusted technical expert and strategic partner across IAM and infrastructure initiatives. #LI-LP2 Replacement: This position is open due to an existing vacancy to support our evolving business needs. What’s in it For You? Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected. Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance. Career Development and Growth: By fostering a culture of c

Browse all locations