LCBO Logo

LCBO

Senior IAM Engineer

Sorry, this job was removed at 12:43 a.m. (EST) on Thursday, Sep 17, 2026
Be an Early Applicant
In-Office
Toronto, ON, CAN
Senior level
In-Office
Toronto, ON, CAN
Senior level

Similar Jobs

4 Days Ago
In-Office
Toronto, ON, CAN
Senior level
Senior level
Software
Designs, administers, and automates enterprise identity and access management across hybrid and multi-cloud environments. Responsibilities include SSO, MFA, PAM, provisioning and deprovisioning workflows, access governance, identity lifecycle automation, tier 3 support, root-cause analysis, compliance audits, and zero-trust security improvements. The role collaborates with cloud, infrastructure, compliance, and security teams while mentoring junior engineers.
Top Skills: AbacActive DirectoryAWSBashCloudFormationGCPIgaLdapMfaAzureMicrosoft Entra IdOauth 2.0OktaOpenid ConnectPamPing IdentityPowershellPythonRbacSaml 2.0SsoTerraformZero Trust
18 Days Ago
In-Office or Remote
4 Locations
Senior level
Senior level
Artificial Intelligence • Big Data • Cloud • Machine Learning • Software
Own the reliability and resilience of enterprise IAM services, resolving incidents, monitoring authentication and provisioning signals, correlating events, improving detection rules, validating automated remediation, and optimizing identity lifecycle workflows. The role supports Okta, Active Directory, and Microsoft Entra ID environments, contributes to post-incident improvements, partners across technical teams, and participates in rotational on-call support.
Top Skills: Active DirectoryAiopsCloud EnvironmentsEvent Management SystemsMicrosoft Entra IdObservability PlatformsOktaPowershellRest ApisSaaS
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Design, develop, and maintain enterprise authentication capabilities on a Unified Authentication Platform. Integrate IAM platforms (Ping, IBM ISAM), implement Passkeys (FIDO2/WebAuthn), MFA, OAuth2/OIDC/SAML token lifecycle, REST APIs, and directory integrations. Apply secure coding and collaborate with architecture and DevSecOps teams to deliver scalable, secure identity solutions.
Top Skills: Active DirectoryApi SecurityFido2Ibm IsamIbm IsvaJavaJwtLdapMfaOauth 2.0Oauth/Oidc Token ManagementOpenid Connect (Oidc)Ping IdentityPingfederatePingoneRest ApisSAMLSpring BootWebauthnZero Trust
Designs, implements, and operates enterprise IAM across cloud and on-premises environments. Responsibilities include Entra ID and Active Directory administration, federation, privileged access management, CyberArk and certificate lifecycle management, RBAC and ABAC, identity governance, non-human identity management, application provisioning, automation, audit support, and compliance. The role provides technical leadership for identity modernization and partners with security, infrastructure, HR, and business teams.
The summary above was generated by AI

Location Address:

100 Queens Quay East, 9th Floor, Toronto

Number of Openings:

1

Pay:

$83,275.00 - $149,941.00


Job Posting Description:

IAM – Senior Identity Engineer

This is an Onsite role #LI-OnSite

Are you passionate about providing enterprise wide technical leadership and domain expertise for identity and access management? Reporting to the Senior Manager, Infrastructure, you will own the design, implementation and ongoing operation of identity, authentication, authorization and privileged access capabilities spanning our cloud and on-premises estate, with a near-term focus on extending governance to SAP and supply chain platforms.

You will work across a broad technology environment — Microsoft Entra ID and Active Directory, CyberArk, 1Password, Sectigo, and a growing portfolio of SaaS and enterprise applications — and integrate identity with core infrastructure platforms including Windows, Linux, AIX, Citrix, VMware, NetApp, Commvault and Cisco UCS. Expertise in identity and authorization services in one or more of Azure, AWS or GCP is required.

As an important member of the LCBO's IT transformation and modernization program, you will contribute to cross-functional continuous improvement initiatives and serve as the champion for identity within the Core Backbone team.

If you are a proven identity professional who wants to take on the challenge of modernizing enterprise identity and data centre capabilities, this role is for you.

About the Role

  • Design, implement and manage secure, scalable Identity and Access Management solutions across cloud and on-premises environments
  • Define and enforce policies for identity lifecycle, access provisioning and de-provisioning, privileged access, and federated authentication — SAML 2.0, OIDC, OAuth 2.0, SCIM and WS-Federation
  • Design and troubleshoot SAML and OIDC federations between Entra ID and third-party SaaS and on-premises applications, including claims mapping, attribute release, signing certificate rotation and metadata exchange
  • Administer and modernize Microsoft Entra ID and on-premises Active Directory, including Conditional Access, Entra ID Governance, Entra Connect and hybrid identity, and core AD infrastructure services (DNS, DHCP, sites and services, FSMO role placement, domain and forest health)
  • Implement and operate just-in-time (JIT) privileged access and Entra Privileged Identity Management (PIM) eligible versus active role assignments, time-bound activation, approval workflows, MFA and justification on activation, and privileged role access reviews
  • Drive standing privilege reduction toward a zero standing privilege model, including tiered administration, privileged access workstations, break-glass account design and emergency access procedures
  • Own privileged and credential management across the enterprise using CyberArk (vaulting, credential rotation, session isolation and monitoring, JIT elevation) and 1Password (team and service credential lifecycle, secrets hygiene, offboarding)
  • Manage the enterprise certificate lifecycle with Sectigo — issuance, renewal, revocation, automation and expiry prevention for internal and public-facing services
  • Integrate IAM with HR systems, directories, and business-critical SaaS and enterprise applications — including supply chain and warehouse management platforms such as Blue Yonder and Manhattan — covering SSO federation, SCIM or API-based provisioning, and role mapping
  • Develop and support role- and attribute-based access controls (RBAC, ABAC), least-privilege role design, and regular entitlement reviews and access recertification
  • Extend identity governance to enterprise business applications, including ERP platforms, with attention to segregation of duties and toxic-combination risk
  • Manage non-human identity — service accounts, managed identities, service principals and workload identity federation — including ownership, rotation and lifecycle
  • Partner with security, infrastructure, HR and business teams so that access is both secure and productive
  • Automate identity workflows and reporting using PowerShell, Microsoft Graph and IGA tooling; comfort across multi-vendor identity platforms is expected — this is not a single-vendor environment
  • Support audits, respond to findings and champion compliance across PCI DSS, NIST and internal risk frameworks

About You

  • University degree in Computer Science, Engineering, Math or a related field
  • 10+ years of experience designing complex infrastructure platforms
  • 5+ years experience leading projects, overseeing delivery and coaching engineers
  • 5–10 years of experience in Identity and Access Management roles in enterprise or hybrid environments
  • A strong identity as a security-first technologist who understands that IAM is about both safety and simplicity
  • Hands-on expertise with platforms such as Microsoft Entra ID, Okta, SailPoint, CyberArk, Ping or ForgeRock
  • Experience with federated identity (SAML, OIDC, OAuth), directory services (LDAP and Active Directory) and privileged access management strategies
  • Experience with PKI, DHCP and DNS
  • Scripting or automation experience (PowerShell, Python, Terraform) to support IAM and IGA orchestration
  • Familiarity with compliance and governance frameworks such as NIST, ISO 27001, CIS and PCI DSS
  • A passion for making security usable — balancing strong controls with seamless user experience

Nice to have

  • SAP Cloud Identity Access Governance (IAG) access requests, access analysis, role design, privileged access
  • SAP S/4HANA authorization concepts (PFCG roles, business roles, derived roles) and how they map to enterprise identity governance
  • SAP Identity Provisioning Service (IPS) / Identity Authentication Service (IAS)
  • Experience federating and governing access for retail or supply chain platforms such as Blue Yonder, Manhattan Associates, or comparable WMS/ERP applications
  • Relevant certifications: SC-300, SC-100, AZ-500, CISSP, or CyberArk Defender/Sentry
  • Familiarity with compliance and governance frameworks like NIST, ISO 27001, CIS, or PCI-DSS.
  • A passion for making security usable—balancing strong controls with seamless user experience.

We offer a comprehensive suite of benefits including:

  • Health/Dental Benefits
  • Access to an Employee & Family Assistance Program
  • a Defined Benefit Pension
  • Discounts on products and services via Workperks.

There is a world of opportunities at the LCBO…

Join an organization where you can be challenged while achieving your true potential. A place where you can make a positive impact supporting Ontario business and communities. Discover a safe, healthy, diverse, inclusive, and accountable workplace where your wellbeing is our top priority. At the LCBO, your contributions are respected and valued.  Be part of our journey as we invest in people and technology to transform an organization. There really is a world of opportunities at the LCBO.

We foster a culture of inclusion and belonging, so everyone feels valued, respected, and heard. The LCBO is an equal opportunity employer and committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility of Ontarians with Disabilities Act. If contacted for an interview or employment opportunity, please advise if you require an accommodation.

Please submit your resume via Workday by 11:59pm on the deadline date.  We appreciate your interest and advise that only those selected for an interview will be contacted.

The LCBO collects and uses the personal information you provide under the authority of the Liquor Control Board of Ontario Act, 2019, SO 2019, c 15, Sch 21, Section 3 and in compliance with the Freedom of Information and Protection of Privacy Act for the sole purpose of processing your job application.  When you click “Apply with LinkedIn” you are agreeing to share your information with our service providers engaged by us in connection with recruitment and human resources related activities.

If you have any questions concerning the LCBO’s collection and use of personal information, please contact the Freedom of Information and Privacy Office.

Work Hours:

36.25

Union / Non-Union:

Non-Union

Job Posting End Date:

September 16, 2026

The LCBO is an equal opportunity employer and committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act.

HQ

LCBO Toronto, Ontario, CAN Office

100 Queens Quay E, Toronto, Ontario, Canada, M5E 0C7

LCBO Brampton, Ontario, CAN Office

Brampton, Canada

LCBO Cambridge, Ontario, CAN Office

Cambridge, Canada

LCBO Clarington, Ontario, CAN Office

Clarington, Canada

LCBO Hamilton, Ontario, CAN Office

Hamilton, Canada

LCBO Kitchener, Ontario, CAN Office

Kitchener, Canada

LCBO Mississauga, Ontario, CAN Office

Mississauga, Canada

LCBO Oakville, Ontario, CAN Office

Oakville, Canada

LCBO Scarborough, Ontario, CAN Office

Scarborough, Canada

LCBO Vaughan, Ontario, CAN Office

Vaughan, Canada

LCBO Waterloo, Ontario, CAN Office

Waterloo, Canada

LCBO Whitby, Ontario, CAN Office

Whitby, Canada

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account