IAM Specialist
Select how often (in days) to receive an alert:
Start Date:
ASAP
Work Model:
Hybrid
Location:
Downtown Toronto (outside Union Station – TTC & GO accessible)
Dress Code:
Business Casual
A Great Place to Work
Founded in 1993, Kinross is a Canadian-based senior gold mining company with operations and projects in the United States, Brazil, Mauritania, Chile and Canada. Our focus on delivering value is based on our four core values of Putting People First, Outstanding Corporate Citizenship, High Performance Culture, and Rigorous Financial Discipline.
Mining responsibly is a priority for Kinross, and we foster a culture that makes responsible mining and operational success inseparable. Our values-based approach ensures that sustainability and our environmental, social and governance commitments are a core part of our strategy and plans for future growth. In line with our values, we also aim to build meaningful partnerships with all of our stakeholders, including communities, shareholders, employees, governments and suppliers.
Kinross maintains listings on the Toronto Stock Exchange (symbol: K) and the New York Stock Exchange (symbol: KGC).
Job SummaryThe IAM Specialist is responsible for the design, implementation, integration, and ongoing operation of the organization’s identity infrastructure, with primary ownership of Active Directory (AD), Microsoft Entra (formerly Azure AD), and the enterprise Identity Governance and Administration (IGA) platform. This is a hands-on engineering role that is evolving from operational execution toward strategic oversight: as automation and AI take on routine identity tasks, the engineer increasingly acts as an architect of the organization’s identity fabric — ensuring security, resilience, interoperability, and compliance across hybrid and multi-cloud environments.
The successful candidate should be able to understand and manage identity dependencies across infrastructure, cloud platforms, security controls, automations while evaluating the broader impact of identity-related decisions across the enterprise. They will balance deep technical execution (directory services, authentication protocols, governance, automation) with governance, and cross-functional collaboration needed to secure an increasingly autonomous, AI-driven enterprise.
- Responsible for Active Directory modernization, transformation, and future-state architecture.
- Administer, secure, and optimize on-premises Active Directory (domains, forests, trusts, Group Policy, DNS, sites & services) and Microsoft Entra .
- Manage hybrid identity:
Entra Connect / Cloud Sync, password hash sync / pass-through authentication, federation, and seamless SSO. - Design and maintain Conditional Access policies, MFA, Privileged Identity Management (PIM), and Identity Protection.
Identity Governance & Administration (IGA)
- Manage, configure, and continuously improve the enterprise IGA platform (e.g., Saviynt, SailPoint), including connectors, workflows, and integrations with AD, Entra , and downstream applications.
- Own the identity lifecycle end to end — provisioning, deprovisioning, and joiner/mover/leaver automation — orchestrated through the IGA platform.
- Design and operate access certification and recertification campaigns, segregation-of-duties (SoD) controls, role-based access control (RBAC), and entitlement management.
- Build and maintain birthright access, access request and approval workflows, and policy-driven provisioning rules.
- Partner with audit, compliance, and application owners to ensure governance controls meet regulatory and internal requirements, and produce evidence for audits.
- Configure and troubleshoot SSO and application onboarding across SAML, OIDC, OAuth 2.0, and SCIM.
- Integrate enterprise applications with Entra , AD, and the IGA platform; manage service principals, enterprise apps, app registrations, and API permissions.
- Govern machine and workload identities — service accounts, API keys, certificates, and secrets — with appropriate rotation and least-privilege controls.
Automation, Resilience & AI Oversight
- Develop and maintain automation (Power Shell, Microsoft Graph API, IGA…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: