×
Register Here to Apply for Jobs or Post Jobs. X

Senior IAM Engineer

Job in Toronto, Ontario, C6A, Canada
Listing for: LCBO
Full Time position
Listed on 2026-09-08
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 83275 CAD Yearly CAD 83275.00 YEAR
Job Description & How to Apply Below

Location Address:

100 Queens Quay East, 9th Floor, Toronto

Number of Openings:

1

Pay:

$83,275.00 - $

Job Posting

Description:

IAM – Senior Identity Engineer This is an Onsite role #LI-On Site

Are you passionate about providing enterprise wide technical leadership and domain expertise for identity and access management? Reporting to the Senior Manager, Infrastructure, you will own the design, implementation and ongoing operation of identity, authentication, authorization and privileged access capabilities spanning our cloud and on-premises estate, with a near‑term focus on extending governance to SAP and supply chain platforms.

You will work across a broad technology environment — Microsoft Entra  Active Directory, Cyber Ark, 1

Password, Sectigo, and a growing portfolio of SaaS and enterprise applications — and integrate identity with core infrastructure platforms including Windows, Linux, AIX, Citrix, VMware, Net App, Commvault and Cisco UCS. Expertise in identity and authorization services in one or more of Azure, AWS or GCP is required.

As an important member of the LCBO’s IT transformation and modernization program, you will contribute to cross‑functional continuous improvement initiatives and serve as the champion for identity within the Core Backbone team.

If you are a proven identity professional who wants to take on the challenge of modernizing enterprise identity and data centre capabilities, this role is for you.

About the Role
  • Design, implement and manage secure, scalable Identity and Access Management solutions across cloud and on‑premises environments
  • Define and enforce policies for identity lifecycle, access provisioning and de‑provisioning, privileged access, and federated authentication — SAML 2.0, OIDC, OAuth 2.0, SCIM and WS‑Federation
  • Design and troubleshoot SAML and OIDC federations between Entra  third‑party SaaS and on‑premises applications, including claims mapping, attribute release, signing certificate rotation and metadata exchange
  • Administer and modernize Microsoft Entra  on‑premises Active Directory, including Conditional Access, Entra , Entra Connect and hybrid identity, and core AD infrastructure services (DNS, DHCP, sites and services, FSMO role placement, domain and forest health)
  • Implement and operate just‑in‑time (JIT) privileged access and Entra Privileged Identity Management (PIM) eligible versus active role assignments, time‑bound activation, approval workflows, MFA and justification on activation, and privileged role access reviews
  • Drive standing privilege reduction toward a zero standing privilege model, including tiered administration, privileged access workstations, break‑glass account design and emergency access procedures
  • Own privileged and credential management across the enterprise using Cyber Ark (vaulting, credential rotation, session isolation and monitoring, JIT elevation) and 1

    Password (team and service credential lifecycle, secrets hygiene, offboarding)
  • Manage the enterprise certificate lifecycle with Sectigo — issuance, renewal, revocation, automation and expiry prevention for internal and public‑facing services
  • Integrate IAM with HR systems, directories, and business‑critical SaaS and enterprise applications — including supply chain and warehouse management platforms such as Blue Yonder and Manhattan — covering SSO federation, SCIM or API‑based provisioning, and role mapping
  • Develop and support role‑and‑attribute‑based access controls (RBAC, ABAC), least‑privilege role design, and regular entitlement reviews and access recertification
  • Extend identity governance to enterprise business applications, including ERP platforms, with attention to segregation of duties and toxic‑combination risk
  • Manage non‑human identity — service accounts, managed identities, service principals and workload identity federation — including ownership, rotation and lifecycle
  • Partner with security, infrastructure, HR and business teams so that access is both secure and productive
  • Automate identity workflows and reporting using Power Shell, Microsoft Graph and IGA tooling; comfort across multi‑vendor identity platforms is expected — this is not a single‑vendor environment
  • Support audits,…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary