Thomson Reuters
Lead IAM Engineer
Location unstated
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Lead / management
- Country
- CA
- Work mode
- On-site / unstated
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
We are seeking a highly skilled and experienced Lead IAM Engineer to join our team. This role will be responsible for the design, implementation, administration, optimization, and support of complex enterprise identity infrastructure across both on-premises and cloud-integrated environments.
The ideal candidate will have deep technical expertise in Microsoft Active Directory Domain Services (AD DS), Microsoft Entra ID, Entra ID Connect, identity federation, and multi-factor authentication (MFA). This individual will serve as a senior technical resource for identity architecture, security hardening, operational excellence, modernization initiatives, and escalated engineering support.
This is a critical role for someone who thrives in a highly available, security-focused enterprise environment and has a strong track record of managing identity platforms at scale.
About the role:
Design, implement, administer, and support enterprise Active Directory environments across multiple on-premises domains and forests.
Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation.
Administer and support Entra ID and hybrid identity solutions.
Manage and maintain Entra ID Connect, including sync configuration, health monitoring, and troubleshooting.
Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows.
Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives.
Evaluate current-state identity platforms and recommend improvements.
Design and implement hybrid identity and federation solutions for enterprise applications and services.
Contribute to roadmap planning for IAM and directory services modernization.
Implement identity security best practices for Active Directory and hybrid identity environments.
Strengthen AD security posture through hardening, least privilege, privileged access controls, and secure administrative models.
Partner with other IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts.
Review and improve controls related to authentication, access governance and privileged access
Serve as a senior escalation point for complex directory services, federation, and authentication issues.
Troubleshoot and resolve issues involving: AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures
Perform root cause analysis and implement long-term corrective actions.
Ensure high availability and disaster recovery readiness for identity systems.
Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using PowerShell and other relevant tools.
Create and maintain technical documentation, engineering standards, runbooks, and design artifacts.
Support operational maturity through process improvement and standardization.
Work closely with the architecture teams on enterprise identity initiatives.
Provide technical guidance to junior engineers and operations team.
Participate in project planning, implementation, and change management activities.
Support acquisitions, divestitures, or business transformations involving identity integration and migration.
About You
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience.
10+ years of hands-on experience in engineering and administration of Microsoft Active Directory in large enterprise environments.
Strong experience with multi-domain and multi-forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols, Identity synchronization and federation troubleshooting, PowerShell scripting and automation
Experience designing and implementing secure identity solutions in enterprise environments.
Strong problem-solving, troubleshooting, and root cause analysis skills.
Familiarity with security frameworks and best practices for identity infrastructure.
Excellent written and verbal communication skills.
Experience with:
Enterprise IAM strategy and modernization
Mergers, acquisitions, divestitures, or domain consolidations
Conditional Access and Passwordless authentication
Privileged Access Management
Identity governance and access lifecycle processes
What Success Looks Like in This Role
Active Directory and hybrid identity services are well-architected and operationally mature.
Authentication, federation, and synchronization issues are proactively identified and resolved.
Security risks are reduced through improved configuration, hardening, and access controls.
Automation, documentation, and standardization improve team efficiency and reliability.
Identity platforms are secure, stable, and highly available.
The engineer serves as a trusted technical expert and strategic partner across IAM and infrastructure initiatives.
#LI-LP2
- Replacement: This position is open due to an existing vacancy to support our evolving business needs.
- What’s in it For You?
- Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
- Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
- Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
- Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
- Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
- Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
- Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
Our use of AI within the recruitment process Thomson Reuters utilizes Artificial Intelligence (AI) to support parts of our global recruitment process. Unless you opt-out, our AI system will assess the information provided by you and compare it to the requirements listed for the role, and present the result to our recruitment personnel for further review. The AI system acts as a supporting tool, but there is always a human making the decision if you will be considered for the role
Thomson Reuters complies with local laws that r
Similar jobs
- Lead IAM EngineerBraze · TorontoFirst seen 13d ago
- Principal IAM Engineer - Directory ServicesSyneoshealth · SRB-Belgrade-HybridFirst seen 2d ago
- Senior/Lead - Cyber Security - IAM Engineer - Identity and GovernanceFico · Work from Home, United StatesFirst seen 2d agoremote
- Manager - IAM Engineering and IntegrationGM Financial United States · Arlington, TX, United StatesFirst seen 2d ago
- CIAM Engineering ManagerState Street · 2 LocationsFirst seen 2d ago
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job