About the Role
This critical role is for a Lead IAM Engineer who thrives in a highly available, security-focused enterprise environment and has a strong track record of managing identity platforms at scale. The position is open due to an existing vacancy to support evolving business needs.
Responsibilities
- Design, implement, administer, and support enterprise Active Directory environments across multiple on-premises domains and forests.
- Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation.
- Administer and support Entra ID and hybrid identity solutions.
- Manage and maintain Entra ID Connect, including sync configuration, health monitoring, and troubleshooting.
- Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows.
- Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives.
- Evaluate current-state identity platforms and recommend improvements.
- Design and implement hybrid identity and federation solutions for enterprise applications and services.
- Contribute to roadmap planning for IAM and directory services modernization.
- Implement identity security best practices for Active Directory and hybrid identity environments.
- Strengthen AD security posture through hardening, least privilege, privileged access controls, and secure administrative models.
- Partner with other IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts.
- Review and improve controls related to authentication, access governance and privileged access.
- Serve as a senior escalation point for complex directory services, federation, and authentication issues.
- Troubleshoot and resolve issues involving: AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures.
- Perform root cause analysis and implement long-term corrective actions.
- Ensure high availability and disaster recovery readiness for identity systems.
- Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using PowerShell and other relevant tools.
- Create and maintain technical documentation, engineering standards, runbooks, and design artifacts.
- Support operational maturity through process improvement and standardization.
- Work closely with the architecture teams on enterprise identity initiatives.
- Provide technical guidance to junior engineers and operations team.
- Participate in project planning, implementation, and change management activities.
- Support acquisitions, divestitures, or business transformations involving identity integration and migration.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience.
- 10+ years of hands-on experience in engineering and administration of Microsoft Active Directory in large enterprise environments.
- Strong experience with multi-domain and multi-forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols, Identity synchronization and federation troubleshooting, PowerShell scripting and automation.
- Experience designing and implementing secure identity solutions in enterprise environments.
- Strong problem-solving, troubleshooting, and root cause analysis skills.
- Familiarity with security frameworks and best practices for identity infrastructure.
- Excellent written and verbal communication skills.
- Experience with Enterprise IAM strategy and modernization.
- Experience with Mergers, acquisitions, divestitures, or domain consolidations.
- Experience with Conditional Access and Passwordless authentication.
- Experience with Privileged Access Management.
- Experience with Identity governance and access lifecycle processes.
Skills
- Microsoft Active Directory Domain Services (AD DS)
- Microsoft Entra ID
- Entra ID Connect
- Identity federation
- Multi-factor authentication (MFA)
- ADFS
- PowerShell
Location
- Ontario, Canada
Work Type
- Hybrid Work Model
- Work from anywhere for up to 8 weeks per year
Experience Level
- 10+ years of hands-on experience in engineering and administration of Microsoft Active Directory in large enterprise environments.
Education Level
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience.
Salary/Compensations
- $140,600 CAD - $190,600 CAD
Benefits
- Flexible vacation
- Two company-wide Mental Health Days off
- Access to the Headspace app
- Retirement savings
- Tuition reimbursement
- Employee incentive programs
- Resources for mental, physical, and financial wellbeing
About the Company
- Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions.
- We serve professionals across legal, tax, accounting, compliance, government, and media.
- Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency.
- Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
- We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments.
- At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them.
- Join us and help shape the industries that move society forward.
- As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals.
Equal Opportunity
- As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals.
- To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law.
- Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
- We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law.
