05 Sep
|
LCBO (Liquor Control Board of Ontario)
|
Ontario
05 Sep
LCBO (Liquor Control Board of Ontario)
Ontario
Location Address: 100 Queens Quay East, 9th Floor, Toronto
Number of Openings: 1
Pay: $83,275.00 - $149,941.00
Work Hours: 36.25
Job Summary IAM – Senior Identity Engineer. This is an Onsite role.
Are you passionate about providing enterprise wide technical leadership and domain expertise for identity and access management? Reporting to the Senior Manager, Infrastructure, you will own the design, implementation and ongoing operation of identity, authentication, authorization and privileged access capabilities spanning our cloud and on-premises estate, with a near-term focus on extending governance to SAP and supply chain platforms. You will work across a broad technology environment - Microsoft Entra ID and Active Directory, CyberArk, 1Password, Sectigo, and a growing portfolio of SaaS and enterprise applications - and integrate identity with core infrastructure platforms including Windows, Linux, AIX, Citrix, VMware, NetApp, Commvault and Cisco UCS. Expertise in identity and authorization services in one or more of Azure, AWS or GCP is required. As an important member of the LCBO's IT transformation and modernization program, you will contribute to cross-functional continuous improvement initiatives and serve as the champion for identity within the Core Backbone team. If you are a proven identity professional who wants to take on the challenge of modernizing enterprise identity and data centre capabilities, this role is for you.
Responsibilities Design, implement and manage secure, scalable Identity and Access Management solutions across cloud and on-premises environments
Define and enforce policies for identity lifecycle, access provisioning and de-provisioning, privileged access, and federated authentication - SAML 2.0, OIDC, OAuth 2.0, SCIM and WS-Federation
Design and troubleshoot SAML and OIDC federations between Entra ID and third-party SaaS and on-premises applications, including claims mapping, attribute release, signing certificate rotation and metadata exchange
Administer and modernize Microsoft Entra ID and on-premises Active Directory, including Conditional Access, Entra ID Governance, Entra Connect and hybrid identity, and core AD infrastructure services (DNS, DHCP, sites and services, FSMO role placement, domain and forest health)
Implement and operate just-in-time (JIT) privileged access and Entra Privileged Identity Management (PIM) eligible versus active role assignments, time-bound activation, approval workflows, MFA and justification on activation, and privileged role access reviews
Drive standing privilege reduction toward a zero standing privilege model, including tiered administration, privileged access workstations, break-glass account design and emergency access procedures
Own privileged and credential management across the enterprise using CyberArk (vaulting, credential rotation, session isolation and monitoring, JIT elevation) and 1Password (team and service credential lifecycle, secrets hygiene, offboarding)
Manage the enterprise certificate lifecycle with Sectigo - issuance, renewal, revocation, automation and expiry prevention for internal and public-facing services
Integrate IAM with HR systems, directories, and business-critical SaaS and enterprise applications - including supply chain and warehouse management platforms such as Blue Yonder and Manhattan - covering SSO federation, SCIM or API-based provisioning, and role mapping
Develop and support role- and attribute-based access controls (RBAC, ABAC), least-privilege role design, and regular entitlement reviews and access recertification
Extend identity governance to enterprise business applications, including ERP platforms, with attention to segregation of duties and toxic-combination risk
Manage non-human identity - service accounts, managed identities, service principals and workload identity federation - including ownership, rotation and lifecycle
Partner with security, infrastructure, HR and business teams so that access is both secure and productive
Automate identity workflows and reporting using PowerShell, Microsoft Graph and IGA tooling; comfort across multi-vendor identity platforms is expected - this is not a single-vendor environment
Support audits, respond to findings and champion compliance across PCI DSS, NIST and internal risk frameworks
About You University degree in Computer Science, Engineering, Math or a related field
10+ years of experience designing complex infrastructure platforms
5+ years experience leading projects, overseeing delivery and coaching engineers
5-10 years of experience in Identity and Access Management roles in enterprise or hybrid environments
A strong identity as a security-first technologist who understands that IAM is about both safety and simplicity
Hands-on expertise with platforms such as Microsoft Entra ID, Okta, SailPoint, CyberArk, Ping or ForgeRock
Experience with federated identity (SAML, OIDC, OAuth), directory services (LDAP and Active Directory) and privileged access management strategies
Experience with PKI, DHCP and DNS
Scripting or automation experience (PowerShell, Python, Terraform) to support IAM and IGA orchestration
Familiarity with compliance and governance frameworks such as NIST, ISO 27001, CIS and PCI DSS
A passion for making security usable - balancing strong controls with seamless user experience
Nice to Have SAP Cloud Identity Access Governance (IAG) access requests, access analysis, role design, privileged access
SAP S/4HANA authorization concepts (PFCG roles, business roles, derived roles) and how they map to enterprise identity governance
SAP Identity Provisioning Service (IPS) / Identity Authentication Service (IAS) Experience federating and governing access for retail or supply chain platforms such as Blue Yonder, Manhattan Associates, or comparable WMS/ERP applications
Relevant Certifications SC-300
SC-100
AZ-500
CISSP
CyberArk Defender/Sentry
Familiarity with compliance and governance frameworks like NIST, ISO 27001, CIS, or PCI-DSS
Benefits Health/Dental Advantages
Access to an Employee & Family Assistance Program
A Defined Benefit Pension
Discounts on products and services via Workperks
Company Culture & Commitment There is a world of opportunities at the LCBO… Join an organization where you can be challenged while achieving your true potential. A place where you can make a positive impact supporting Ontario business and communities. Discover a safe, healthy, diverse, inclusive, and accountable workplace where your wellbeing is our top priority. At the LCBO, your contributions are respected and valued. Be part of our journey as we invest in people and technology to transform an organization. We foster a culture of inclusion and belonging, so everyone feels valued, respected, and heard.
The LCBO is an equal opportunity employer and committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility of Ontarians with Disabilities Act. The LCBO (Liquor Control Board of Ontario) is an Ontario government enterprise and one of the world’s largest buyers and retailers of beverage alcohol.
Job Posting End Date September 16, 2026
#J-18808-Ljbffr
📌 Senior IAM Engineer (Ontario)
🏢 LCBO (Liquor Control Board of Ontario)
📍 Ontario