Associate Manager, Digital Identity
Avanade View all jobs
- Toronto, ON
- $114,400-135,850 per year
- Permanent
- Full-time
- Develop and implement modern authentication solutions (OAuth, SAML, token-based authentication, claims transformations).
- Manage identities and authentication services using Microsoft Entra ID, including SSO, Conditional Access, MFA, PIM, and authentication methods.
- Enhance and secure Active Directory environments, including AD tiered models, GPOs, DNS, PKI/Certification Authority, and AD recovery.
- Manage IAM lifecycle processes (provisioning, deprovisioning, JML, IGA).
- Configure and maintain Entra ID Hybrid Sync and application provisioning (SCIM, custom attributes).
- Develop and implement External Identity solutions including Customer Identity and Access Management (CIAM)
- Troubleshoot and resolve complex IAM issues across AD, Entra ID, and authentication flows.
- Lead or contribute to solution design and delivery for identity projects.
- Collaborate with cross-functional teams and stakeholders in an agile environment.
- Support privileged access management and secrets management initiatives.
- 7+ years' experience in Identity and Access Management (IAM), with a strong focus on Microsoft Entra ID (Azure AD).
- Experienced in consulting and advisory discussions with clients and other consulting firms.
- SC-300 - Microsoft Certified: Identity and Access Administrator Associate
- Proven understanding of Active Directory and legacy authentication protocols (LDAP, Kerberos, NTLM, etc.), Entra ID Sync.
- Demonstrated expertise with Entra ID and Entra ID Domain Services, including relevant use cases.
- Skilled in managing identities, setting up conditional access, implementing multi-factor authentication, configuring global secure access (Entra Internet Access & Private Access) and overseeing identity governance with Microsoft Entra ID.
- Experience with modern authentication protocols and integrating applications using those protocols.
- Experience leading small to medium project general design and delivery (solution architecture and associated infrastructure or business and functional requirements).
- Understanding of the business, privacy, security, and compliance challenges surrounding Digital Identities and a passion for solving these challenges for clients.
- Experience of privileged access management solutions and an understanding of secrets management.
- Experience with additional IAM platforms such as Auth0, Ping Identity, or ForgeRock.
- Scripting and automation capabilities using Python PowerShell, or similar languages to extend IAM functionality.