The Impact You'll Make:Does leading one of Canada's most complex identity ecosystems excite you? Loblaw Technology supports corporate offices, stores, pharmacies, distribution centres, digital properties, SaaS platforms, and multi-cloud environments. This role will lead the strategy, engineering, and reliable operation of identity controls that securely connect colleagues, suppliers, administrators, applications, and non-human identities. Lead a team that values diverse ideas, builds secure and resilient services, and develops our talent from within. You will have the opportunity to modernize enterprise identity at scale and make a measurable difference to security, colleague experience, and business operations.
What You'll Do- Lead Loblaw's enterprise identity and access management strategy, architecture, engineering, and operations across workforce, supplier, privileged, service, and machine identities.
- Own the roadmap and lifecycle for Active Directory, Microsoft Entra ID, SailPoint, CyberArk, Okta, federation services, and identity integrations, ensuring these platforms remain secure, resilient, supported, and fit for purpose.
- Establish reliable joiner, mover, and leaver controls across HR source systems and downstream applications, with clear service levels, reconciliation, exception management, and timely deprovisioning.
- Modernize authentication through phishing-resistant MFA, FIDO2/passkeys, Conditional Access, identity risk controls, and passwordless access while retiring legacy authentication methods and protocols.
- Lead privileged access management, including CyberArk vaulting and rotation, privileged sessions, break-glass access, service accounts, application secrets, SSH keys, and administrator authentication.
- Strengthen Active Directory and Entra governance by addressing orphaned and disabled accounts, weak passwords, stale access, privileged groups, service account ownership, role design, segregation of duties, and access certifications.
- Build a resilient IAM operating model covering capacity, high availability and disaster recovery, monitoring, incident/change/problem management, automation, runbooks, and after-hours coverage.
- Embed identity as a foundational Zero Trust control by partnering across HR, application, cloud, network, endpoint, data, SOC, infrastructure, operations, privacy, legal, and audit teams.
- Own IAM vendors, managed services, licensing, budgets, and investment roadmaps; report service health, control effectiveness, risks, and decisions to executive stakeholders.
- Lead and develop a multidisciplinary team of identity architects, engineers, product owners, analysts, and operations specialists, building succession, documentation, and two-deep coverage for critical services.
What You'll Bring- Progressive experience in identity and access management, cybersecurity, or enterprise infrastructure, including leading technical teams or major IAM programs.
- Demonstrated success leading IAM in a large, complex, multi-site enterprise, ideally within retail, healthcare, financial services, telecommunications, or another regulated environment.
- Deep knowledge of Active Directory, Microsoft Entra ID, SailPoint, CyberArk, Okta, and identity integration standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos, federation, and APIs.
- Proven experience designing and operating joiner, mover, and leaver processes integrated with HR platforms such as Workday or Ceridian, including data-quality, reconciliation, and downstream provisioning controls.
- Expertise in Conditional Access, phishing-resistant MFA, FIDO2/passkeys, passwordless authentication, identity risk, Zero Trust access, and legacy authentication decommissioning.
- Strong privileged-access and non-human identity experience, including vaulting, credential rotation, session monitoring, service accounts, secrets, SSH keys, break-glass accounts, and machine identity governance.
- Experience establishing identity governance, RBAC/ABAC, segregation of duties, access reviews, role mining, policy frameworks, and evidence aligned with NIST, ISO 27001, CIS Controls, and applicable regulatory obligations.
- Strong operational leadership across high availability, disaster recovery, capacity, monitoring, incident/problem/change management, automation, and service-level management for business-critical IAM platforms.
- Excellent executive communication, stakeholder management, financial management, and vendor leadership skills, with the ability to translate complex identity risks into clear decisions and measurable outcomes.
- Bachelor's or Master's degree in Computer Science, Information Security, Engineering, Information Systems, or a related field. Certifications such as CISSP, CISM, CRISC, Microsoft SC-300/SC-100, SailPoint, CyberArk, or Okta are strong assets.
Hiring Range / Échelle salariale à l'embauche :
$128,000.00 - $176,000.00 / 128.000,00$ - 176.000,00$ (per year / par an)
A candidate's experience and knowledge as well as the geographical region in which the position is located may be factored into the pay a candidate receives for this position. This posting is for an existing vacancy. The Company uses artificial intelligence for the purpose of screening, assessing and/or selecting applicants for this position. / L'expérience et les connaissances d'un candidat ainsi que la région géographique dans laquelle le poste est situé peuvent être prises en compte dans la rémunération qu'un candidat reçoit pour ce poste. Cette offre d'emploi concerne un poste vacant existant. L'entreprise utilise l'intelligence artificielle dans le but de filtrer, d'évaluer et/ou de sélectionner les candidats à ce poste.
#EN
#SS #LTnA #ON