T Rowe Price Group, Inc

Lead Infrastructure Engineer, IAM

T Rowe Price Group, Inc • $122K — $209K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in designing and modernizing IAM capabilities in large enterprises.
  • Hands-on expertise with hybrid identity architectures including Active Directory and cloud models.
  • Ability to independently lead complex technical initiatives.
  • Strong understanding of security controls and operational risk in regulated environments.
  • Demonstrated experience creating standards and influencing architecture decisions.
  • Advanced troubleshooting skills in identity and network dependencies.

Responsibilities

  • Define and advance the IAM technology strategy and reference patterns for hybrid environments.
  • Lead migration efforts from legacy identity solutions to modern cloud-based models.
  • Serve as a technical advisor for identity architecture and access management decisions.
  • Collaborate with cross-functional teams to design secure access models for various platforms.
  • Drive adoption of Zero Trust principles and modern MFA capabilities across enterprise systems.
  • Establish IAM standards and procedures for compliance and operational effectiveness.
  • Mentor engineers through design reviews and technical guidance.

Benefits

  • Competitive compensation package.
  • Eligibility for annual performance-based bonuses.
  • Generous retirement plan for long-term financial security.
  • Hybrid work schedule allowing for flexibility in work location.
  • Health and wellness benefits including online therapy options.
  • Paid time off for personal needs including vacations and volunteering.
  • Resources for family care, including fertility and adoption assistance.
Full Job Description
Role Summary

This is a highly visible senior-level individual contributor leadership role where you will influence the strategic direction of Identity and Access Management across a global, highly regulated organization. As a trusted technical leader, you will drive the evolution of our identity ecosystem, transforming legacy, Active Directory-centric architectures into a modern, cloud-first identity platform built on Zero Trust principles. You will lead the design and advancement of next-generation identity capabilities across Microsoft Entra ID, AWS IAM Identity Center, federation, privileged access management (PAM), conditional access, PKI/certificate services, identity automation, and cloud-native security controls. Working across infrastructure, security, and application teams, you will establish the technical vision, architecture, and roadmap for enterprise identity services that secure thousands of users, applications, and critical business systems.

In this role, you will serve as a senior technical authority, providing deep expertise, strategic influence, and hands-on guidance without direct people management responsibilities. Partnering closely with security, infrastructure, cloud, application, audit, operations, and architecture teams, you will define enterprise standards, assess and mitigate risk, guide critical engineering decisions, and mentor technical talent across the organization. Success in this position requires the ability to balance long-term architectural vision with practical execution, ensuring identity capabilities are secure, resilient, scalable, and aligned with both business objectives and evolving regulatory requirements.

Responsibilities
  • Define and advance the enterprise IAM technology strategy, roadmap, standards, and reference patterns for modern identity services across hybrid Active Directory, Microsoft Entra ID, and AWS environments.
  • Lead complex IAM modernization efforts, including migration from legacy AD, ADFS, MIM, LDAP, and directory service patterns to cloud-based authentication, authorization, lifecycle, and access governance models.
  • Serve as an authoritative technical advisor for identity architecture decisions, including federation, conditional access, privileged access, identity protection, cross-tenant access, B2B/B2C identity, entitlement management, and certificate-based authentication.
  • Partner with cloud, infrastructure, security, audit, risk, and application teams to design secure and scalable access models for AWS, Microsoft, SaaS, and enterprise application ecosystems.
  • Drive adoption of Zero Trust, least privilege, adaptive access, JIT access, risk-based authentication, and modern MFA capabilities across enterprise platforms.
  • Establish and maintain IAM standards, design patterns, engineering guardrails, operational procedures, and compliance reporting practices.
  • Provide hands-on technical leadership for complex troubleshooting across Kerberos, SPNs, delegation, certificates, federation, conditional access, MFA, SAML assertions, OAuth flows, DNS, and network authentication dependencies.
  • Mentor engineers and technical leaders through design reviews, troubleshooting sessions, knowledge sharing, and standards-based engineering practices.
  • Assess security risks and technical debt within IAM platforms and define remediation plans that improve resiliency, auditability, and operational effectiveness.
  • Influence senior stakeholders and cross-functional teams through clear communication, pragmatic decision-making, and enterprise-level technical judgment


Qualifications

Required:
  • 8+ years of experience designing, implementing, operating, or modernizing IAM capabilities in a large enterprise environment.
  • Deep hands-on expertise with hybrid identity architectures spanning Active Directory, Microsoft Entra ID, federation, privileged access management, and cloud authentication models.
  • Demonstrated ability to independently lead complex technical initiatives.
  • Strong understanding of security controls, access governance, audit requirements, and operational risk management in regulated environments.
  • Proven ability to create standards, influence architecture decisions, and mentor engineering teams.
  • Strong troubleshooting skills across identity, directory, certificate, authentication, federation, cloud, DNS, and network dependencies.


Preferred:
  • Experience modernizing identity capabilities as part of a broader cloud, data center exit, endpoint modernization, or platform transformation program.
  • Experience integrating identity patterns into AWS-based application and infrastructure platforms.
  • Experience with certificate lifecycle management, PKI modernization, passwordless authentication, and Zero Trust adoption.
  • Experience defining enterprise IAM roadmaps, control frameworks, engineering standards, or capability maturity plans.
  • Relevant Microsoft, AWS, security, or identity-focused certifications are beneficial but not required.


FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to three days per week from home.

Base Salary Ranges

Please review the job posting for the location of this specific opportunity.

$122,000.00 - $209,000.00 for the location of: Maryland, Colorado, Washington and remote workers
$135,000.00 - $230,000.00 for the location of: Washington, D.C.
$153,000.00 - $261,000.00 for the location of: New York, California

Placement within the range provided above is based on the individual's relevant experience and skills for the role. Base salary is only one component of our total compensation package. Employees may be eligible for a discretionary bonus, which is determined upon company and individual performance.

Benefits

We value your goals and needs, at work and in life. As an associate, you'll be supported with resources, benefits, and work-life balance so you can thrive in ways that matter to you.

Featured employee benefits to enrich your life:

  • Competitive compensation


  • Annual bonus eligibility


  • A generous retirement plan


  • Hybrid work schedule


  • Health and wellness benefits, including online therapy


  • Paid time off for vacation, illness, medical appointments, and volunteering days


  • Family care resources, including fertility and adoption benefits


Learn more about our benefits.

About T Rowe Price Group, Inc

T. Rowe Price Group, Inc. is an American publicly owned global asset management firm that offers funds, advisory services, account management, and retirement plans and services for individuals, institutions, and financial intermediaries. The company was founded in 1937 by Thomas Rowe Price Jr. and went public in 1986. The company is headquartered in Baltimore, Maryland and has offices in 16 countries worldwide. As of December 31, 2020, the company had $1.47 trillion in assets under management. The company is listed on the NASDAQ stock exchange under the ticker symbol TROW.
Learn more about T Rowe Price Group, Inc
Size
7,529 employees
Market Cap
$24.5 billion
Industry
Net Income
$2.3 billion
Founded
1937
5 Year Trend
+12.4%
Revenue
$6.2 billion
NASDAQ

Similar Jobs

More Jobs at T Rowe Price Group, Inc

More Information Technology Jobs

Find similar Lead Infrastructure Engineer, IAM jobs: