Description & RequirementsRole Summary We are looking for an experienced Senior Systems Engineer with deep expertise in both Identity & Access Management (IAM) and Windows Systems Administration to join our Identity Security Operations and Delivery team. You will lead the operations and delivery of enterprise identity solutions, with a primary focus on Microsoft Entra ID and our global hybrid Active Directory deployment. This is a senior operations role where you will secure human and non-human identities, enable enterprise identity lifecycle management, configure application single sign-on and provisioning, enable a Zero Trust security posture, support passwordless (FIDO2) authenticator deployment, and manage complex system integrations. You will be working closely with security, application, and infrastructure stakeholders, reporting to a manager based in Vancouver, Canada. You will be part of EA's IT Security team, within EAIT Global Infrastructure Services.
Location - Vancouver (Hybrid - 3 days)
Responsibilities: - You are a team player who will complete project deliverables, lead troubleshooting sessions, resolve escalated incidents from our support partners, fulfil service requests, implement changes, identify improvements, and prepare documentation.
- You will design and deliver end-to-end SSO integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0 across Entra ID and Okta.
- You will Implement and manage SCIM provisioning for SaaS applications, including licensing optimization and deprovisioning hygiene.
- You will secure both human and non-human identities, including service accounts, Agentic AI and Application Secrets, through modern authentication protocols.
- You will define and maintain authorization models including role-based access control (RBAC), birth right application/groups and nested group strategies.
- You will automate identity operations and administration using scripting (eg. Python, PowerShell) and platform APIs (Microsoft Graph).
- You will support a hybrid multi-forest Microsoft AD infrastructure, including Windows Server domain controllers and PKI infrastructure, and Entra administration.
- You will maintain the identity security posture-identifying and remediating over-privileged access, orphaned accounts, and configuration drift.
Qualifications: - 10+ years of IT experience, with 5+ years specializing in Identity & Access Management.
- Deep, hands-on expertise with Microsoft Entra ID - Conditional Access, application registrations, enterprise applications, dynamic groups, and identity governance features.
- Expert understanding of core IAM protocols: SAML 2.0, OpenID Connect, OAuth 2.0, and SCIM, as well as FIDO2.
- Practical experience implementing Zero Trust architectures and passwordless/phishing-resistant authentication.
- Scripting and automation ability (Python and/or PowerShell) using platform APIs.
- 3+ years experience administrating cloud infrastructure in AWS or Azure. (Including familiarity with infrastructure as code, Azure Virtual Desktop, Azure Hybrid AD join, AWS ALB and Route 53, IAM roles, KMS and Certificate manager)
- Experience administrating Microsoft Windows Server / Active Directory, PKI and related technologies.
- Familiarity with enterprise networking concepts including firewalls, application proxies, load balancers, VPN, the TCP/IP protocol, and other enterprise network technologies.
- Bachelor's degree in computer science or information technology with Microsoft SC-300 (Identity & Access Administrator); or equivalent practical experience.
Pay Transparency - North AmericaCOMPENSATION AND BENEFITS The ranges listed below are what EA in good faith expects to pay applicants for this role in these locations at the time of this posting. If you reside in a different location, a recruiter will advise on the applicable range and benefits. Pay offered will be determined based on a number of relevant business and candidate factors (e.g. education, qualifications, certifications, experience, skills, geographic location, or business needs).
PAY RANGES* British Columbia (depending on location e.g. Vancouver vs. Victoria) *$122,300 - $170,700 CAD
Pay is just one part of the overall compensation at EA.
For Canada, we offer a package of benefits including vacation (3 weeks per year to start), 10 days per year of sick time, paid top-up to EI/QPIP benefits up to 100% of base salary when you welcome a new child (12 weeks for maternity, and 4 weeks for parental/adoption leave), extended health/dental/vision coverage, life insurance, disability insurance, retirement plan to regular full-time employees. Certain roles may also be eligible for bonus and other incentive programs.
Post To
External careers site, Internal careers site
LinkedInID
1449