This job is closed
Applications are no longer available for this announcement. Explore current related opportunities below.
Job description
At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.
We believe doing the right thing for our clients and our associates is good business . With a career at the firm, y ou can expect opportunities to create real impact at work and in your community. Y ou'll enjoy resources to support your career path, a s well as compensation , benefits , and flexibility to enrich your life. Here, you'll find a collaborative culture that respect s and valu e s differences and colleagues who share a spirit of generosity .
Join us for the opportunity to g row and make a difference in ways that matter to you .
Role Summary
This is a highly visible senior-level individual contributor leadership role where you will influence the strategic direction of Identity and Access Management across a global, highly regulated organization. As a trusted technical leader, you will drive the evolution of our identity ecosystem, transforming legacy, Active Directory-centric architectures into a modern, cloud-first identity platform built on Zero Trust principles. You will lead the design and advancement of next‑generation identity capabilities across Microsoft Entra ID, AWS IAM Identity Center, federation, privileged access management (PAM), conditional access, PKI/certificate services, identity automation, and cloud‑native security controls. Working across infrastructure, security, and application teams, you will establish the technical vision, architecture, and roadmap for enterprise identity services that secure thousands of users, applications, and critical business systems.
In this role, you will serve as a senior technical authority, providing deep expertise, strategic influence, and hands‑on guidance without direct people management responsibilities. Partnering closely with security, infrastructure, cloud, application, audit, operations, and architecture teams, you will define enterprise standards, assess and mitigate risk, guide critical engineering decisions, and mentor technical talent across the organization. Success in this position requires the ability to balance long‑term architectural vision with practical execution, ensuring identity capabilities are secure, resilient, scalable, and aligned with both business objectives and evolving regulatory requirements.
Responsibilities
Define and advance the enterprise IAM technology strategy, roadmap, standards, and reference patterns for modern identity services across hybrid Active Directory, Microsoft Entra ID, and AWS environments.
Lead complex IAM modernization efforts, including migration from legacy AD, ADFS, MIM, LDAP, and directory service patterns to cloud‑based authentication, authorization, lifecycle, and access governance models.
Serve as an authoritative technical advisor for identity architecture decisions, including federation, conditional access, privileged access, identity protection, cross‑tenant access, B2B/B2C identity, entitlement management, and certificate‑based authentication.
Partner with cloud, infrastructure, security, audit, risk, and application teams to design secure and scalable access models for AWS, Microsoft, SaaS, and enterprise application ecosystems.
Drive adoption of Zero Trust, least privilege, adaptive access, JIT access, risk‑based authentication, and modern MFA capabilities across enterprise platforms.
Establish and maintain IAM standards, design patterns, engineering guardrails, operational procedures, and compliance reporting practices.
Provide hands‑on technical leadership for complex troubleshooting across Kerberos, SPNs, delegation, certificates, federation, conditional access, MFA, SAML assertions, OAuth flows, DNS, and network authentication dependencies.
Mentor engineers and technical leaders through design reviews, troubleshooting sessions, knowledge sharing, and standards‑based engineering practices.
Assess security risks and technical debt within IAM platforms and define remediation plans that improve resiliency, auditability, and operational effectiveness.
Influence senior stakeholders and cross‑functional teams through clear communication, pragmatic decision‑making, and enterprise‑level technical judgment .
Qualifications
Required:
8+ years of experience designing, implementing, operating, or modernizing IAM capabilities in a large enterprise environment.
Deep hands‑on expertise with hybrid identity architectures spanning Active Directory, Microsoft Entra ID, federation, privileged…
Demonstrated ability to indep
#J-18808-Ljbffr
Worksite address
owings mills, MD, 21117, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.