Confirmed on the employer's own hiring board on Sep 23, 2026. First seen by Alion on Sep 23, 2026. T. Rowe Price scores B on the Alion truth index.
At T. Rowe Price, we identifyand actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.
We believe doing the right thing for our clients and our associates is good business.With a career at the firm, you can expect opportunities to create real impact at workand in your community. You’llenjoy resources to support your career path, as well ascompensation, benefits,and flexibility to enrich your life. Here, you’llfind acollaborative culture that respectsand valuesdifferencesand colleagues who share a spirit of generosity.
Join us for the opportunity togrow and make a difference in ways that matter to you.
Role Summary
This is a highly visible senior-level individual contributor leadership role where you will influence the strategic direction of Identity and Access Management across a global, highly regulated organization. As a trusted technical leader, you will drive the evolution of our identity ecosystem, transforming legacy, Active Directory-centric architectures into a modern, cloud-first identity platform built on Zero Trust principles. You will lead the design and advancement of next-generation identity capabilities across Microsoft Entra ID, AWS IAM Identity Center, federation, privileged access management (PAM), conditional access, PKI/certificate services, identity automation, and cloud-native security controls. Working across infrastructure, security, and application teams, you will establish the technical vision, architecture, and roadmap for enterprise identity services that secure thousands of users, applications, and critical business systems.
In this role, you will serve as a senior technical authority, providing deep expertise, strategic influence, and hands-on guidance without direct people management responsibilities. Partnering closely with security, infrastructure, cloud, application, audit, operations, and architecture teams, you will define enterprise standards, assess and mitigate risk, guide critical engineering decisions, and mentor technical talent across the organization. Success in this position requires the ability to balance long-term architectural vision with practical execution, ensuring identity capabilities are secure, resilient, scalable, and aligned with both business objectives and evolving regulatory requirements.
Responsibilities
- Define and advance the enterprise IAM technology strategy, roadmap, standards, and reference patterns for modern identity services across hybrid Active Directory, Microsoft Entra ID, and AWS environments.
- Lead complex IAM modernization efforts, including migration from legacy AD, ADFS, MIM, LDAP, and directory service patterns to cloud-based authentication, authorization, lifecycle, and access governance models.
- Serve as an authoritative technical advisor for identity architecture decisions, including federation, conditional access, privileged access, identity protection, cross-tenant access, B2B/B2C identity, entitlement management, and certificate-based authentication.
- Partner with cloud, infrastructure, security, audit, risk, and application teams to design secure and scalable access models for AWS, Microsoft, SaaS, and enterprise application ecosystems.
- Drive adoption of Zero Trust, least privilege, adaptive access, JIT access, risk-based authentication, and modern MFA capabilities across enterprise platforms.
- Establish and maintain IAM standards, design patterns, engineering guardrails, operational procedures, and compliance reporting practices.
- Provide hands-on technical leadership for complex troubleshooting across Kerberos, SPNs, delegation, certificates, federation, conditional access, MFA, SAML assertions, OAuth flows, DNS, and network authentication dependencies.
- Mentor engineers and technical leaders through design reviews, troubleshooting sessions, knowledge sharing, and standards-based engineering practices.
- Assess security risks and technical debt within IAM platforms and define remediation plans that improve resiliency, auditability, and operational effectiveness.
- Influence senior stakeholders and cross-functional teams through clear communication, pragmatic decision-making, and enterprise-level technical judgment.
Qualifications
Required:
- 8+ years of experience designing, implementing, operating, or modernizing IAM capabilities in a large enterprise environment.
- Deep hands-on expertise with hybrid identity architectures spanning Active Directory, Microsoft Entra ID, federation, privileged access management, and cloud authentication models.
- Demonstrated ability to independently lead complex technical initiatives.
- Strong understanding of security controls, access governance, audit requirements, and operational risk management in regulated environments.
- Proven ability to create standards, influence architecture decisions, and mentor engineering teams.
- Strong troubleshooting skills across identity, directory, certificate, authentication, federation, cloud, DNS, and network dependencies.
Preferred:
- Experience modernizing identity capabilities as part of a broader cloud, data center exit, endpoint modernization, or platform transformation program.
- Experience integrating identity patterns into AWS-based application and infrastructure platforms.
- Experience with certificate lifecycle management, PKI modernization, passwordless authentication, and Zero Trust adoption.
- Experience defining enterprise IAM roadmaps, control frameworks, engineering standards, or capability maturity plans.
- Relevant Microsoft, AWS, security, or identity-focused certifications are beneficial but not required.
FINRA Requirements
FINRA licenses are not required and will not be supported for this role.
Work Flexibility
This role is eligible for hybrid work, with up to three days per week from home.
Base Salary Ranges
Please review the job posting for the location of this specific opportunity.
$122,000.00 - $209,000.00 for the location of: Maryland, Colorado, Washington and remote workers$135,000.00 - $230,000.00 for the location of: Washington, D.C.
$153,000.00 - $261,000.00 for the location of: New York, California
Placement within the range provided above is based on the individual’s relevant experience and skills for the role. Base salary is only one componentof our total compensation package. Employees may be eligible for a discretionary bonus, which is determinedupon company and individual performance.
Commitment to Diversity, Equity,andInclusion
At T. Rowe Price, our associates are our greatest asset. We thrive because our company culture is built on inclusion and because we sustain a work environment where associates can bring their best selves to work every day. The backgrounds, talents, and experiences of our global associates allow us to embrace new ideasand perspectives that move our business priorities forward and enable us to deliver strong client outcomes. Here, you can expect equal opportunity and fair and consistent treatment for all.
Benefits
We value your goals and needs, at work and in life. As an associate, you’llbe supported with resources, benefits, and work-life balanceso you canthrive in ways that matter to you.
Featured employee benefits to enrich your life:
Competitive compensation
Annual bonus eligibility
A generous retirement plan
Hybrid work schedule
Health and wellness benefits, including online therapy
Paid time off for vacation, illness, medical appointments, and volunteering days
Family care resources, including fertility and adoption benefits
Learn more about our benefits.

