{"id":1153044,"url":"https://alion.io/job/t-rowe-price-lead-infrastructure-engineer-iam","title":"Lead Infrastructure Engineer, IAM","company":{"id":704268,"name":"T. Rowe Price","domain":"troweprice.com","url":"https://alion.io/company/t-rowe-price","size_band":"1001-5000","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Workday","truth_index":{"grade":"B","score":78,"open_postings":9,"ghost_share":0,"stale_share":0.889,"repost_share":0,"time_to_fill_p50_days":43,"computed_at":"2026-09-23T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Owings Mills, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":122000,"max":209000,"currency":"USD","period":"year","gross":null,"usd_annual":209000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"DNS","optional":false},{"name":"IAM","optional":false},{"name":"LDAP","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"PKI","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-23T18:54:58Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T03:18:31Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"At T. Rowe Price, we identifyand actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.\nWe believe doing the right thing for our clients and our associates is good business.With a career at the firm, you can expect opportunities to create real impact at workand in your community. You’llenjoy resources to support your career path, as well ascompensation, benefits,and flexibility to enrich your life. Here, you’llfind acollaborative culture that respectsand valuesdifferencesand colleagues who share a spirit of generosity.\nJoin us for the opportunity togrow and make a difference in ways that matter to you.\nRole Summary\nThis is a highly visible senior-level individual contributor leadership role where you will influence the strategic direction of Identity and Access Management across a global, highly regulated organization. As a trusted technical leader, you will drive the evolution of our identity ecosystem, transforming legacy, Active Directory-centric architectures into a modern, cloud-first identity platform built on Zero Trust principles. You will lead the design and advancement of next-generation identity capabilities across Microsoft Entra ID, AWS IAM Identity Center, federation, privileged access management (PAM), conditional access, PKI/certificate services, identity automation, and cloud-native security controls. Working across infrastructure, security, and application teams, you will establish the technical vision, architecture, and roadmap for enterprise identity services that secure thousands of users, applications, and critical business systems.\nIn this role, you will serve as a senior technical authority, providing deep expertise, strategic influence, and hands-on guidance without direct people management responsibilities. Partnering closely with security, infrastructure, cloud, application, audit, operations, and architecture teams, you will define enterprise standards, assess and mitigate risk, guide critical engineering decisions, and mentor technical talent across the organization. Success in this position requires the ability to balance long-term architectural vision with practical execution, ensuring identity capabilities are secure, resilient, scalable, and aligned with both business objectives and evolving regulatory requirements.\nResponsibilities\nDefine and advance the enterprise IAM technology strategy, roadmap, standards, and reference patterns for modern identity services across hybrid Active Directory, Microsoft Entra ID, and AWS environments.\nLead complex IAM modernization efforts, including migration from legacy AD, ADFS, MIM, LDAP, and directory service patterns to cloud-based authentication, authorization, lifecycle, and access governance models.\nServe as an authoritative technical advisor for identity architecture decisions, including federation, conditional access, privileged access, identity protection, cross-tenant access, B2B/B2C identity, entitlement management, and certificate-based authentication.\nPartner with cloud, infrastructure, security, audit, risk, and application teams to design secure and scalable access models for AWS, Microsoft, SaaS, and enterprise application ecosystems.\nDrive adoption of Zero Trust, least privilege, adaptive access, JIT access, risk-based authentication, and modern MFA capabilities across enterprise platforms.\nEstablish and maintain IAM standards, design patterns, engineering guardrails, operational procedures, and compliance reporting practices.\nProvide hands-on technical leadership for complex troubleshooting across Kerberos, SPNs, delegation, certificates, federation, conditional access, MFA, SAML assertions, OAuth flows, DNS, and network authentication dependencies.\nMentor engineers and technical leaders through design reviews, troubleshooting sessions, knowledge sharing, and standards-based engineering practices.\nAssess security risks and technical debt within IAM platforms and define remediation plans that improve resiliency, auditability, and operational effectiveness.\nInfluence senior stakeholders and cross-functional teams through clear communication, pragmatic decision-making, and enterprise-level technical judgment.\nQualifications\nRequired:\n8+ years of experience designing, implementing, operating, or modernizing IAM capabilities in a large enterprise environment.\nDeep hands-on expertise with hybrid identity architectures spanning Active Directory, Microsoft Entra ID, federation, privileged access management, and cloud authentication models.\nDemonstrated ability to independently lead complex technical initiatives.\nStrong understanding of security controls, access governance, audit requirements, and operational risk management in regulated environments.\nProven ability to create standards, influence architecture decisions, and mentor engineering teams.\nStrong troubleshooting skills across identity, directory, certificate, authentication, federation, cloud, DNS, and network dependencies.\nPreferred:\nExperience modernizing identity capabilities as part of a broader cloud, data center exit, endpoint modernization, or platform transformation program.\nExperience integrating identity patterns into AWS-based application and infrastructure platforms.\nExperience with certificate lifecycle management, PKI modernization, passwordless authentication, and Zero Trust adoption.\nExperience defining enterprise IAM roadmaps, control frameworks, engineering standards, or capability maturity plans.\nRelevant Microsoft, AWS, security, or identity-focused certifications are beneficial but not required.\nFINRA Requirements\nFINRA licenses are not required and will not be supported for this role.\nWork Flexibility\nThis role is eligible for hybrid work, with up to three days per week from home.\nBase Salary Ranges\nPlease review the job posting for the location of this specific opportunity.\n$122,000.00 - $209,000.00 for the location of: Maryland, Colorado, Washington and remote workers$135,000.00 - $230,000.00 for the location of: Washington, D.C.\n$153,000.00 - $261,000.00 for the location of: New York, California\nPlacement within the range provided above is based on the individual’s relevant experience and skills for the role. Base salary is only one componentof our total compensation package. Employees may be eligible for a discretionary bonus, which is determinedupon company and individual performance.\nCommitment to Diversity, Equity,andInclusion\nAt T. Rowe Price, our associates are our greatest asset. We thrive because our company culture is built on inclusion and because we sustain a work environment where associates can bring their best selves to work every day. The backgrounds, talents, and experiences of our global associates allow us to embrace new ideasand perspectives that move our business priorities forward and enable us to deliver strong client outcomes. Here, you can expect equal opportunity and fair and consistent treatment for all.\nBenefits\nWe value your goals and needs, at work and in life. As an associate, you’llbe supported with resources, benefits, and work-life balanceso you canthrive in ways that matter to you.\nFeatured employee benefits to enrich your life:\nCompetitive compensation\n\nAnnual bonus eligibility\n\nA generous retirement plan\n\nHybrid work schedule\n\nHealth and wellness benefits, including online therapy\n\nPaid time off for vacation, illness, medical appointments, and volunteering days\n\nFamily care resources, including fertility and adoption benefits\n\nLearn more about our benefits.\nT. Rowe Price is an equal opportunity employer and values diversity of thought, gender, and race. We believe our continued success depends upon the equal treatment of all associates and applicants for employment without discrimination on the basis of race, religion, creed, color, national origin, sex, gender, age, mental or physical disability, marital status, sexual orientation, gender identity or expression, citizenship status, military or veteran status, pregnancy, or any other classification protected by country, federal, state, or local law.","description_format":"text","description_chars":8487,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Hybrid work","Retirement plans"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services","Asset Management"],"lifecycle":[{"event":"open","at":"2026-09-23T18:54:58Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":43,"reasons":["conf:7","win:early","comp:brand"],"computed_at":"2026-09-24T02:08:33Z"},"pay":{"stated_usd_annual":209000,"is_top_pay":true},"html_url":"https://alion.io/job/t-rowe-price-lead-infrastructure-engineer-iam","json_url":"https://alion.io/job/t-rowe-price-lead-infrastructure-engineer-iam.json","meta":{"generated_at":"2026-09-24T02:08:33Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}