Start Date: ASAP
Work Model: Hybrid
Location: Downtown Toronto (outside Union Station – TTC & GO accessible)
Dress Code: Business Casual
A Great Place to Work
Who We Are
Founded in 1993, Kinross is a Canadian-based senior gold mining company with operations and projects in the United States, Brazil, Mauritania, Chile and Canada. Our focus on delivering value is based on our four core values of Putting People First, Outstanding Corporate Citizenship, High Performance Culture, and Rigorous Financial Discipline.
Mining responsibly is a priority for Kinross, and we foster a culture that makes responsible mining and operational success inseparable. Our values-based approach ensures that sustainability and our environmental, social and governance commitments are a core part of our strategy and plans for future growth. In line with our values, we also aim to build meaningful partnerships with all of our stakeholders, including communities, shareholders, employees, governments and suppliers.
Kinross maintains listings on the Toronto Stock Exchange (symbol: K) and the New York Stock Exchange (symbol: KGC).
Job Summary
The IAM Specialist is responsible for the design, implementation, integration, and ongoing operation of the organization’s identity infrastructure, with primary ownership of Active Directory (AD), Microsoft Entra ID (formerly Azure AD), and the enterprise Identity Governance and Administration (IGA) platform. This is a hands-on engineering role that is evolving from operational execution toward strategic oversight: as automation and AI take on routine identity tasks, the engineer increasingly acts as an architect of the organization’s identity fabric — ensuring security, resilience, interoperability, and compliance across hybrid and multi-cloud environments. The successful candidate should be able to understand and manage identity dependencies across infrastructure, cloud platforms, security controls, automations while evaluating the broader impact of identity-related decisions across the enterprise. They will balance deep technical execution (directory services, authentication protocols, governance, automation) with governance, and cross-functional collaboration needed to secure an increasingly autonomous, AI-driven enterprise.
Key Responsibilities
Directory Services (Active Directory & Entra ID)
- Responsible for Active Directory modernization, transformation, and future-state architecture.
- Administer, secure, and optimize on-premises Active Directory (domains, forests, trusts, Group Policy, DNS, sites & services) and Microsoft Entra ID.
- Manage hybrid identity: Entra Connect / Cloud Sync, password hash sync / pass-through authentication, federation, and seamless SSO.
- Design and maintain Conditional Access policies, MFA, Privileged Identity Management (PIM), and Identity Protection.
Identity Governance & Administration (IGA)
- Manage, configure, and continuously improve the enterprise IGA platform (e.g., Saviynt, SailPoint), including connectors, workflows, and integrations with AD, Entra ID, and downstream applications.
- Own the identity lifecycle end to end — provisioning, deprovisioning, and joiner/mover/leaver automation — orchestrated through the IGA platform.
- Design and operate access certification and recertification campaigns, segregation-of-duties (SoD) controls, role-based access control (RBAC), and entitlement management.
- Build and maintain birthright access, access request and approval workflows, and policy-driven provisioning rules.
- Partner with audit, compliance, and application owners to ensure governance controls meet regulatory and internal requirements, and produce evidence for audits.
Authentication, Authorization & Integration
- Configure and troubleshoot SSO and application onboarding across SAML, OIDC, OAuth 2.0, and SCIM.
- Integrate enterprise applications with Entra ID, AD, and the IGA platform; manage service principals, enterprise apps, app registrations, and API permissions.
- Govern machine and workload identities — service accounts, API keys, certificates, and secrets — with appropriate rotation and least-privilege controls.
Automation, Resilience & AI Oversight
- Develop and maintain automation (PowerShell, Microsoft Graph API, IGA connectors/SDKs, infrastructure-as-code) to streamline identity workflows.
- Apply AI/automation tools to routine identity and governance tasks while maintaining human oversight — validating AI-generated configurations and code, and intervening where nuanced judgment is required.
- Conduct resilience and chaos testing of identity systems (e.g., directory outage, MFA bypass scenarios) and lead root-cause analysis during incidents.
Security, Risk & Governance
- Enforce identity security best practices, hardening, and Zero Trust principles across AD, Entra ID, and the IGA platform.
- Support compliance, audit, and regulatory requirements through access certification, logging, and policy enforcement.
- Partner with security operations, DevOps/platform teams, HR, and application owners to embed identity standards across the enterprise.
Qualifications and Skills
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.
- 4+ years of hands-on experience with Active Directory and Microsoft Entra ID in enterprise/hybrid environments.
- Demonstrated experience implementing or operating an enterprise IGA platform (Saviynt, SailPoint, or equivalent) is highly valued.
- Relevant certifications preferred: Microsoft Certified — Identity and Access Administrator (SC-300), Azure Administrator (AZ-104), or vendor IGA certifications (e.g., Saviynt, SailPoint).
Required Technical Skills
- Active Directory: Deep expertise in domains, forests, trusts, Group Policy, DNS, replication, FSMO roles, AD security hardening, and recovery.
- Microsoft Entra ID: Conditional Access, MFA, PIM, Identity Protection, app registrations, enterprise applications, dynamic groups, and licensing.
- Identity Governance & Administration: Hands-on experience administering and integrating an enterprise IGA platform — Saviynt, SailPoint, or equivalent (e.g., One Identity, Microsoft Entra ID Governance) — including connectors, lifecycle workflows, access certifications, RBAC, and SoD controls.
- Hybrid Identity: Entra Connect / Cloud Sync, federation (AD FS or third-party), and hybrid join scenarios.
- Protocols: Strong working knowledge of SAML, OIDC, OAuth 2.0, SCIM, Kerberos, and LDAP — including the ability to troubleshoot complex integration failures.
- Automation & Scripting: PowerShell (advanced), Microsoft Graph API, IGA connector/SDK development, and familiarity with infrastructure-as-code (e.g., Bicep/Terraform).
- Security Fundamentals: Zero Trust, least-privilege, privileged access management, and identity threat detection.
- Emerging / AI-era skills (preferred): AI agent and workload identity governance, human-AI orchestration, identity data modeling, and validation of AI-generated identity configurations.
Required Soft Skills
- Strategic judgment — ability to make sound decisions in high-stakes, ambiguous, and non-routine identity scenarios that automation cannot resolve.
- Cross-functional influence & collaboration — works effectively across security, DevOps, HR, compliance, audit, and application teams; translates technical identity concepts for non-technical stakeholders.
- Problem-solving & root-cause analysis — strong analytical and troubleshooting skills, especially under incident pressure.
- Critical Thinking — Analyzes information objectively, challenges assumptions, and makes well-reasoned decisions based on evidence and sound judgment.
- Design Thinking — Applies a human-centered, creative approach to understand problems, generate innovative.
- Communication — clear written and verbal communication, including technical documentation and stakeholder engagement.
- Adaptability & continuous learning — thrives in a rapidly changing environment; embraces upskilling and AI fluency as the role evolves.
- Ownership & accountability — exercises autonomy, anticipates risk, and follows through on outcomes.
- Ethical reasoning — applies sound judgment to access, trust, and governance decisions in an AI-driven enterprise.
Compensation and Total Rewards
The base salary range for this role is $100,000 to $125,000 CAD plus a target Short-Term Incentive bonus of 20% and group benefit coverage. The hiring range reflects our targeted compensation framework for the role. The actual offer will be determined through a comprehensive evaluation of each candidate’s experience, capabilities, and potential impact, along with consideration of internal equity, team structure, and benchmark market data for similar positions. In addition to base salary, Kinross offers a comprehensive total rewards package designed to support employee well-being, performance, and long-term development.
Use of AI in Our Hiring Process
We use AI-enabled tools to help sort and review applications based on job-related criteria. All hiring decisions, including who moves forward in the process, are made by a human.
Existing Vacancy
This job posting is for an existing vacancy.
