Lead Infrastructure Engineer, IAM

T. Rowe Price

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Owings Mills, MD
Salary
$122,000–$209,000 / yr
Employment
Full-time
Posted
4 days ago
Freshness
Confirmed live today

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $190k
This role $166k
$108k most similar roles pay here $249k

This role pays less than 65% of similar roles. Most pay $144,837–$235,750 — the shaded band above. At the midpoint, this role pays about $166k versus about $190k for comparable roles.

Based on 240 similar postings.

Employer

About T. Rowe Price

T. Rowe Price is an asset management firm focused on delivering global investment management excellence and retirement services

T. Rowe Price currently has 29 open roles on FindRole.

Listed pay typically runs $121,000–$206,000 across 29 roles with salary data.

Most-posted roles

View all roles at T. Rowe Price

At a glance

TL;DR · Lead Infrastructure Engineer, IAM

Lead Infrastructure Engineer, IAM is a senior-level individual contributor role focused on driving the strategic direction of Identity and Access Management across a global, highly regulated organization. You will lead the evolution of the identity ecosystem by transforming legacy, Active Directory-centric architectures into modern, cloud-first platforms built on Zero Trust principles. Key responsibilities include designing next-generation capabilities for Microsoft Entra ID, AWS IAM Identity Center, federation, privileged access management, and PKI services. You will collaborate with infrastructure, security, and application teams to establish technical standards, manage identity lifecycle models, and mitigate risks. The role requires deep expertise in Kerberos, SAML, OAuth, and certificate-based authentication. You will serve as a technical authority to ensure secure, scalable access for thousands of users while mentoring engineers through complex troubleshooting and architectural decision-making across hybrid cloud environments.

What you'll do

  • Define and advance the enterprise IAM technology strategy, roadmap, and standards across hybrid Active Directory, Microsoft Entra ID, and AWS environments.
  • Lead the migration of legacy identity systems to modern, cloud-first platforms based on Zero Trust principles.
  • Serve as a technical authority for architecture decisions regarding federation, privileged access management, and certificate services.
  • Design secure and scalable access models for SaaS, enterprise applications, and cloud infrastructure.
  • Drive the adoption of risk-based authentication, least privilege, and modern MFA capabilities across all platforms.
  • Establish engineering guardrails, operational procedures, and compliance reporting practices for identity systems.
  • Provide hands-on technical leadership to troubleshoot complex issues involving Kerberos, SAML, OAuth, and network authentication.
  • Mentor engineers and technical leaders through design reviews and knowledge sharing on standards-based practices.

What we're looking for

  • 8+ years of experience designing, implementing, operating, or modernizing IAM capabilities in a large enterprise environment.
  • Deep hands-on expertise with hybrid identity architectures including Active Directory, Microsoft Entra ID, federation, and privileged access management.
  • Demonstrated ability to independently lead complex technical initiatives.
  • Strong understanding of security controls, access governance, audit requirements, and operational risk management in regulated environments.
  • Proven ability to create standards, influence architecture decisions, and mentor engineering teams.
  • Strong troubleshooting skills across identity, directory, certificate, authentication, federation, cloud, DNS, and network dependencies.
  • Experience modernizing identity capabilities as part of a broader cloud, data center exit, or platform transformation program (preferred).
  • Experience with AWS platforms, PKI modernization, passwordless authentication, Zero Trust, and defining enterprise IAM roadmaps (preferred).

More like this

Similar roles

Principal Security Engineer, Identity and Access Management

Nordstrom

Seattle, WA 27 days ago $191,000–$297,000
IAM Identity Governance Privileged Access Management PAM CIAM SSO OAuth 2.0 OpenID Connect SAML SCIM SPIFFE/SPIRE FIDO2 WebAuthn AWS IAM Azure Entra ID GCP IAM Zero Trust infrastructure-as-code CI/CD Identity Orchestration
10+ yrs exp Hybrid

Cybersecurity Identity Architect

3M

Maplewood, MN +1 40 days ago $221,591–$270,834
IAM SSO MFA Identity Federation IGA SAML OAuth OpenID Connect LDAP Kerberos Azure AD Entra Saviynt CyberArk AWS Azure GCP mTLS SPIFFE SPIRE Zero Trust NIST ISO GDPR HIPAA SOX PCI-DSS
10+ yrs exp

ICAM Architect

Booz Allen Hamilton

McLean, VA 79 days ago $86,800–$198,000
Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Java JavaScript Python PowerShell Groovy RESTful APIs Active Directory LDAP Zero Trust MFA Saviynt Sailpoint Omada Oracle IAM CI/CD AWS Cognito Azure AD B2C Keycloak Google Cloud Identity

Lead Infrastructure Engineer

JPMorgan Chase

Plano, TX 44 days ago
AWS Infrastructure as Code Python Linux Windows SaaS DNS TLS SSO Active Directory SAML OIDC Qlik Sense Tableau ThoughtSpot Sigma Monitoring Telemetry Networking
5+ yrs exp

Lead Infrastructure Engineer

JPMorgan Chase

San Francisco, CA 32 days ago
Cisco Arista Fortinet BGP OSPF VLANs STP LACP Python Infrastructure Engineering Network Migration Automation Scripting Troubleshooting
5+ yrs exp

Lead Infrastructure Engineer

Citi

Irving, TX 23 days ago $125,760–$188,640
Linux Python Bash SQL Ansible Tomcat WebSphere AppDynamics Grafana Dynatrace Active Directory NAS SAN ScaleIO S3 Infrastructure as Code VMware Hyper-V ServiceNow
6+ yrs exp Hybrid