Systems Engineer, Lead Consultant Identity & Authentication - Remote -

Allstatecanada — Canada · Posted ~2 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description Who is Allstate: Allstate Insurance Company of Canada is a leading home and auto insurer focused on providing its customers prevention and protection products and services for every stage of life. Serving Canadians since 1953, Allstate strives to reassure both customers and employees with its “You’re in Good Hands®” promise and is proud to have been named a Best Employer in Canada for nine consecutive years. Allstate is committed to making a positive difference in the communities in which it operates through partnerships with charitable organizations, employee giving and volunteerism. To learn more, visit www.allstate.ca. For safety tips and advice, visit www.goodhandsadvice.ca. Through our Employee Value Proposition, we have worked hard to develop and nurture a culture where employees feel valued, experience personal growth, have career options and truly enjoy the work they do. Role Designation: Remote Benefits To Joining Allstate Flexible Work Arrangements. Employee discounts (15% on auto and property insurance, plus many other products and services). Good Office program (receive up to $400 back after purchasing office equipment). Student Loan Payment Matching Program for Government Student loans. Comprehensive Retirement Savings Program with employer matched contributions. Annual Wellness allowance to support employees with improving health and wellbeing. Personal days. Tuition Reimbursement. Working within the community and giving back. Job description: The Systems Engineer, Lead Consultant Identity & Authentication leads and initiates efforts to research, design, plan and maintain new or existing network hardware and software technology components. The consultant utilizes systems, scripting, and developer skills to execute tasks related to analysis, integration, and moderately to highly complex incidents and problems affecting production systems and multiple applications. This role also helps define and update items in the configuration management plan. Accountabilities: Lead identifying and recommending major and significant changes for moderately complex network hardware and software technology components for purposes of incident avoidance. Resolve incidents and perform root cause analysis, escalating high complexity incidents and problems to provide future application, hardware and/or software resiliency. Lead efforts to ensure plans integrate effectively with other aspects of the technical hardware and software components. Lead the support for production service requests, performing routine administration, and supporting moderately complex network hardware and software infrastructure (i.e., Request Center, Change Order execution). Lead the effort to develop and maintain tools for the use of maintaining, modifying, and monitoring hardware and software technology components. Lead implementation of moderately complex network hardware and software technology components by analyzing the current system environment and infrastructure, using technical tools and utilities, and performing complex product customizations. Lead execution of testing, debugging, performance analysis, and documenting moderately complex hardware and software technology components. Collaborate to build consensus with other Engineers to ensure that the modified hardware and software infrastructure interacts appropriately, data conversion impacts are considered, and other areas of impact are addressed and meet business function and performance requirements. Lead and initiate the completion of the following activities (concerning moderately complex new network hardware and software technology components or enhancements to existing components): research, analysis, design, selection, planning, and engineering. Qualifications: 5+ years of experience designing, implementing, and supporting enterprise Identity and Access Management (IAM) solutions in complex hybrid environments. Advanced experience with Active Directory Domain Services (ADDS), Active Directory Federation Services (ADFS), Microsoft Entra ID, Active Directory Certificate Services (ADCS), and Hybrid Identity. Strong proficiency in PowerShell scripting, automation, APIs, Infrastructure as Code (IaC), and modern engineering practices. Experience with authentication and federation technologies including LDAP, Kerberos, SAML, OAuth, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. Experience administering and supporting Group Policy (GPO), Domain Name System (DNS), Windows Server Update Services (WSUS), and System Center Operations Manager (SCOM) in enterprise environments. Knowledge of identity security, Zero Trust principles, and identity governance. Strong analytical, troubleshooting, and problem-solving skills. Experience leading technical initiatives, mentoring engineers, and providing technical guidance across cross-functional teams. Bonus Qualifications: Experience with privileged access management, certificate lifecycle management, or cloud identity platforms. Experience with GitHub, CI/CD pipelines, Infrastructure as Code, and automation frameworks. Familiarity with AI-assisted development, intelligent automation, operational analytics, or emerging AI technologies. Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Certified: Azure Administrator Associate (AZ-104) Microsoft Certified: Azure Security Engineer Associate (AZ-500) Microsoft Certified: Cybersecurity Architect Expert (SC-100) Supervisory Responsibilities This job does not have supervisory duties. If you are applying for a position open to candidates across Canada, unless otherwise indicated, strong English communication skills are required, as the role involves regular interaction with clients, advisors, or employees across the country. Allstate Canada Group has policies and practices that provide workplace accommodations. If you require accommodation, please let us know and we will work with you to meet your needs. À propos d’Allstate : Allstate du Canada, compagnie d’assurance est un chef de file dans le domaine des assurances automobile et habitation; elle offre à ses clients des produits et services de prévention et de protection qui conviennent à toutes les étapes de la vie. Au service des Canadiens depuis 1953, l’entreprise met tout en œuvre pour que non seulement ses clients, mais aussi ses employés soient en bonnes mainsMD, comme en fait foi sa présence au palmarès des Employeurs de choix au Canada pendant neuf années de suite. Allstate du Canada tient à contribuer au mieux-être des communautés dans lesquelles elle exerce ses activités au moyen de partenariats avec des organismes caritatifs et de programmes misant sur la générosité de ses employés. Pour en savoir plus, visitez le www.allstate.ca. Pour connaître nos conseils en matière de sécurité, consultez le blogue Allstate Assurance au blogue.allstate.ca. À Allstate, nous avons conscience que la qualité de nos produits découle directement du niveau de satisfaction du personnel à l’égard de l’entreprise. C’est pourquoi nous misons sur le maintien d’une culture où les employés se sentent valorisés et où ils peuvent poursuivre une carrière passionnante. Notre proposition de valeur aux employés permet ainsi de s’épanouir de façon unique. Désignation du rôle : télétravail Les avantages offerts par Allstate La flexibilité des modalités de travail; Des rabais d’employé (15 % sur les assurances automobile et habitation, ainsi que des rabais sur de nombreux autres produits et services); Le programme Bureau en bonnes mains (jusqu’à 400 $ sont octroyés pour se procurer de l’équipement de bureau nécessaire à domicile); Un programme de paiement de contrepartie pour le remboursement des prêts étudiants aux programmes gouvernementaux; Un régime d’épargne-retraite complet prévoyant des cotisations de contrepartie de l’employeur; Une allocation annuelle couvrant des dépenses effectuées pour améliorer sa santé et son bien-être; Des congés personnels; Le remboursement de droits de scolarité; Une implication dans la vie communautaire. Description du poste : Le ou la titulaire du poste de conseiller(ère) en chef et ingénieur en systèmes de gestion des identités et d’authentification dirige et amorce les efforts de recherche, de conception, de planification et d’entretien des composants nouveaux ou existants de la technologie et des logiciels réseau. Cette personne met à profit ses compétences en systèmes, en rédaction de scripts et en développement afin d’exécuter des tâches d’analyse et d’intégration ainsi que de traiter des incidents et des problèmes de complexité moyenne à élevée touchant les systèmes de production et plusieurs applications. Le ou la titulaire de ce poste contribue également à définir et à mettre à jour les éléments du plan de gestion de la configuration. Responsabilités : Diriger la détermination et la recommandation de changements majeurs et importants aux composants technologiques de complexité moyenne liés au matériel et aux logiciels réseau afin de prévenir les incidents. Résoudre les incidents qui surviennent et effectuer des analyses des causes profondes; communiquer les incidents et les problèmes très complexes aux échelons supérieurs afin d’améliorer la résilience future des applications, du matériel ou des logiciels. Diriger les efforts visant à assurer l’intégration efficace des plans aux autres aspects des composants techniques matériels et logiciels. Diriger le soutien des demandes de service en production, effectuer les tâches d’administration courantes et soutenir l’infrastructure matérielle et logicielle réseau de complexité moyenne (p. ex., Centre de demandes, exécution des demandes de changement). Diriger les efforts de développement et de maintenance des outils servant à entretenir, à modifier et à surveiller les composants technologiques matériels et logiciels. Diriger la mise en œuvre de composants technologiques de complexité moyenne liés au matériel et aux logiciels réseau en analysant l’environnement système et l’infrastructure actuels, en utilisant des outils et des services techniques et en effectuant des personnalisations complexes de produits. Diriger l’exécution des essais, du débogage, des analyses de rendement et de la documentation des composants technologiques matériels et logiciels de complexité moyenne. Collaborer avec les autres ingénieurs afin de dégager un consensus et de veiller à ce que l’infrastructure matérielle et logicielle modifiée interagisse adéquatement, que les répercussions de la conversion des données soient prises en compte et que les autres secteurs touchés soient traités, tout en répondant aux exigences fonctionnelles et de rendement de l’entreprise. Diriger et lancer la réalisation des activités suivantes relativement à de nouveaux composants technologiques de complexité moyenne liés au matériel et aux logiciels réseau, ou à l’amélioration de composants existants : recherche, analyse, conception, sélection, planification et ingénierie. Exigences : Au moins cinq ans d’expérience dans la conception, la mise en œuvre et le soutien de solutions d’entreprise de gestion des identités et des accès (GIA) dans des environnements hybrides complexes. Expérience avancée des services de domaine Active Directory (ADDS), des services de fédération Active Directory (ADFS), de Microsoft Entra ID, des services de certificats Active Directory (ADCS) et de l’identité hybride. Excellente maîtrise des scripts PowerShell, de l’automatisation, des API, de l’infrastructure en tant que code (IaC) et des pratiques modernes d’ingénierie. Expérience des technologies d’authentification et de fédération, notamment LDAP, Kerberos, SAML, OAuth, OpenID Connect (OIDC), WS-Federation et l’authentification par certificat. Expérience de l’administration et du soutien de la stratégie de groupe (GPO), du système de noms de domaine (DNS), des services WSUS (Windows Server Update Services) et de System Center Operations Manager (SCOM) dans des environnements d’entreprise. Connaissance de la sécurité des identités, des principes de confiance zéro et de la gouvernance des identités. Solides compétences en analyse, en dépannage et en résolution de problèmes. Expérience de la direction de projets techniques, du mentorat d’ingénieurs et de la prestation de conseils techniques auprès d’équipes interfonctionnelles. Atouts : Expérience de la gestion des accès privilégiés, de la gestion du cycle de vie des certificats ou des plateformes d’identité infonuagiques. Expérience de GitHub, des pipelines d’intégration et de déploiement continus (CI/CD), de l’infrastructure en tant que code et des cadres d’automatisation. Connaissance du développement assisté par l’IA, de l’automatisation intelligente, de l’analytique opérationnelle ou des technologies d’IA émergentes. Certification Microsoft : Administrateur des identités et des accès associé (SC-300) Certification Microsoft : Administrateur Azure associé (AZ-104) Certification Microsoft : Ingénieur en sécurité Azure associé (AZ-500) Certification Microsoft : Expert en architecture de cybersécurité (SC-100) Responsabilités de supervision Ce poste ne comporte pas des tâches de supervision. Si vous postulez pour un poste ouvert aux candidats provenant de différentes provinces canadiennes, sauf indication contraire, la maîtrise de l’anglais est requise, car ce poste exige une communication régulière avec les clients, les conseillers ou les employés à l’échelle nationale. Le Groupe Allstate du Canada dispose de politiques et de pratiques permettant d’offrir des mesures d’adaptation en milieu de travail. Si nécessaire, nous établirons avec vous les mesures qui doivent être prises pour répondre à vos besoins. Compétences Gestion des accès, gestion des accès, Active Directory (AD), services de domaine Active Directory (AD DS), services de fédération Active Directory (AD FS), pensée analytique, authentification, automatisation, cadres d’automatisation, services de certificats, identité infonuagique, collaboration, réseaux complexes, débogage, conception, reprise après sinistre (DR), système de noms de domaine (DNS), services de domaine, gestion des identités et des accès (GIA), gouvernance des identités, infrastructure en tant que code (IaC), automatisation intelligente (IA), Microsoft Hyper-V Server, administration de Microsoft Server, suite Microsoft System Center Skills Access Management, Active Directory (AD), Active Directory Domain Services (AD DS), Active Directory Federation Services (AD FS), Analytical Thinking, Authentication, Automation, Certificate Services, Cloud Identity, Collaboration, Complex Network, Debugging, Design, Disaster Recovery (DR), Domain Name System (DNS), Domain Services, Identity Access Management (IAM), Identity Governance, Infrastructure As Code (IaC), Intelligent Automation (IA), Microsoft Hyper-V Server, Microsoft Server Administration, Microsoft System Center Suite, Software Development Compensation Expected compensation for this role ranges from $ 93,500.00 - 143,500.00 annually. Actual salary offered to successful candidates will vary based on their skills and experience. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate Canada Group uses AI technology tools to assist in screening, selecting, assessing, and scheduling interviews with candidates as part of the recruitment process. This job posting is for a current open role within the organization.