Determined, imaginative, curious—if these are some of the ways you describe yourself, we want to learn more about you!
At TC Energy, we are proud to connect the world to the energy it needs. Guided by our values of safety in every step, personal accountability, one team and active learning, we deliver the critical energy that North America and the world rely on while balancing reliability, affordability and sustainability.
The Opportunity
We are seeking a highly experienced Senior Identity Architect to provide strategic and technical leadership for enterprise Identity and Access Management (IAM) capabilities across hybrid and multi-cloud environments. As the senior architect for identity security, you will define enterprise identity architecture standards, reference patterns, and target-state designs that enable secure, seamless access to enterprise resources while supporting business objectives, regulatory requirements, and Zero Trust principles.
In this role, you will leverage deep expertise across Identity Governance and Administration (IGA), Privileged Access Management (PAM), Identity Providers (IdP), Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), Privileged Access Workstations (PAWs), Non-Human Identity (NHI), Identity Threat Detection and Response (ITDR), and emerging Identity for AI capabilities. You will establish identity standards, architectural principles, and governance frameworks while designing scalable, enterprise-level identity solutions that balance security, user experience, operational efficiency, and compliance requirements.
Working closely with security, infrastructure, cloud, application, and enterprise architecture teams, you will assess identity risks, develop practical controls, and design secure access models for complex enterprise ecosystems spanning workforce, third-party, privileged, machine, and AI identities. As a hands-on architect, you will lead architecture workshops, facilitate decision-making among technical and business stakeholders, and provide clear guidance on modern identity strategies and implementation approaches across Azure, AWS, SaaS, on-premises, and hybrid environments.
This role will play a key part in shaping the organization’s long-term identity strategy by partnering with architects, engineers, leadership teams, and business stakeholders to develop future-state architectures and multi-year transformation roadmaps. Success in this role requires strong analytical and problem-solving capabilities, exceptional communication skills, and the ability to influence enterprise technology decisions without direct authority. You will evaluate emerging technologies, identify opportunities for innovation, and incorporate new capabilities into the organization’s identity strategy to strengthen security, improve operational efficiency, and reduce enterprise risk.
This position is ideal for a collaborative and forward-thinking identity leader who brings deep technical credibility, a strategic mindset, and a passion for building secure, scalable identity services that support the evolving needs of the enterprise.
What You'll Do
Define and maintain enterprise identity architecture principles, standards, reference architectures, and design patterns
Design enterprise-scale IAM solutions across hybrid and multi-cloud environments, including Azure and AWS
Lead architecture and design activities across: Identity Governance and Administration (IGA), Privileged Access Management (PAM), Identity Providers (IdP), Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), Privileged Access Workstations (PAWs), Non-Human Identity (NHI), Access Management and Federation, as well as Identity Threat Detection and Response (ITDR)
Develop conceptual, logical, physical, and integration architecture artifacts and diagrams
Create solution architectures, security patterns, and implementation blueprints that align with enterprise security objectives
Design Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Policy-Based Access Control (PBAC) models
Define privileged access strategies including least privilege, Just-in-Time (JIT) access, privileged session controls, and administrative isolation
Design and govern identity controls for employees, contractors, third parties, service accounts, APIs, workloads, and machine identities
Collaborate with enterprise, security, cloud, and application architects to establish secure identity integrations and access models
Partner with internal architecture teams to develop and maintain multi-year IAM and Zero Trust Identity roadmaps
Conduct identity maturity assessments, architecture reviews, technology evaluations, and risk assessments
Provide technical leadership and architectural oversight throughout project lifecycles
Develop executive-level architecture presentations, strategy materials, and business-focused recommendations
Establish identity security controls and architecture requirements supporting regulatory, audit, privacy, and compliance obligations
Define enterprise approaches for Identity Security for AI, including governance of AI agents, machine identities, autonomous workloads, and emerging AI-driven access models
Minimum Requirements
Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline
10+ years of experience in Identity and Access Management, Cybersecurity Architecture, or Enterprise Security Architecture
5+ years of experience in a senior or principal architect role, designing enterprise-scale IAM solutions
Preferred Qualifications
Deep knowledge of: Identity Governance and Administration (IGA), Privileged Access Management (PAM), Identity Providers (IdP), Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), Privileged Access Workstations (PAWs), Identity Federation and Access Management, Non-Human Identity Security Identity Governance, as well as Identity Threat Detection and Response (ITDR)
Strong understanding of cloud identity architectures across Azure and AWS
Experience designing secure identity solutions in hybrid enterprise environments
Experience creating architecture documentation, reference architectures, and executive-level technical presentations
Strong understanding of authentication, authorization, federation, privileged access controls, and identity lifecycle governance, processes and measurement requirements
Knowledge of industry standards and frameworks including: NIST Cybersecurity Framework, NIST SP 800-63 Digital Identity Guidelines, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations NIST 800-207 Zero Trust Architecture, ISO 27001, SOX, SOC2
Demonstrated ability to translate business and security requirements into scalable architectural solutions
Experience developing enterprise Zero Trust Identity strategies and target-state architectures
Experience with Identity Security for AI, including: AI agent identity governance, Workload and machine identity security, Service account governance, API identity management, Autonomous system authorization models, and AI-specific privileged access controls
Experience supporting highly regulated industries and critical infrastructure environments
Experience with Identity Governance transformations and modernization programs
Knowledge of Identity Architecture patterns in large-scale cloud, SaaS, and hybrid ecosystems
Industry certifications such as: CISSP, CCSP, SABSA, TOGAF, Certified Identity and Access Manager (CIAM), Identity and Access certifications Cloud security certifications (AWS and Azure)
Experience establishing IAM capability roadmaps in collaboration with enterprise architecture and security teams
Familiarity with threat modeling, attack path analysis, and identity-focused cyber risk management
Understanding of emerging identity trends, including passwordless authentication, decentralized identity, verifiable credentials, and identity-centric security architectures
To remain competitive, support our high-performance culture and allow for more flexibility in the way we work, we offer a hybrid work model and flexible dress code for our eligible office-based workforce in Canada, the U.S. and Mexico. #LI-Hybrid
About our business
We are a leader in North American energy infrastructure, spanning Canada, the U.S. and Mexico. Every day, our dedicated team proudly connects the world to the energy it needs—moving over 30 per cent of the cleaner-burning natural gas used across the continent. Complemented by strategic ownership and low-risk investments in power generation, our infrastructure fuels industries and generates affordable, reliable and sustainable power across North America, while enabling LNG exports to global markets.
TC Energy is an equal opportunity employer and participates in the E-Verify program supervised by the US government. We welcome applications from all qualified individuals regardless of race, religion, age, sex, color, national origin, sexual orientation, gender identity, veteran status, or disability. We are also committed to providing accommodations throughout the recruitment process. Applicants requiring accommodations or accessible formats are encouraged to contact us at [email protected] for support.
All applicants must have legal authorization to work in the country where the position is based, without restrictions. Background screening is required for all positions, which may include criminal and/or credit checks. Offers may be extended at a different level or job title that best aligns with the successful candidate's qualifications.
Learn more
Visit us at TCEnergy.com and connect with us on our social medial channels for our latest news, employee stories, community activities, and other updates.
Thank you for considering TC Energy in your career journey.
TC Energy Calgary, Alberta, CAN Office
450 1st Street SW, Calgary, Alberta, Canada, T2P 5H1


