Security Engineer II - Identity and Access Management
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer II - Identity and Access Management based in Canada.
Join a security engineering team focused on building a modern, scalable, and frictionless Identity and Access Management (IAM) program.
You will help secure cloud-native infrastructure, applications, developer workflows, and critical business systems in an AWS-focused environment.
The role combines hands-on engineering, automation, access governance, and privileged access management.
You will play a key part in reducing standing privileges, eliminating manual processes, and strengthening least-privilege controls.
Your work will also contribute to protecting AI/ML systems and securing access to data, models, and inference services.
Collaboration with Security, DevOps, Infrastructure, and engineering teams will be central to your success.
This is a fully remote opportunity available to professionals located in Ontario or British Columbia, Canada.
Accountabilities
- Build and enhance Identity Governance and Administration (IGA) capabilities supporting least-privilege access and audit readiness.
- Implement and operate Privileged Access Management (PAM) solutions for cloud and privileged resources, including just-in-time access.
- Configure and maintain Okta capabilities, including SSO, MFA, lifecycle management, policies, SAML/OIDC integrations, and SCIM provisioning.
- Develop and improve access request, approval, review, and certification workflows through IGA platforms.
- Automate joiner, mover, and leaver processes as well as access reviews using scripting, APIs, and infrastructure-as-code.
- Integrate IAM controls across AWS services, SaaS applications, cloud accounts, and developer/DevOps pipelines.
- Partner with Security, DevOps, Infrastructure, and engineering teams to onboard applications, troubleshoot access issues, and implement secure identity solutions.
- Design and implement identity and access controls for AI/ML environments, helping protect training data, models, and inference APIs.
- Support SOC 2, PCI DSS, and other compliance and audit activities by providing access evidence and improving security controls.
- Maintain documentation, contribute to runbooks, and participate in on-call activities when required.
- At least 3 years of relevant professional experience with a Bachelor’s degree, or 2 years with a Master’s degree, or an equivalent combination of education and experience.
- Hands-on experience with IAM technologies such as Okta, Microsoft Entra ID, CyberArk, Ping, or SailPoint.
- Working knowledge of SAML, OAuth 2.0/OIDC, and SCIM protocols.
- Practical understanding of AWS IAM concepts, including roles, policies, federation, least privilege, and role-based access control (RBAC).
- Hands-on scripting experience with technologies such as Python or PowerShell, particularly for automating IAM operations through APIs.
- Familiarity with directory services including Active Directory, LDAP, and cloud-based identity alternatives.
- Knowledge of security and compliance frameworks such as NIST, SOC 2, and PCI DSS.
- Strong communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders.
- Experience with AWS services such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, and AWS Developer Tools is an asset.
- Familiarity with DevOps practices, CI/CD pipelines, and secrets management is an asset.
- IAM-related certifications, such as CIAM/CAMS, CyberArk certifications, or Okta Certified Consultant, are considered a plus.
- Competitive base salary of CAD 104,000–130,000, calibrated according to location, skills, and experience.
- Annual bonus opportunities for eligible employees based on individual and organizational performance.
- Multiple health insurance options.
- Flexible vacation time plus additional floating holidays.
- Retirement savings program with company contributions.
- Equity participation in a publicly traded company.
- Monthly stipend to support remote work.
- Annual professional development stipend.
- Family-forming benefits.
- Generous parental leave with base salary top-up.
- Fully remote work within Ontario or British Columbia, Canada.
Requirements
Benefits
Skills mentioned
- Active Directory
- AI
- API
- Aurora
- Automation
- AWS
- CAD
- CI Cd
- Cloud
- Cloud Native
- Cloudwatch
- Cyberark
- DEVOPS
- Dynamodb
- Entra Id
- Gdpr
- IAM
- Infrastructure As Code
- Lambda
- Ldap
- Machine Learning
- Nist
- Oauth
- Okta
- PCI Dss
- Powershell
- Python
- Rbac
- Rds
- Regulatory Compliance
- Reporting & Documentation
- SAAS
- Saml
- Scim
- Secrets Management
- Sns
- SOC 2
- Sqs
- Sso
- Troubleshooting

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.
Apply for this job
Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.
