Senior Security Engineer - Identity and Access Management
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - Identity and Access Management based in Canada.
This is a senior cybersecurity role focused on building and advancing a modern Identity and Access Management (IAM) program within a fully cloud-native environment. You will help shape secure, scalable, and frictionless access across cloud infrastructure, SaaS applications, developer environments, and business systems. The role spans identity governance, privileged access, authentication, secrets management, and certificate lifecycle management. You will also contribute to securing AI/ML environments, including access to training data, models, and inference services. Working closely with Security, DevOps, and Infrastructure teams, you will influence architecture and embed identity controls throughout the engineering lifecycle. This is an opportunity to combine hands-on technical delivery, automation, strategic thinking, and technical leadership in a high-impact security environment.
Accountabilities
- Develop and implement robust IAM strategies aligned with cloud-native security principles, zero-trust architecture, and least-privilege access.
- Build and mature capabilities across Identity Governance and Administration (IGA), Privileged Access Management (PAM), SSO, MFA, access management, secrets management, and certificate lifecycle management.
- Design and maintain IAM integrations across AWS services, SaaS platforms, third-party identity solutions, and developer or DevOps environments.
- Automate identity provisioning, de-provisioning, access reviews, and related IAM operations using scripting, infrastructure-as-code, and AI-enabled tools.
- Establish secure access controls for cloud-native workloads and AI/ML systems, including training data, models, and inference APIs.
- Integrate IAM controls into CI/CD pipelines, secrets management processes, and broader engineering workflows.
- Partner with Security, DevOps, Infrastructure, and other cross-functional teams to embed secure identity practices across the technology lifecycle.
- Mentor junior engineers and provide technical leadership on IAM initiatives, architecture, and implementation decisions.
- Monitor emerging identity and cloud security threats, compliance requirements, and industry practices to continuously improve the IAM strategy.
- 8+ years of relevant professional experience with a Bachelor's degree, 5+ years with a Master's degree, 3+ years with a PhD, or an equivalent combination of education and experience.
- Strong hands-on experience with IAM platforms such as Okta, CyberArk, Ping, or SailPoint.
- Deep knowledge of IAM in cloud-native environments, particularly AWS IAM, roles, policies, permissions boundaries, federation, and access controls.
- Strong proficiency with infrastructure-as-code technologies such as Terraform or CloudFormation.
- Practical knowledge of authentication and authorization protocols including SAML, OAuth 2.0, OpenID Connect, and Kerberos.
- Experience with directory services such as Active Directory and LDAP, as well as modern cloud-based alternatives.
- Strong scripting and automation capabilities using technologies such as Python or PowerShell.
- Experience integrating IAM into CI/CD pipelines, DevOps workflows, secrets management, and cloud environments.
- Solid understanding of security and compliance frameworks such as NIST, SOC 2, and PCI DSS.
- Strong communication, collaboration, and influencing skills, with the ability to lead cross-functional initiatives and communicate complex security concepts effectively.
- Ability to mentor others, work independently, make sound technical decisions, and balance security requirements with business and engineering needs.
- Relevant certifications such as CISSP, CISM, CIAM/CAMS, CyberArk, or Okta credentials are considered an asset.
- Experience with AWS services such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, and AWS developer tooling is a plus.
- Competitive base salary of CAD $136,800–$171,000, calibrated according to location, skills, experience, and other job-related factors.
- Annual bonus opportunities based on individual performance and overall organizational results.
- Multiple health insurance options.
- Flexible vacation time plus additional floating holidays.
- Retirement savings program with company contributions.
- Equity participation in a publicly traded organization.
- Monthly stipend to support remote work.
- Annual professional development stipend to support learning and career growth.
- Family-forming benefits and generous parental leave, including base salary top-up.
- Flexible-first remote work environment available across Canada, with this role specifically supporting employees in Ontario or British Columbia.
- Inclusive workplace committed to equal opportunity, belonging, and diverse perspectives.
Requirements
Benefits
Skills mentioned
- Active Directory
- AI
- Aurora
- Authentication
- Automation
- AWS
- CAD
- CI Cd
- Cism
- Cissp
- Cloud
- Cloud Native
- Cloudformation
- Cloudwatch
- Cyberark
- Cybersecurity
- DEVOPS
- Dynamodb
- Gdpr
- IAM
- Infrastructure As Code
- Lambda
- Ldap
- Machine Learning
- Nist
- Oauth
- Okta
- Openid
- PCI Dss
- Powershell
- Python
- Rds
- Regulatory Compliance
- SAAS
- Saml
- Secrets Management
- Sns
- SOC 2
- Sqs
- Terraform

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.
Apply for this job
Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.
