Job Title: Senior Identity and Access Management (IAM) Specialist
Location: Toronto, Ontario (Hybrid; up to 3 days onsite)
Start Date: May 20, 2025
End Date: April 3, 2026
Duration: ~11 months
Role Overview
We are seeking a Senior Identity and Access Management (IAM) Specialist to design, implement, and manage secure access solutions across our enterprise environment. This role is a critical part of our cybersecurity program, focusing on zero trust principles, scalability, and regulatory compliance.
Key Responsibilities
Design and implement an enterprise-wide IAM strategy.
Define and manage identity lifecycle processes (provisioning, de-provisioning, recertification).
Develop and enforce access control policies, including RBAC and ABAC models.
Implement MFA, SSO, and privileged access management (PAM) solutions.
Manage and integrate IAM tools (e.g., Azure AD, Okta) across cloud and on-prem environments.
Conduct access reviews, segregation of duties (SoD) checks, and entitlement audits.
Monitor access-related events, respond to incidents, and remediate vulnerabilities.
Collaborate with internal and external teams to align IAM practices.
Create and maintain documentation (policies, procedures, guidelines).
Support broader cybersecurity governance, compliance, and incident response.
Required Qualifications
7+ years in IAM roles within enterprise environments.
Strong knowledge of IAM principles, protocols (SAML, OAuth2, OpenID Connect), and technologies.
Proven experience with leading IAM platforms (Azure AD, Okta, Ping Identity, ForgeRock, SailPoint, CyberArk).
Experience designing/implementing RBAC, ABAC, and Just-In-Time (JIT) access models.
Familiarity with zero trust architecture.
Knowledge of regulatory standards (NIST 800-63, ISO 27001, SOC 2, CIS).
Experience with IAM risk assessments and audit remediation.
Strong communication and documentation skills.
Ability to work with technical and non-technical stakeholders.
Desirable Qualifications
Bachelor's degree in Computer Science, Information Security, or related field.
Certifications: CIAM, CISSP, CISM (preferred).
Public sector or regulated industry experience (preferred).