Security Engineer II - Identity and Access Management
JobgetherThis position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer II - Identity and Access Management based in Canada.
Join a security engineering team focused on building a modern, scalable, and frictionless Identity and Access Management (IAM) program.
You will help secure cloud-native infrastructure, applications, developer workflows, and critical business systems in an AWS-focused environment.
The role combines hands-on engineering, automation, access governance, and privileged access management.
You will play a key part in reducing standing privileges, eliminating manual processes, and strengthening least-privilege controls.
Your work will also contribute to protecting AI/ML systems and securing access to data, models, and inference services.
Collaboration with Security, DevOps, Infrastructure, and engineering teams will be central to your success.
This is a fully remote opportunity available to professionals located in Ontario or British Columbia, Canada.
Accountabilities
-
Build and enhance Identity Governance and Administration (IGA) capabilities supporting least-privilege access and audit readiness.
-
Implement and operate Privileged Access Management (PAM) solutions for cloud and privileged resources, including just-in-time access.
-
Configure and maintain Okta capabilities, including SSO, MFA, lifecycle management, policies, SAML/OIDC integrations, and SCIM provisioning.
-
Develop and improve access request, approval, review, and certification workflows through IGA platforms.
-
Automate joiner, mover, and leaver processes as well as access reviews using scripting, APIs, and infrastructure-as-code.
-
Integrate IAM controls across AWS services, SaaS applications, cloud accounts, and developer/DevOps pipelines.
-
Partner with Security, DevOps, Infrastructure, and engineering teams to onboard applications, troubleshoot access issues, and implement secure identity solutions.
-
Design and implement identity and access controls for AI/ML environments, helping protect training data, models, and inference APIs.
-
Support SOC 2, PCI DSS, and other compliance and audit activities by providing access evidence and improving security controls.
-
Maintain documentation, contribute to runbooks, and participate in on-call activities when required.
Requirements:
-
At least 3 years of relevant professional experience with a Bachelor’s degree, or 2 years with a Master’s degree, or an equivalent combination of education and experience.
-
Hands-on experience with IAM technologies such as Okta, Microsoft Entra ID, CyberArk, Ping, or SailPoint.
-
Working knowledge of SAML, OAuth 2.0/OIDC, and SCIM protocols.
-
Practical understanding of AWS IAM concepts, including roles, policies, federation, least privilege, and role-based access control (RBAC).
-
Hands-on scripting experience with technologies such as Python or PowerShell, particularly for automating IAM operations through APIs.
-
Familiarity with directory services including Active Directory, LDAP, and cloud-based identity alternatives.
-
Knowledge of security and compliance frameworks such as NIST, SOC 2, and PCI DSS.
-
Strong communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders.
-
Experience with AWS services such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, and AWS Developer Tools is an asset.
-
Familiarity with DevOps practices, CI/CD pipelines, and secrets management is an asset.
-
IAM-related certifications, such as CIAM/CAMS, CyberArk certifications, or Okta Certified Consultant, are considered a plus.
Benefits:
-
Competitive base salary of CAD 104,000–130,000, calibrated according to location, skills, and experience.
-
Annual bonus opportunities for eligible employees based on individual and organizational performance.
-
Multiple health insurance options.
-
Flexible vacation time plus additional floating holidays.
-
Retirement savings program with company contributions.
-
Equity participation in a publicly traded company.
-
Monthly stipend to support remote work.
-
Annual professional development stipend.
-
Family-forming benefits.
-
Generous parental leave with base salary top-up.
-
Fully remote work within Ontario or British Columbia, Canada.