Remote job
Security Engineer II - Identity and Access Management
Job details
About this role
Role overview A mid-level Security Engineer is sought to strengthen an Identity and Access Management (IAM) program within a fully cloud-native environment built on AWS. The role centers on designing, automating, and operating identity controls that reduce standing privileges and manual effort across systems and services.
Responsibilities - Configure and operate single sign-on, lifecycle policies, multi-factor enforcement, and SCIM integrations across SaaS and internal applications. - Manage just-in-time access profiles and privileged access controls for cloud and sensitive resources, partnering with engineering to minimize standing permissions. - Build and refine access request, approval, and certification workflows in identity governance platforms to support least privilege and audit readiness. - Automate joiner, mover, and leaver provisioning as well as access reviews through scripting, APIs, and infrastructure-as-code. - Collaborate with security, DevOps, and infrastructure teams to onboard applications and cloud accounts and to resolve access-related issues. - Support SOC 2, PCI DSS, and similar audits through access reporting and control evidence.
Requirements - Three or more years of relevant experience with a bachelor's degree, or two years with a master's, or equivalent professional experience. - Hands-on experience with identity platforms such as Okta, Entra ID, CyberArk, Ping, or SailPoint. - Working knowledge of SAML, OAuth2/OIDC, and SCIM. - Familiarity with AWS identity concepts including roles, policies, and federation, plus least privilege and role-based access control patterns. - Scripting ability in Python or PowerShell to automate identity operations through APIs. - Understanding of compliance frameworks such as NIST, SOC 2, or PCI DSS, paired with clear communication skills.
Nice to have - Relevant IAM certifications or credentials. - Experience with AWS services such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, and Code Pipeline. - Familiarity with secrets management and CI/CD pipelines.
Benefits and work setup - Remote-first role open to candidates located anywhere in Ontario or British Columbia, Canada. - Base salary range of CAD 104,000 to CAD 130,000 for new hires, plus an annual bonus program. - Multiple health insurance options, flexible vacation time with floating holidays, and a retirement savings program with company contribution. - Equity in a publicly traded company, a monthly remote-work stipend, and an annual professional development stipend. - Family-forming benefits and parental leave with a base salary top-up.