Remote job
Senior Security Engineer - Identity and Access Management
Job details
About this role
Role overview
Seeking a seasoned Senior Security Engineer to lead the design and evolution of an Identity and Access Management (IAM) program within a fully cloud-native environment. This role combines hands-on engineering with strategic program leadership, shaping how access is governed across infrastructure, SaaS platforms, and emerging AI/ML workloads. The position is remote within Ontario or British Columbia, Canada.
Responsibilities
- Build and mature Identity Governance and Administration (IGA) capabilities, including provisioning, de-provisioning, and access reviews. - Implement and operate Privileged Access Management (PAM) controls tailored to a cloud-first infrastructure. - Architect a Certificate Lifecycle Management solution supporting cloud-native services and short-lived workloads. - Integrate IAM across cloud services, SaaS platforms, and developer/DevOps pipelines using infrastructure-as-code. - Design secure access controls for AI/ML systems, covering training pipelines, datasets, models, and inference endpoints. - Mentor engineers and partner with Security, DevOps, and Infrastructure teams to embed identity controls throughout the engineering lifecycle.
Requirements
- 8+ years of relevant experience with a Bachelor's degree, or equivalent combination of education and work history. - Hands-on expertise with IAM platforms such as Okta, CyberArk, Ping, or SailPoint. - Deep knowledge of AWS IAM, including roles, policies, permissions boundaries, and federation patterns. - Strong scripting skills (e.g., Python, PowerShell) and proficiency with infrastructure-as-code tools such as Terraform or CloudFormation. - Familiarity with authentication and authorization protocols (SAML, OAuth2, OpenID Connect, Kerberos) and directory platforms like Active Directory and LDAP. - Working understanding of compliance frameworks such as NIST, SOC 2, and PCI DSS.
Nice to have
- Relevant certifications such as CISSP, CISM, CIAM/CAMS, or vendor-specific credentials from CyberArk or Okta. - Broader AWS service experience across Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, and CodePipeline. - Experience embedding IAM into CI/CD pipelines and secrets management workflows.
Benefits and work setup
- Remote-first flexibility for candidates located in Ontario or British Columbia. - Base salary range of CAD 136,800 – 171,000, plus an annual bonus program. - Multiple health insurance options, flexible vacation time, and floating holidays. - Retirement savings program with employer contribution and equity in a publicly-traded company. - Monthly remote-work stipend and an annual professional development stipend. - Family-forming benefits and generous parental leave with a base salary top-up.