Remote job
Senior Security Engineer - Identity and Access Management
Job details
About this role
Role overview This role focuses on shaping and implementing modern identity strategies across a fully cloud-based environment, with no on-premises data center footprint. The engineer will build and operate a secure, scalable, and frictionless Identity and Access Management program spanning governance, privileged access, certificate lifecycle, and integrations with SaaS and developer pipelines. A meaningful portion of the work involves designing access controls that protect AI/ML systems, including training data, models, and inference APIs.
Responsibilities - Develop and lead implementation of IAM strategies aligned with cloud-native architecture and security principles. - Build and evolve Identity Governance and Administration (IGA) capabilities, and operate Privileged Access Management in a cloud-first AWS environment. - Design and architect a Certificate Lifecycle Management solution supporting cloud-native workloads. - Drive IAM integration across AWS services, SaaS platforms, and developer and DevOps pipelines. - Automate identity provisioning, de-provisioning, and access reviews using AI tools and infrastructure-as-code. - Design identity and access controls for AI/ML systems, covering training data, models, and inference endpoints. - Promote least privilege and zero-trust principles through scalable access controls and policy automation. - Mentor junior engineers and serve as technical lead for IAM projects, partnering with Security, DevOps, and Infrastructure teams.
Requirements - Strong passion for Identity and Access Management with proven expertise in cloud-native environments, particularly AWS. - Hands-on experience with IGA, PAM, SSO, MFA, secrets management, and certificate lifecycle. - Familiarity with AWS-native services such as Lambda, EC2, S3, and IAM, and with third-party identity tools like Okta and CyberArk. - Experience automating provisioning, de-provisioning, and access reviews using infrastructure-as-code. - Track record mentoring engineers and serving as a technical lead on security initiatives.
Nice to have - Experience securing AI/ML platforms, including model training and inference pipelines. - Background staying ahead of emerging cloud threats and evolving compliance requirements.
Benefits and work setup - Fully remote within Ontario or British Columbia, Canada under a flexible-first model. - Opportunity to shape a cloud-native IAM program end to end.