Cybersecurity Engineer – DevSecOps, IAM, PAM

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision!

Toronto

Hybrid

CAD 120,000 - 160,000

Full time

2 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Astra-North Infoteck Inc. in Toronto, ON is seeking a Cybersecurity Engineer with strong IAM, PAM, and DevSecOps experience to strengthen identity and access controls. You will implement governance for NPIDs, manage privileged access, and automate security workflows using Python.

The role involves collaborating with security, infrastructure, and development teams in a hybrid environment and supporting audit readiness.

Qualifications

  • Experience in Cybersecurity Engineering with IAM/PAM focus.
  • Hands-on with CyberArk, AD/Azure Entra ID, and SailPoint.
  • Proficient in DevSecOps and scripting (Python, PowerShell).
  • Familiarity with IAM governance and NPIDs is a plus.

Responsibilities

  • Manage IAM and PAM programs, onboarding, recertification, and RBAC.
  • Oversee NPID creation, rotation, and lifecycle governance.
  • Embed security controls in CI/CD using Jenkins, Azure DevOps, GitHub Actions.
  • Lead risk and control reporting for audits and regulators.
  • Develop Python automation for IAM workflows and NPID audits.

Skills

Cybersecurity Engineering
IAM
PAM
DevSecOps
Python
PowerShell

Tools

CyberArk
Active Directory
Microsoft Entra ID / Azure AD
SailPoint
Jenkins
Azure DevOps
GitHub Actions
Veracode
Snyk
Checkmarx
HashiCorp Vault
Azure Key Vault
Confluence
ServiceNow
Tableau

Job description

Job Description: Cybersecurity Engineer – DevSecOps / IAM / PAM

Location: Toronto, ON

Work Arrangement: Hybrid – 4 Days Work From Office (WFO)

Duration: 6–12 Months

Role Overview

We are seeking an experienced Cybersecurity Engineer with strong expertise in IAM, PAM, CyberArk, Active Directory, Entra ID, Python, and DevSecOps.

The successful candidate will support and enhance RBC's cybersecurity posture by managing identity and access lifecycles, Non-Personal IDs (NPIDs), risk and control frameworks, and DevSecOps security integration, while driving process automation through Python-based tooling.

Key Responsibilities
1. Identity & Access Management (IAM)
  • Onboard applications and services into IAM platforms, including SailPoint, CyberArk, and Active Directory.
  • Manage access provisioning, recertification, and deprovisioning workflows.
  • Enforce Least Privilege and Role-Based Access Control (RBAC) policies.
  • Support Privileged Access Management (PAM) onboarding and credential vaulting.
  • Manage identity lifecycle processes in Azure AD / Microsoft Entra ID.
2. Non-Personal ID (NPID) Management
  • Create, maintain, and retire Non-Personal IDs, including service accounts, shared accounts, and system IDs.
  • Ensure NPIDs comply with password policies, rotation schedules, and ownership requirements.
  • Conduct periodic reviews and attestations of NPID inventories.
  • Identify and remediate orphaned, stale, or non-compliant NPIDs.
  • Support audit and compliance activities related to service-account governance.
3. DevSecOps Security
  • Embed security controls into CI/CD pipelines using tools such as:
    • Jenkins
    • Azure DevOps
    • GitHub Actions
  • Advise development teams on secrets management using:
    • HashiCorp Vault
    • Azure Key Vault
  • Support integration and implementation of:
    • SAST
    • DAST
    • SCA
  • Work with security and development teams on tools such as Veracode, Snyk, and Checkmarx.
  • Participate in secure code reviews and threat modeling for new applications and services.
4. Risk & Controls Management
  • Own and track cybersecurity risk controls across assigned application portfolios.
  • Identify, raise, manage, and remediate security risk findings and exceptions.
  • Monitor compliance with cybersecurity policies and control requirements.
  • Prepare risk and control reporting for audits, regulators, and senior management.
  • Support evidence collection and remediation activities for internal and external audits.
5. Automation & Tooling
  • Develop Python-based automation to streamline IAM workflows, NPID audits, vulnerability reporting, and other security operations.
  • Develop integrations with internal APIs and platforms such as:
    • Confluence
    • ServiceNow
    • Tableau
  • Maintain and enhance automation pipelines for recurring security operations tasks.
  • Use Python libraries such as pandas, requests, openpyxl, and Selenium.
  • Develop scheduled jobs, automated data extraction, and reporting solutions to reduce manual effort.
Required Skills & Qualifications
  • Strong experience in Cybersecurity Engineering, IAM, PAM, and DevSecOps.
  • Hands‑on experience with:
    • CyberArk
    • Active Directory
    • Microsoft Entra ID / Azure AD
    • SailPoint
  • Strong understanding of Identity & Access Management (IAM) and Privileged Access Management (PAM).
  • Experience with Non-Personal IDs (NPIDs), service accounts, and identity governance.
  • Strong scripting and automation skills using Python.
  • Experience with Python libraries including pandas, requests, openpyxl, and Selenium.
  • Working knowledge of PowerShell.
  • Familiarity with DevSecOps practices and CI/CD security.
  • Knowledge of Jenkins, Azure DevOps, and GitHub Actions.
  • Experience with application security tools such as Veracode, Snyk, and Checkmarx.
  • Knowledge of secrets-management technologies such as HashiCorp Vault and Azure Key Vault.
  • Understanding of cybersecurity risk, controls, compliance, and audit requirements.
  • Strong analytical, communication, and problem-solving skills.
  • Ability to work effectively with cybersecurity, infrastructure, application development, and DevOps teams.
Key Technology Stack

IAM / PAM: SailPoint, CyberArk, Active Directory, Microsoft Entra ID

Automation: Python, pandas, requests, openpyxl, Selenium, PowerShell

DevSecOps: Jenkins, Azure DevOps, GitHub Actions

Secrets Management: HashiCorp Vault, Azure Key Vault

Application Security: Veracode, Snyk, Checkmarx

Enterprise Tools: ServiceNow, Confluence, Tableau

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist - Cloud (Global Security)- EN
Senior Security Specialist - Cloud (Global Security)- EN

RBC • Montreal (administrative region)

Hybrid
CAD 95,000 - 130,000
Total Rewards Program (bonuses, stock)
Annual training budget
Hybrid-remote flexibility
+1
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

RBC • Toronto

Hybrid
CAD 120,000 - 180,000
Total Rewards program with bonuses and
Annual training budget
Coaching & development
+3
Staff, Site Reliability Engineer(Global Security)
Staff, Site Reliability Engineer(Global Security)

RBC • Vancouver

On-site
CAD 110,000 - 170,000
Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

RBC • Vancouver

On-site
CAD 110,000 - 150,000
Total rewards program
Annual training budget
Hybrid-remote work environment
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior IAM Systems Engineer, Passwordless Integration (Global Security)
Senior IAM Systems Engineer, Passwordless Integration (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 170,000
Senior Cyber Security Network Analyst (Global Security)
Senior Cyber Security Network Analyst (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 150,000
Total rewards program
Flexible benefits
Coaching and development
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

Socket.dev • Toronto

Hybrid
CAD 110,000 - 140,000
Bonuses & flex benefits
Training & conference budget
Leadership support for development
+3