Security Advisor PAM Specialist

Intact FC

Mississauga

Hybrid

CAD 119,000 - 145,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible work arrangements
Hybrid work model
5 extra days off per year
Wellbeing benefits and ESPP

Job summary

Intact is seeking a Senior PAM Specialist to lead the design and architecture of our IDIRA Privileged Cloud. You will build advanced integrations, including CPM plugins and PSM connectors for MFA‑enabled apps, while advancing JIT access and zero standing privilege.

You will own onboarding standards, reference architectures, and end‑to‑end SIA workflows across AWS, Azure, and GCP, balancing automation with auditability and change control.

Qualifications

  • 7+ years in IAM/Security Engineering with 5+ years in PAM engineering and demonstrable experience with IDIRA Privileged Cloud (CyberArk Privilege Cloud)
  • Strong expertise in: CPM concepts and custom plugin development and PSM session brokering and custom connector development
  • Development/scripting skills: PowerShell/Python/CyberArk REST APIs (as applicable to connectors/plugins/automation)
  • Experience with the CyberArk REST API for programmatic platform management
  • Deep understanding of MFA and federation patterns: SAML, OIDC, OAuth2, conditional access concepts, and step‑up authentication
  • Hands-on experience across AWS, Azure, and GCP
  • Understanding of Zero Trust, least‑privilege, and JIT access principles
  • Strong troubleshooting skills across Windows Server, Linux/Unix, and networking layers
  • Experience in a DevSecOps - CI/CD environment/ Secrets Management would be an asset
  • Strong ethical principles and understanding of business and information security ethics
  • IDIRA/CyberArk certifications: CDE- CPC is a must
  • Team player / good collaboration skills set
  • Strong analytical and problem‑solving skills with attention to detail
  • Ability to communicate complex security concepts to both technical and non‑technical stakeholders
  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English‑speaking colleagues across the country
  • No Canadian work experience required however must be eligible to work in Canada

Responsibilities

  • Own solution architecture for IDIRA Privileged Cloud including tenant design, environment segregation (prod/non‑prod), network connectivity patterns, identity federation/SSO, and operational hardening
  • Define onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidence
  • Establish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)
  • Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information‑related risks
  • Develop and maintain custom CPM plugins for systems and applications not supported out‑of‑the‑box
  • Engineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportability
  • Create standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycle
  • Design and build custom PSM connectors for: Web applications (including complex flows), Thick clients / legacy applications and Administrative tools requiring step‑up authentication
  • Engineer solutions for MFA‑enabled apps, balancing automation and security (e.g., brokered sessions, step‑up patterns, conditional access alignment, approved MFA handling approaches)
  • Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break‑glass procedures)
  • Lead deployment and adoption of SIA capabilities to enable just‑in‑time access and zero‑standing privilege for infrastructure and cloud workloads
  • Define end-to-end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocation
  • Integrate SIA patterns into operational processes (incident response, privileged break‑glass, platform engineering standards)
  • Implement automation using APIs and event‑driven patterns to reduce manual effort while maintaining strict auditability and change control
  • Design privileged access patterns across AWS, Azure, and GCP, including privileged roles, automation identities, and administrative access models.
  • Secure cloud administrative sessions and credentials for: Cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, Managed services (databases, secrets services, CI/CD runners, serverless)
  • Design and implement vaulting strategies for Agentic AI identities — autonomous AI agents, LLM orchestrators, robotic process automation (RPA) bots, and AI‑driven pipelines that require privileged credentials
  • Enforce least‑privilege principles for AI agents accessing sensitive systems, databases, and cloud services
  • Participate in the development of organizational standards for AI agent identity governance and credential hygiene
  • Identify and remediate security gaps, misconfigurations, and over‑privileged accounts across the PAM estate
  • Serve as senior escalation for complex Privileged Cloud onboarding and runtime issues (connectivity, session issues, rotation failures, connector behavior)
  • Participate in incident response activities involving privileged account compromise or misuse

Skills

IAM/Security
PAM engineering
IDIRA/CyberArk
CPM plugins
PSM brokering
SAML/OIDC/OAuth2
Cloud: AWS/AZURE/GCP
Zero Trust
DevSecOps
Communication

Education

CyberArk CPC
CyberArk CDE

Tools

PowerShell
Python
CyberArk REST API

Job description

Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times.

Our employee promise represents Intact’s commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career. In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us.

Pay at Intact is about much more than just salary.
  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team , we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.

About the role

We are seeking a Senior PAM Specialist with deep hands‑on expertise in IDIRA (formerly CyberArk) to lead the design and architecture of our PAM program and to build advanced integrations, including custom CPM plugins, PSM connectors for MFA‑enabled applications, and forward‑leaning capabilities such as Agentic AI vaulting and JIT (Just‑in‑time) implementation.

What you’ll do here:
  • Own solution architecture for IDIRA Privileged Cloud including tenant design, environment segregation (prod/non‑prod), network connectivity patterns, identity federation/SSO, and operational hardening
  • Define onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidence
  • Establish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)
  • Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information‑related risks
  • Develop and maintain custom CPM plugins for systems and applications not supported out‑of‑the‑box
  • Engineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportability
  • Create standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycle
  • Design and build custom PSM connectors for: Web applications (including complex flows), Thick clients / legacy applications and Administrative tools requiring step‑up authentication
  • Engineer solutions for MFA‑enabled apps, balancing automation and security (e.g., brokered sessions, step‑up patterns, conditional access alignment, approved MFA handling approaches)
  • Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break‑glass procedures)
  • Lead deployment and adoption of SIA capabilities to enable just‑in‑time access and zero‑standing privilege for infrastructure and cloud workloads
  • Define end-to-end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocation
  • Integrate SIA patterns into operational processes (incident response, privileged break‑glass, platform engineering standards)
  • Implement automation using APIs and event‑driven patterns to reduce manual effort while maintaining strict auditability and change control
  • Design privileged access patterns across AWS, Azure, and GCP, including privileged roles, automation identities, and administrative access models.
  • Secure cloud administrative sessions and credentials for: Cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, Managed services (databases, secrets services, CI/CD runners, serverless)
  • Design and implement vaulting strategies for Agentic AI identities — autonomous AI agents, LLM orchestrators, robotic process automation (RPA) bots, and AI‑driven pipelines that require privileged credentials
  • Enforce least‑privilege principles for AI agents accessing sensitive systems, databases, and cloud services
  • Participate in the development of organizational standards for AI agent identity governance and credential hygiene
  • Identify and remediate security gaps, misconfigurations, and over‑privileged accounts across the PAM estate
  • Serve as senior escalation for complex Privileged Cloud onboarding and runtime issues (connectivity, session issues, rotation failures, connector behavior)
  • Participate in incident response activities involving privileged account compromise or misuse
What you bring to the table:
  • 7+ years in IAM/Security Engineering with 5+ years in PAM engineering and demonstrable experience with IDIRA Privileged Cloud (CyberArk Privilege Cloud)
  • Strong expertise in: CPM concepts and custom plugin development and PSM session brokering and custom connector development
  • Development/scripting skills: PowerShell/Python/CyberArk REST APIs (as applicable to connectors/plugins/automation)
  • Experience with the CyberArk REST API for programmatic platform management
  • Deep understanding of MFA and federation patterns: SAML, OIDC, OAuth2, conditional access concepts, and step‑up authentication
  • Hands‑on experience across AWS, Azure, and GCP
  • Understanding of Zero Trust, least‑privilege, and JIT access principles
  • Strong troubleshooting skills across Windows Server, Linux/Unix, and networking layers
  • Experience in a DevSecOps - CI/CD environment/ Secrets Management would be an asset
  • Strong ethical principles and understanding of business and information security ethics
  • IDIRA/CyberArk certifications: CDE- CPC is a must
  • Team player / good collaboration skills set
  • Strong analytical and problem‑solving skills with attention to detail
  • Ability to communicate complex security concepts to both technical and non‑technical stakeholders
  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English‑speaking colleagues across the country
  • No Canadian work experience required however must be eligible to work in Canada

#LI-Hybrid

Il s’agit d’un nouveau rôle au sein de notre équipe en pleine croissance | This role is a new member of our growing team.

_We are an equal opportunity employer_

At Intact, our Value of respect is founded on seeing diversity as a strength. We strive to create an accessible workplace where employees feel valued, included and encouraged to share their unique perspectives.

We encourage applications from individuals who are members of equity‑deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community.

As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people. This history extends through many centuries and continues to evolve today.

We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). A copy of applicable policies is available on request.

If we can provide a specific adjustment to make the recruitment process more accessible for you, please let us know when we reach out about a job opportunity. We’ll work with you to meet your needs.

Learn more about our recruitment process and your candidate journey here.

Please note that Intact does not provide sponsorship or other support for immigration‑related matters including but not limited to employer‑specific closed work permits. Candidates must be eligible to work in Canada from the anticipated start date and throughout their employment and are solely responsible for maintaining their work eligibility.

If you are an employee of Intact or belairdirect, please apply for this role on Internal Career Site.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Technical Advisor Senior
IT Technical Advisor Senior

Intact Financial Corporation • San Juan de Terranova

Hybrid
CAD 102,000 - 124,000
Flexible work arrangements
Hybrid work model
Up to 5 extra days off per year
+2
Manager, Identity Platform
Manager, Identity Platform

Intact Financial Corporation • Montreal (administrative region)

On-site
CAD 128,000 - 157,000
Hybrid work model
Possibility to purchase up to 5 extra…
Wellbeing benefits incl. telemedicine
+1
IT Technical Advisor Senior
IT Technical Advisor Senior

Intact • Montreal (administrative region)

Hybrid
CAD 102,000 - 124,000
Hybrid work model
Additional days off (up to 5) per year
Wellbeing programs and telemedicine
+1
Manager, Identity Platform
Manager, Identity Platform

Intact FC • Ottawa

Hybrid
CAD 128,000 - 157,000
Hybrid work model
Wellbeing benefits
Employee Share Purchase Plan
IT Technical Advisor Senior
IT Technical Advisor Senior

Intact FC • Mississauga

Hybrid
CAD 102,000 - 124,000
Hybrid work model
Employee Share Purchase Plan (ESPP)
Annual bonus up to 12% of base salary
+3
Senior Security Advisor - Detection Engineering
Senior Security Advisor - Detection Engineering

Intact FC • Laval (administrative region)

Hybrid
CAD 102,000 - 124,000
Hybrid work model
Buy up to 5 extra days off per year
Wellbeing benefits (telemedicine, Well
+1
Security Advisor Senior - Emergency vulnerability response
Security Advisor Senior - Emergency vulnerability response

Intact • Montreal (administrative region)

Hybrid
CAD 102,000 - 124,000
Hybrid work model
Up to 5 extra days off per year
Wellbeing benefits (telemedicine, etc)
Security Advisor Senior - Emergency vulnerability response
Security Advisor Senior - Emergency vulnerability response

Intact Financial Corporation • Toronto

Hybrid
CAD 102,000 - 124,000
Flexible work arrangements
Hybrid work model
Extra days off (up to 5 per year)
+2
Director, Broker & Third-Party Security
Director, Broker & Third-Party Security

Intact • Toronto

Hybrid
CAD 162,000 - 198,000
Director, Broker & Third-Party Security
Director, Broker & Third-Party Security

Intact FC • Toronto

Hybrid
CAD 162,000 - 198,000
Share plan
Pension plan with guaranteed income
Hybrid work model
+1