Security Engineer II - Identity and Access Management

Jobgether SRL

British Columbia

Hybrid

CAD 104,000 - 130,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Annual bonus opportunities
Remote stipend
Equity participation
Professional development stipend
Family-forming benefits
Parental leave
Fully remote in Ontario/BC

Job summary

Jobgether SRL seeks a Security Engineer II - IAM to build and operate a scalable identity program in a primarily AWS environment. The role emphasizes least-privilege access, PAM, and automation, with Okta lifecycle and SCIM provisioning as core tasks.

You will work with Security, DevOps, and Engineering to secure cloud resources, implement RBAC, and support compliance efforts across SOC 2 and PCI DSS.

Qualifications

  • Minimum 3 years of relevant professional experience with a Bachelor’s degree, or 2 years with a Master’s degree.
  • Hands-on experience with IAM technologies such as Okta, Microsoft Entra ID, CyberArk, Ping, or SailPoint.
  • Working knowledge of SAML, OAuth 2.0/OIDC, and SCIM protocols.
  • Practical understanding of AWS IAM concepts, including roles, policies, federation, least privilege, and RBAC.
  • Scripting experience with Python or PowerShell for automating IAM operations via APIs.
  • Familiarity with Active Directory/LDAP and cloud identity alternatives.
  • Knowledge of NIST, SOC 2, and PCI DSS.
  • Strong communication and collaboration skills.
  • Experience with AWS services is an asset.
  • CI/CD and secrets management familiarity is a plus.
  • IAM certifications are a plus.

Responsibilities

  • Build and enhance Identity Governance and Administration (IGA) capabilities with least-privilege access and audit readiness.
  • Operate Privileged Access Management (PAM) for cloud resources, including just-in-time access.
  • Configure Okta capabilities: SSO, MFA, lifecycle, policies, SAML/OIDC, SCIM provisioning.
  • Develop and improve access request, approvals, and certification workflows.
  • Automate joiner/mover/leaver processes and access reviews via scripts and APIs.
  • Integrate IAM controls across AWS, SaaS, and DevOps pipelines.
  • Collaborate with Security, DevOps, Infra, and engineering to onboard apps.
  • Design IAM controls for AI/ML environments protecting data and models.
  • Support SOC 2, PCI DSS through access evidence and controls.
  • Maintain runbooks and participate in on-call as needed.

Skills

Okta
Microsoft Entra ID
CyberArk
SailPoint
Ping Identity
SAML / OIDC / OAuth 2.0
SCIM provisioning
Python / PowerShell
AWS IAM
RBAC / least privilege
Communication

Education

Bachelor's degree or equivalent

Tools

Okta SSO
MFA configuration
Just-in-time access tooling
SCIM tooling

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer II - Identity and Access Management based in Canada.

Join a security engineering team focused on building a modern, scalable, and frictionless Identity and Access Management (IAM) program.

You will help secure cloud-native infrastructure, applications, developer workflows, and critical business systems in an AWS-focused environment.

The role combines hands-on engineering, automation, access governance, and privileged access management.

You will play a key part in reducing standing privileges, eliminating manual processes, and strengthening least-privilege controls.

Your work will also contribute to protecting AI/ML systems and securing access to data, models, and inference services.

Collaboration with Security, DevOps, Infrastructure, and engineering teams will be central to your success.

This is a fully remote opportunity available to professionals located in Ontario or British Columbia, Canada.

Accountabilities
  • Build and enhance Identity Governance and Administration (IGA) capabilities supporting least-privilege access and audit readiness.
  • Implement and operate Privileged Access Management (PAM) solutions for cloud and privileged resources, including just-in-time access.
  • Configure and maintain Okta capabilities, including SSO, MFA, lifecycle management, policies, SAML/OIDC integrations, and SCIM provisioning.
  • Develop and improve access request, approval, review, and certification workflows through IGA platforms.
  • Automate joiner, mover, and leaver processes as well as access reviews using scripting, APIs, and infrastructure-as-code.
  • Integrate IAM controls across AWS services, SaaS applications, cloud accounts, and developer/DevOps pipelines.
  • Partner with Security, DevOps, Infrastructure, and engineering teams to onboard applications, troubleshoot access issues, and implement secure identity solutions.
  • Design and implement identity and access controls for AI/ML environments, helping protect training data, models, and inference APIs.
  • Support SOC 2, PCI DSS, and other compliance and audit activities by providing access evidence and improving security controls.
  • Maintain documentation, contribute to runbooks, and participate in on-call activities when required.
Requirements
  • At least 3 years of relevant professional experience with a Bachelor’s degree, or 2 years with a Master’s degree, or an equivalent combination of education and experience.
  • Hands-on experience with IAM technologies such as Okta, Microsoft Entra ID, CyberArk, Ping, or SailPoint.
  • Working knowledge of SAML, OAuth 2.0/OIDC, and SCIM protocols.
  • Practical understanding of AWS IAM concepts, including roles, policies, federation, least privilege, and role-based access control (RBAC).
  • Hands-on scripting experience with technologies such as Python or PowerShell, particularly for automating IAM operations through APIs.
  • Familiarity with directory services including Active Directory, LDAP, and cloud-based identity alternatives.
  • Knowledge of security and compliance frameworks such as NIST, SOC 2, and PCI DSS.
  • Strong communication and collaboration skills, with the ability to work effectively with both technical and non-technical stakeholders.
  • Experience with AWS services such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, and AWS Developer Tools is an asset.
  • Familiarity with DevOps practices, CI/CD pipelines, and secrets management is an asset.
  • IAM-related certifications, such as CIAM/CAMS, CyberArk certifications, or Okta Certified Consultant, are considered a plus.
Benefits
  • Competitive base salary of CAD 104,000-130,000, calibrated according to location, skills, and experience.
  • Annual bonus opportunities for eligible employees based on individual and organizational performance.
  • Multiple health insurance options.
  • Flexible vacation time plus additional floating holidays.
  • Retirement savings program with company contributions.
  • Equity participation in a publicly traded company.
  • Monthly stipend to support remote work.
  • Annual professional development stipend.
  • Family-forming benefits.
  • Generous parental leave with base salary top-up.
  • Fully remote work within Ontario or British Columbia, Canada.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Identity & Access Management
Senior Identity & Access Management

TEEMA • Brampton

On-site
CAD 90,000 - 125,000
Technology Manager – Identity & Access Management
Technology Manager – Identity & Access Management

Best Buy Canada • Vancouver

On-site
CAD 90,000 - 100,000
Employee discounts on tech
Flexible health benefits
Training programs
+2
Bilingual Technical Design Lead, Identity & Access Management
Bilingual Technical Design Lead, Identity & Access Management

Maplesoft Group, an SEB Company • Ottawa

On-site
CAD 108,000 - 134,000
Health & Dental benefits
Pension plan
Hybrid work environment
+1
IAM Support Engineer – ETL & Data Modeling
IAM Support Engineer – ETL & Data Modeling

KeyData Cyber • Toronto

On-site
CAD 52,000 - 70,000
Bonus program
Onsite Toronto Office
Software Development Engineer II, AWS Identity - IAM Identity Center
Software Development Engineer II, AWS Identity - IAM Identity Center

Amazon Web Services (AWS) • Toronto

On-site
CAD 115,000 - 192,000
IAM Consultant, Authentication Services
IAM Consultant, Authentication Services

Global Technical Talent, an Inc. 5000 Company • Toronto

Hybrid
CAD 126,000 - 146,000
Medical, Vision, and Dental Insurance
401k Retirement Fund
Senior Security Engineer, Detection and Response
Senior Security Engineer, Detection and Response

Jobgether SRL • Canada

Remote
CAD 137,000 - 171,000
Annual bonus
Health insurance
Remote work stipend
+5
Staff AI Developer
Staff AI Developer

Jobgether SRL • Canada

Remote
CAD 75,000 - 246,000
Remote work from Canada
RRSP matching
Private health coverage
+2
Software Development Engineer II, AWS Identity - IAM Identity Center
Software Development Engineer II, AWS Identity - IAM Identity Center

Amazon Inc. • Toronto

On-site
CAD 115,000 - 192,000
Health insurance
RSUs
Paid time off
IAM Analyst / IAM Administrator 6-8 months Contract
IAM Analyst / IAM Administrator 6-8 months Contract

Compugen Inc • Fairview

On-site
CAD 90,000 - 120,000