Senior IAM Systems Engineer, Passwordless Integration (Global Security)

RBC

Toronto

On-site

CAD 120,000 - 170,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RBC is seeking a Senior IAM Systems Engineer to drive passwordless integration across Windows/macOS endpoints, VDI platforms, and directory services. You will partner with authentication, endpoint, and security teams to deliver an organization-wide passwordless experience.

You will design federation patterns, deploy credential providers, and automate configuration, monitoring, and rollout processes while aligning with regulatory controls and enterprise standards.

Qualifications

  • 7+ years in identity and authentication engineering.
  • 3+ years Python or Java with REST and microservices.
  • Experience with IaC, CI/CD, containers, and cloud platforms.
  • Hands-on with Windows/macOS integration and credential providers.
  • Experience with Citrix/VDI and Active Directory/Kerberos.
  • Familiarity with federation protocols (OIDC, OAuth 2.0, SAML, WebAuthn).
  • Passwordless deployment in enterprise environments.
  • Scripting and automation for configuration management.
  • Knowledge of cryptographic primitives for authentication.
  • CI/CD tooling experience (Jenkins, GitHub Actions, GitLab).
  • Experience with Entra ID and/or Auth0 (nice-to-have).
  • Endpoint management platforms (Intune/Jamf/SCCM).
  • Mobile authentication and Zero Trust familiarity (nice-to-have).
  • Leadership in authentication rollouts (nice-to-have).
  • IAM platform automation (nice-to-have).
  • Regulatory landscape awareness (FRB/OSFI) (nice-to-have).

Responsibilities

  • Lead integration of passwordless across workforce systems and endpoints.
  • Collaborate with endpoint, workplace, Citrix, and directory services teams.
  • Design integration patterns for federated and non-federated systems.
  • Configure, test, and operationalize passwordless deployments on devices.
  • Drive integration with workforce authentication platforms and downstream consumers.
  • Build automation for deployment, policy management, and health checks.

Skills

Identity integration
Python/Java (OOP)
DevOps / CI-CD
Endpoint integration
Citrix / VDI
AD / Kerberos / Federation
Passwordless deployment
Scripting (PowerShell/Python)
Crypto primitives
CI/CD tooling
Entra ID / Auth0
Intune / Jamf / SCCM
Mobile authentication
Zero Trust
IAM platform automation
Regulatory knowledge

Job description

Job Description

What is the opportunity?

The Senior IAM Systems Engineer, Passwordless Integration is responsible for rolling out and integrating the enterprise Passwordless authentication solution across the systems and platforms employees use every day. This role works across the organization — partnering with endpoint, workplace, infrastructure, and access teams — to bring passwordless authentication to Windows and macOS devices, virtual desktop and application delivery platforms, directory services, and other enterprise systems. Sitting within Platform Enablement Engineering and partnering closely with the Authentication team, this engineer bridges identity and the broader enterprise, turning a passwordless capability into a real, organization-wide experience.

Passwordless is a strategic pillar of the IAM roadmap — directly improving security posture, reducing credential-related risk, and elevating the user experience. This engineer will shape how the enterprise integrates and scales passwordless across a heterogeneous estate, working at the intersection of authentication, endpoint, and access engineering.

What will you do?

  • Lead integration of the enterprise passwordless solution with workforce systems, including Windows endpoints, macOS endpoints, Citrix and other VDI / application delivery platforms, Active Directory, and other authentication-consuming systems
  • Partner with endpoint engineering (Windows, macOS), workplace technology, Citrix / virtualization, and directory services teams to deliver consistent passwordless experiences across the estate
  • Design and execute integration patterns for federated and non-federated systems, including login flows, fallback behaviors, lifecycle and recovery scenarios
  • Configure, test, and operationalize passwordless authenticator deployments on managed and unmanaged endpoints
  • Drive integration with workforce authentication platforms and downstream consumers
  • Build automation for configuration deployment, policy management, and operational health checks of the passwordless integration footprint
  • Partner with the Authentication team — who holds product accountability — to deliver against the passwordless roadmap and prioritize integration backlog
  • Establish observability, alerting, and operational practices for passwordless integrations across systems
  • Work with Architecture, Security, Risk, and Audit to ensure integration meet regulatory and internal control requirements
  • Provide deep technical input into rollout planning, change management, and user experience design
  • Support production operations, incident response, and root cause analysis for passwordless integrations across systems
  • Document integration patterns, runbooks, and standards for use by partner teams across the enterprise
  • Build operational automation for the Passwordless toolset—patching, certificate rotation, configuration drift detection, and routine support operations
  • Integrate with CI/CD pipelines and infrastructure platforms

What do you need to succeed?

Must-have:

  • 7+ years in identity, authentication, endpoint, or platform integration engineering
  • Software Development: 3+ years of experience withPython or Java with strong OOP design principles, solid understanding of REST API’s, microservices architecture
  • DevOps Infrastructure:Experience with Infrastructure-as-code, CI/CD pipelines, containerization (Docker/Kubernetes), cloud platforms
  • Strong hands‑on experience integrating authentication solutions with Windows and macOS endpoints, including credential providers, login flows, and device‑bound authentication
  • Software
  • Hands‑on experience integrating authentication with Citrix or equivalent VDI / virtual application delivery platforms
  • Strong working knowledge of Active Directory, Kerberos, and modern federation protocols (OIDC, OAuth 2.0, SAML, FIDO2 / WebAuthn)
  • Experience deploying and operating phishing‑resistant or passwordless authentication solutions in an enterprise environment
  • Strong scripting / automation skills (PowerShell, Python, or equivalent) for configuration management and operational tooling
  • Strong understanding of cryptographic primitives relevant to authentication (public‑key cryptography, attestation, key management) and how they apply to endpoint‑bound credentials
  • Deep hands‑on expertise with CI/CD platforms (Jenkins, GitHub Actions, GitLab CI)

Nice-to-have:

  • Experience integrating with Entra ID and/or Auth0 authentication flows
  • Familiarity with enterprise endpoint management platforms (Intune, Jamf, SCCM) and how authentication integrates with managed‑device posture
  • Experience with mobile authentication (iOS / Android platform authenticators, secure enclave) and consumer‑style passwordless flows
  • Familiarity with Zero Trust Architecture and phishing‑resistant authentication strategy
  • Experience leading enterprise‑wide authentication rollouts or migrations
  • Experience automating IAM platforms (Entra ID, Auth0, SailPoint, CyberArk, or equivalent)
  • Working knowledge of the banking/financial services regulatory landscape (FRB, Part 30, OSFI) and how it shapes authentication controls

What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference in our communities, and achieving mutual success

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high‑performing team
  • Opportunities to do challenging work and take on progressively greater accountabilities

#LI-POST

#TECHPJ

Job Skills

Information Technology (IT) Infrastructure, Programming Languages, Software Change Request Management, Software Development Life Cycle (SDLC), Software Engineering, Software Integration Engineering, Software Product Design, Software Product Technical Knowledge, Software Release Management, System Testing Tools

Additional Job Details

Address:

16 YORK ST:TORONTO

City:

Toronto

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2026-05-14

Application Deadline:

2026-09-16

Note** : **Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well‑being of our clients and communities at jobs.rbc.com.

RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff, Site Reliability Engineer(Global Security)
Staff, Site Reliability Engineer(Global Security)

RBC • Vancouver

On-site
CAD 110,000 - 170,000
Director, Unified Sign In
Director, Unified Sign In

Socket.dev • Toronto

On-site
CAD 150,000 - 210,000
Flexible, hybrid work arrangements
Staff, Site Reliability Engineer(Global Security)
Staff, Site Reliability Engineer(Global Security)

RBC • Halifax

On-site
CAD 140,000 - 190,000
Staff, Site Reliability Engineer(Global Security)
Staff, Site Reliability Engineer(Global Security)

RBC • Toronto

On-site
CAD 120,000 - 150,000
Senior Information Security Analyst
Senior Information Security Analyst

RBC • Toronto

On-site
CAD 90,000 - 130,000
Senior Software Developer, Security Automation(Global Security)
Senior Software Developer, Security Automation(Global Security)

RBC • Toronto

On-site
CAD 120,000 - 170,000
Total rewards program
Coaching and development
World-class tools and training
+1
Product Owner, Unified Sign In
Product Owner, Unified Sign In

RBC • Toronto

On-site
CAD 110,000 - 140,000
Sr. Network Security Analyst (Global Security)
Sr. Network Security Analyst (Global Security)

RBC • Toronto

On-site
CAD 90,000 - 120,000
Total rewards program
Coaching and development
Flexible work-life balance
+2
Senior Manager, Identity Experience (Global Security)
Senior Manager, Identity Experience (Global Security)

RBC • Vancouver

On-site
CAD 140,000 - 180,000
Total rewards program
Leadership development and coaching
World-class tools and training
+1
Senior Full Stack Developer (Global Security)
Senior Full Stack Developer (Global Security)

Worky • Toronto

On-site
CAD 120,000 - 170,000
Total Rewards program with bonuses and
Flexible work options
Stock options where applicable
+1