All jobs

IAM Engineer

TorontoCAD 110,000 per annum + Standard BenefitsPosted Aug 14, 2026
Employment type
Full-time
Work mode
Hybrid
Work authorization
Citizenship
Experience
8+ years
Azure Entra ID (formerly Azure AD)Privileged Identity Management (PIM)AWS IAM

About the role

Role: IAM Engineer
Location: Toronto Ontario - Hybrid
Salary: CAD 110,000 per annum + Standard Benefits
Openings: 5
Employment Type: Full-time / Contract
Experience Level: Mid-Level / Senior
Industry: Banking


Total Experience: 4-6 years

Key Responsibilities
• Design and implement Azure Entra ID (formerly Azure AD) identity governance frameworks.
• Configure and manage Privileged Identity Management (PIM) for just-in-time privileged access.
• Implement and enforce Conditional Access policies, MFA, and phishing-resistant authentication (FIDO2, Passkeys).
• Manage RBAC role assignments across Azure subscriptions, resource groups, and management groups.
• Remediate guest user accounts, stale identities, and excessive permission assignments.
• Configure and maintain Break Glass (emergency access) accounts with monitoring and alerting.
• Integrate Microsoft Defender for Cloud governance rules with ServiceNow for ticketing workflows.
• Support cross-cloud IAM alignment across AWS IAM and OCI IAM where applicable.
• Participate in IAM audits, access reviews, and compliance reporting.
• Develop IAM runbooks, RBAC mapping documentation, and onboarding guides.

Required Qualifications
• 5+ years of IAM experience, with 3+ years in Microsoft Azure / Entra ID.
• Deep knowledge of Azure RBAC, PIM, Conditional Access, and Entra ID roles.
• Experience with MFA enforcement, authentication methods, and access policies.
• Understanding of identity lifecycle management and access certification processes.
• Familiarity with Microsoft Defender for Cloud and Secure Score recommendations.
• Experience with ServiceNow or ticketing system integrations for IAM workflows.
• Microsoft Certified: Identity and Access Administrator (SC-300) preferred.
• Strong documentation and stakeholder communication skills.

Nice to Have
• Experience with AWS IAM, Organizations, and SCPs.
• Knowledge of OCI IAM compartments and policy structures.
• Exposure to SASE or Zero Trust Network Access (ZTNA) frameworks.

Sign in as a candidate to apply for this role.

Stay safe in your job search

  • • Never pay a fee to apply, interview, or get hired.
  • • Don’t share bank, card, or Social Security details before a written offer.
  • • Be wary of offers that skip interviews or pressure you to act fast.

Learn more from the FTC or report fraud to the FBI’s IC3.

Sign in as a candidate to report a suspicious posting.