Identity & Access Management (IAM) Specialist (Temporary)

CGI

$95K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity and identity/access management (IAM) with hands-on expertise.
  • Strong knowledge of Microsoft Active Directory and Microsoft Entra ID.
  • Familiarity with authentication and authorization technologies, including MFA and SSO.
  • Experience with Identity Governance and Administration (IGA) principles and technologies.
  • Proficient in Privileged Access Management (PAM) and IAM lifecycle management.

Responsibilities

  • Assess current IAM environments and security controls.
  • Review IAM architecture, policies, and operating models.
  • Identify IAM security gaps and recommend remediation plans.
  • Facilitate workshops with cross-functional teams to gather input.
  • Evaluate identity architectures across various environments (cloud, hybrid).
  • Oversee user provisioning and access certification processes.
  • Monitor and enhance IAM operational capabilities against industry best practices.

Benefits

  • Full-time employment with potential for extension beyond the initial 3-month term.
  • Engagement in a critical area of cybersecurity with high visibility.
  • Opportunity to work with leading IAM technologies and frameworks.
  • Collaboration with diverse teams across the organization.
  • Possibility to increase IAM maturity and influence security posture at the enterprise level.
Full Job Description
Identity & Access Management (IAM) Specialist (Temporary)

Category: Cyber Security

Main location: Canada, Ontario, Toronto

Position ID:J0826-0847

Employment Type: Full Time

Position Description:

* This role is a 3-month temporary position with the possibility of extension*

The Identity & Access Management (IAM) Specialist is responsible for assessing, designing, implementing, and improving enterprise identity and access management capabilities. The specialist works with security, infrastructure, application, cloud, and business teams to ensure that identities are securely authenticated, appropriately authorized, governed throughout their lifecycle, and aligned with organizational security and compliance requirements.The role requires strong knowledge of Microsoft Active Directory and Entra ID, authentication and authorization technologies, Identity Governance and Administration (IGA), Privileged Access Management (PAM), federation, Single Sign On (SSO), Multi Factor Authentication (MFA), Conditional Access, and Zero Trust principles.

Your future duties and responsibilities:
• Conduct current-state assessments of enterprise IAM environments, processes, technologies, and security controls.
• Review IAM architecture, policies, standards, procedures, and operating models.
• Assess authentication and authorization mechanisms across applications, infrastructure, cloud platforms, and enterprise services.
• Identify IAM security gaps, technical risks, process deficiencies, and control weaknesses.
• Evaluate IAM capabilities against recognized security frameworks, industry best practices, and Zero Trust principles.
• Develop prioritized recommendations, remediation plans, and IAM maturity roadmaps.
• Facilitate workshops and stakeholder interviews with security, infrastructure, application, architecture, and business teams.

Identity Architecture & Authentication
• Assess and design enterprise identity architectures across on-premises, cloud, and hybrid environments.
• Review Active Directory and Microsoft Entra ID architecture, configuration, trust relationships, synchronization, and identity flows.
• Assess authentication technologies including password-based authentication, MFA, passwordless authentication, and FIDO2/passkeys.
• Review Single Sign-On (SSO) and federation architectures.
• Evaluate implementations of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, and LDAP.
• Review Conditional Access policies and risk-based authentication controls.
• Identify and recommend remediation for legacy and weak authentication mechanisms.
• Assess authentication flows for users, administrators, service accounts, applications, APIs, and workload identities.

Identity Governance & Administration (IGA)
• Assess Joiner, Mover, and Leaver (JML) lifecycle processes.
• Review user provisioning, modification, deprovisioning, and termination processes.
• Evaluate Role-Based Access Control (RBAC) and other access control models.
• Review access request and approval workflows.
• Assess access certification and periodic access review processes.
• Review segregation of duties (SoD) controls and identify excessive or conflicting access.
• Evaluate entitlement management and application onboarding processes.
• Support IAM/IGA solutions including SailPoint, Saviynt, Microsoft Entra ID Governance, and comparable platforms.

Privileged Access Management (PAM)
• Assess privileged accounts, administrative identities, and elevated access processes.
• Review Privileged Access Management (PAM) and Privileged Identity Management (PIM) controls.
• Evaluate privileged account discovery, credential vaulting, credential rotation, and session management processes.
• Review Just-in-Time (JIT) and Just Enough Administration (JEA) approaches.
• Assess emergency and break-glass account controls.
• Review privileged access to Active Directory, Microsoft Entra ID, servers, databases, applications, and cloud platforms.
• Support CyberArk, Microsoft Entra PIM, BeyondTrust, and equivalent PAM solutions.

Service, Application & Machine Identities
• Assess service accounts, application identities, API identities, and machine-to-machine authentication mechanisms.
• Review service principals, managed identities, certificates, API keys, and application secrets.
• Identify unmanaged or excessive permissions assigned to non-human identities.
• Recommend secure credential, certificate, and secrets management practices.
• Assess workload identity lifecycle and governance controls.

Security Monitoring & Operations
• Review IAM-related logging, monitoring, and alerting capabilities.
• Assess detection capabilities for identity-based attacks including credential compromise, privilege escalation, password spraying, and anomalous authentication activities.
• Review integration between IAM platforms and SIEM/SOC capabilities.
• Define and recommend IAM security metrics, KPIs, and KRIs.
• Support investigation, response, and remediation of identity-related security incidents.
• Recommend improvements to IAM operational monitoring and continuous security practices.

Required qualifications to be successful in this role:
• 5+ years of cybersecurity, identity and access management (IAM), infrastructure security, or related experience, with significant hands-on IAM expertise.
• Strong knowledge of Microsoft Active Directory and Microsoft Entra ID.
• Strong understanding of authentication and authorization concepts and technologies.
• Experience with Multi-Factor Authentication (MFA), Conditional Access, Single Sign-On (SSO), federation, and passwordless authentication.
• Working knowledge of SAML, OAuth 2.0, OpenID Connect (OIDC), Kerberos, and LDAP.
• Experience with Identity Governance and Administration (IGA) concepts and technologies.
• Experience with Privileged Access Management (PAM) concepts, processes, and solutions.
• Strong understanding of identity lifecycle management and Joiner, Mover, Leaver (JML) processes.
• Knowledge of Role-Based Access Control (RBAC), least privilege principles, segregation of duties (SoD), and access certification processes.
• Understanding of hybrid identity environments and cloud IAM architectures.
• Knowledge of service accounts, workload identities, application authentication, and non-human identity management.
• Understanding of Zero Trust security principles and identity-centric security architectures.
• Ability to assess complex IAM environments and translate findings into practical, risk-based remediation recommendations.
• Strong technical documentation, stakeholder interviewing, workshop facilitation, communication, and presentation skills.

Preferred Technology Experience
• Microsoft Entra ID (Azure AD)
• Microsoft Entra ID Governance
• Microsoft Entra Privileged Identity Management (PIM)
• Microsoft Active Directory
• SailPoint
• Saviynt
• CyberArk
• BeyondTrust
• Okta
• Ping Identity
• Microsoft Defender for Identity
• Microsoft Sentinel
• ServiceNow

Preferred Certifications
• Microsoft Certified: Identity and Access Administrator Associate (SC-300)
• Microsoft Security certifications
• Microsoft Azure certifications
• SailPoint certifications
• Saviynt certifications
• CyberArk certifications
• Okta certifications
• Certified Information Systems Security Professional (CISSP)
• Certified Cloud Security Professional (CCSP)
• Vendor-neutral IAM, Identity Governance, or Cybersecurity certifications.

CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $95,000-$145,000. This role is an existing vacancy.

#LI-AB19

Skills:
  • Cyber
  • CyberArk
  • Cybersec. Incident Remediation
  • English
  • Identity and access mgt (IAM)
  • Microsoft 365 Defender


Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar Identity & Access Management (IAM) Specialist (Temporary) jobs: