Principal Identity & Access Management (IAM) Engineer

Aviso Wealth

$130K — $140K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of IAM experience covering authentication, authorization, federation, identity governance, and directory services.
  • Hands-on experience with platforms like SailPoint, Saviynt, Entra ID, and Okta.
  • Expertise in designing RBAC/ABAC models, entitlement catalogs, and access certification programs.
  • Strong knowledge of federation protocols such as SAML, OIDC, OAuth 2.0, SCIM.
  • Proven ability to script and automate using PowerShell, Microsoft Graph, and Python.
  • Experience managing B2B partner identity governance and lifecycle.
  • Regulated environment experience, preferably in financial services, with fluency in audit and compliance.

Responsibilities

  • Own and evolve the enterprise IAM strategy, policies, and standards in line with compliance frameworks.
  • Oversee identity architecture including SSO/MFA, IGA, PAM, and federation patterns.
  • Drive improvements in the user lifecycle process for internal and external parties, focusing on automation.
  • Enhance access review and recertification processes while ensuring compliance and audit readiness.
  • Implement designed solutions by configuring platforms and automating tasks effectively.

Benefits

  • Competitive compensation package rewarding individual contributions.
  • Excellent health, dental, and insurance benefits tailored to employee needs.
  • Generous vacation time alongside fitness benefits and parental leave top-up options.
  • Matching contributions to retirement plans.
  • Commitment to ongoing staff development with a learning assistance program.
  • Regular social events encouraging teamwork.
Full Job Description
The Opportunity:

We're looking to fill an opening for a Principal Identity & Access Management (IAM) Engineer to join our Technology Ops & Support Partners team.

Reporting to the Director, Technology Support Services, the Principal IAM Engineer is responsible for IAM end-to-end: defining the policies, standards, target-state architecture and building.

This is not a slideware role. You'll design the model and then implement it - configuring tooling, writing automation, integrating applications, and standing up the governance that lets us prove who has access to what, for both internal users and external partners.

The Principal IAM Engineer will also monitor adherence to change governance requirements, support the end-to-end lifecycle of standard, normal, and emergency changes, and escalate exceptions, risks, and control gaps as required.

What your day looks like:
  • Own and continuously evolve the enterprise Identity & Access Management (IAM) strategy, policies, and standards across authentication, authorization, lifecycle, and access governance, mapped to NIST CSF 2.0, CIRO, PIPEDA, and SOC/ITGC obligations, and translated into business-level risk for leadership
  • Oversee the end-to-end identity architecture across workforce SSO/MFA, IGA, PAM, directory/federation, and B2B partner identity; guide the ongoing optimization of the toolset (e.g., Entra ID, Okta/Ping, SailPoint/Saviynt, CyberArk) and advance federation and provisioning patterns (SAML, OIDC, OAuth 2.0, SCIM, FIDO2) within a Zero Trust model
  • Drive continuous improvement of the joiner-mover-leaver lifecycle for internal users and the onboarding/offboarding experience for external partner firms and advisors, expanding delegated administration, B2B federation, and least-privilege scoping through automated, auditable workflows
  • Grow and improve the access review and recertification program across internal and external populations, refine the entitlement catalogue and SoD controls, and strengthen reporting so we can consistently demonstrate who has access to what, why, and when it was last reviewed with audit-ready evidence
  • Implement what you design: configure platforms, build connectors and app onboarding, and automate with PowerShell/Microsoft Graph, Python, and Terraform/Bicep; partner with Security/CISO, Technology Ops, application owners, and external partner firms to support audits and regulatory reviews

Requirements

Your experience and skills:
  • 8+ years of experience in IAM, with deep, demonstrated coverage of authentication, authorization, federation, identity governance, and directory services
  • Hands-on experience across the stack: at least one IGA platform (e.g., SailPoint, Saviynt, or Entra ID Governance), a workforce identity platform (Entra ID and/or Okta), and a PAM solution
  • Proven design of RBAC/ABAC models, entitlement catalogues, SoD controls, and access certification / recertification programs
  • Strong capability with federation and provisioning protocols: SAML, OIDC, OAuth 2.0, SCIM
  • Proven scripting/automation ability - you can build, not just specify (PowerShell + Graph API, Python; IaC a plus)
  • Experience with governing external / B2B partner identity - federation with partner IdPs, delegated administration, and lifecycle/reviews for external users
  • Track record in a regulated environment (financial services strongly preferred) with audit and compliance fluency
  • Able to translate technical access risk into clear business and executive-level risk language
  • Fluent communication skills in English are required and bilingual skills in French are an asset

Benefits

  • Competitive compensation package that rewards and recognizes individual contributions
  • Excellent health, dental and insurance benefits to meet the diverse needs of our employees
  • Generous vacation time, fitness benefit, parental leave top-up options
  • Matching contributions to our retirement program
  • Commitment to the continuous improvement of our staff through learning & development and an education assistance program
  • Regular social events to foster teamwork

Salary

This position is posted with an expected salary range of $130,000 - $140,000 CAD annually. Individual compensation packages are based on various factors unique to each candidate and the requirements of the position.

Similar Jobs

More Jobs at Aviso Wealth

More Information Technology Jobs

Find similar Principal Identity & Access Management (IAM) Engineer jobs: