Join the IT Security Operations Team, in the Senior Specialist, Identity & Access Management position. Position Status:Permanent, Full Time
Position Type:Hybrid
Office Location:Ottawa (ON), or Montreal (QC), or Toronto (ON)
In this role you will be responsible for designing, governing, and continuously improving the enterprise Identity and Access Management (IAM) program. You will ensure that digital identities and access rights are appropriately defined, authorized, reviewed, and revoked in alignment with organizational risk tolerance, security policy, and regulatory obligations. The role provides expert-level advisory services to senior management and is accountable for the effectiveness and outcomes of IAM controls across the organization.
What you'll do: - Lead IAM strategy, governance, and oversight by owning the enterprise Identity and Access Management (IAM) framework, including policies, standards, and control objectives.
- Define and enforce core IAM principles, including identity lifecycle management, least privilege, role based access control (RBAC), segregation of duties, and access exception governance.
- Ensure alignment with security, privacy, and compliance requirements, maintaining auditable and regulatory IAM practices across the enterprise.
- Maintain accountability for IAM service effectiveness, including services delivered through internal teams and third party or managed service providers.
- Assess and communicate identity and access related risk, advising senior leadership on access risk acceptance, control design trade offs, and residual risk exposure.
- Provide expert advisory support on IAM implications for new systems, cloud platforms, and third party integrations.
- Define, monitor, and report on IAM KPIs and KRIs, producing executive and board level reporting on access risk posture, control effectiveness, and compliance status.
- Provide functional leadership and cross enterprise collaboration, mentoring IAM specialists, partnering with IT, security, audit, privacy, and business teams, and representing the organization in audits, regulatory reviews, and access related investigations.
What you should have: - A bachelor's degree in information technology, Cybersecurity, or a related field. An equivalent combination of education and/or experience may be considered.
- Advanced certification required (e.g., CISSP, CISM, or equivalent IAM certification).
- 7 to 10 years of progressive experience in IAM, cybersecurity, or IT risk management.
- Demonstrated experience advising senior leadership on enterpriselevel access risk.
- Experience designing or governing IAM programs or control frameworks.