Location Address: Toronto
Work arrangement: Hybrid - In office 2 days per week
Contract Duration: ASAP till Oct 31st
Possibility of extension - Depending on performance and funding
Conversion to FTE - Depending on performance
Number of Positions: 1
Schedule Hours: 9 am-5 pm Monday-Friday (No overtime).
Reason: Backfill
Typical Day in Role:
• Provide strategic leadership and direction for CIAM engineering and platform delivery, ensuring alignment with enterprise security strategy, reliability standards, and digital identity modernization initiatives.
• Own the CIAM capability roadmap, overseeing the design, evolution, and continuous improvement of CIAM platforms and services to meet current and future business and security needs.
• Establish and govern CIAM architecture and frameworks, ensuring alignment with organizational security standards, regulatory obligations, and industry best practices.
• Set technical standards and best practices for identity federation, SSO, MFA, OAuth2/OIDC flows, adaptive authentication, and API‑based integrations across digital channels.
• Ensure CIAM solutions meet regulatory, compliance, and security requirements across geographies, customer segments, and channels, working closely with risk and assurance partners.
• Oversee onboarding and expansion of digital channels onto CIAM platforms, ensuring consistent, secure, and scalable implementations through well‑defined patterns and controls.
• Lead risk assessments and technical security reviews for CIAM integrations, approving design decisions and ensuring that appropriate mitigation strategies are identified and implemented.
• Drive continuous improvement of engineering and delivery processes, including deployment models, onboarding workflows, implementation guidelines, and operational readiness.
• Collaborate with senior stakeholders across engineering, product, security, architecture, and operations to enable smooth adoption of CIAM services and resolve complex cross‑team dependencies.
• Provide thought leadership, coaching, and technical oversight to CIAM engineers and partner teams, enabling high‑quality solutions without the need for direct hands‑on execution.
• Ensure high‑quality technical documentation and guidance is available and maintained, including architectures, standards, runbooks, and troubleshooting procedures.
• Build and maintain strong working relationships with technology partners, delivery teams, and business stakeholders to support successful program and platform outcomes.
• Embed the Bank’s risk appetite and risk culture into CIAM decisions, ensuring proactive risk identification, escalation, and informed decision‑making.
• Champion a customer‑centric, inclusive, and collaborative engineering culture, fostering accountability, continuous learning, and strong engagement across the CIAM organization.
Candidate Requirements/Must Have Skills:
1. 10+ years of progressive experience leading and overseeing the design, implementation, and modernization of enterprise‑scale platforms built on Java/J2EE, Spring Framework, Node.js, RESTful APIs, event‑driven architectures (Kafka), and cloud‑based data services.
2. 5+ years of deep experience providing technical leadership for CIAM platforms, including ForgeRock (AM, IDM, DS) and Ping Identity (PingFederate, PingAccess, PingDirectory), with exposure to Okta and other SaaS IAM providers considered an asset.
3. Expert‑level understanding of identity and access management protocols and standards, including OAuth 2.0, OpenID Connect, SAML, LDAP, and their application across enterprise and customer identity use cases.
4. Demonstrated ability to define IAM and CIAM architectures for hybrid and cloud environments (AWS, Azure, GCP), ensuring scalability, resilience, and alignment with enterprise security strategy.
5. Strong foundation in cybersecurity principles, risk management, and regulatory compliance, with the ability to align IAM decisions to the Bank’s risk appetite and control frameworks.
Nice-To-Have Skills:
1. Strategic oversight of identity federation, SSO, MFA, and adaptive authentication solutions, ensuring secure, consistent implementations across channels and regions.
2. Leadership experience in DevOps and Infrastructure‑as‑Code practices (e.g., Terraform), enabling standardized, repeatable, and secure IAM deployments.
3. Proven leadership in CI/CD and deployment automation, governing engineering standards and release practices using Jenkins, cloud‑native deployment frameworks (GCP/Azure/AWS), and DevOps tooling.
Best VS. Average Candidate:
The best candidate is someone with experience in Java development and in ForgeRock and Ping Identity. Someone with knowledge of application security fundamentals and coding skills.
Candidate review and selection:
2 rounds
1st – Hiring manager and technical panel– 1 hr – MS Teams video call – experience check and role overview and technical questions on experience and requirements.
2nd (Optional) – Hiring manager and team– 1 hr – in-person– situational questions + assess interest in role and cultural fit.