Talent.com
Intact Financial Corporation
Security Advisor PAM SpecialistIntact Financial Corporation • Toronto, Ontario, CAN
Security Advisor PAM Specialist

Security Advisor PAM Specialist

Intact Financial Corporation • Toronto, Ontario, CAN
19 days ago
Salary
CA$118,700.00 yearly
Job type
  • Full-time
Job description

Pay at Intact is about much more than just salary.

  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.


About the role

We are seeking a Senior PAM Specialist with deep hands-on expertise in IDIRA (formerly CyberArk) to lead the design and architecture of our PAM program and to build advanced integrations, including custom CPM plugins, PSM connectors for MFA-enabled applications, and forward-leaning capabilities such as Agentic AI vaulting and JIT (Just-in-time) implementation.


What you'll do here:

  • Own solution architecture for IDIRA Privileged Cloud including tenant design, environment segregation (prod/non-prod), network connectivity patterns, identity federation/SSO, and operational hardening
  • Define onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidence
  • Establish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)
  • Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information-related risks
  • Develop and maintain custom CPM plugins for systems and applications not supported out-of-the-box
  • Engineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportability
  • Create standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycle
  • Design and build custom PSM connectors for: Web applications (including complex flows),Thick clients / legacy applications and Administrative tools requiring step-up authentication
  • Engineer solutions for MFA-enabled apps, balancing automation and security (e.g., brokered sessions, step-up patterns, conditional access alignment, approved MFA handling approaches)
  • Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break-glass procedures)
  • Lead deployment and adoption of SIA capabilities to enable just-in-time access and zero-standing privilege for infrastructure and cloud workloads
  • Define end-to-end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocation
  • Integrate SIA patterns into operational processes (incident response, privileged break-glass, platform engineering standards)
  • Implement automation using APIs and event-driven patterns to reduce manual effort while maintaining strict auditability and change control
  • Design privileged access patterns across AWS, Azure, and GCP, including privileged roles, automation identities, and administrative access models.
  • Secure cloud administrative sessions and credentials for: Cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, Managed services (databases, secrets services, CI/CD runners, serverless)
  • Design and implement vaulting strategies for Agentic AI identities — autonomous AI agents, LLM orchestrators, robotic process automation (RPA) bots, and AI-driven pipelines that require privileged credentials
  • Enforce least-privilege principles for AI agents accessing sensitive systems, databases, and cloud services
  • Participate in the development of organizational standards for AI agent identity governance and credential hygiene
  • Identify and remediate security gaps, misconfigurations, and over-privileged accounts across the PAM estate
  • Serve as senior escalation for complex Privileged Cloud onboarding and runtime issues (connectivity, session issues, rotation failures, connector behavior)
  • Participate in incident response activities involving privileged account compromise or misuse


What you bring to the table:

  • 7+ years in IAM/Security Engineering with 5+ years in PAM engineering and demonstrable experience with IDIRA Privileged Cloud (CyberArk Privilege Cloud)
  • Strong expertise in: CPM concepts and custom plugin development and PSM session brokering and custom connector development
  • Development/scripting skills: PowerShell/Python/CyberArk REST APIs (as applicable to connectors/plugins/automation)
  • Experience with the CyberArk REST API for programmatic platform management
  • Deep understanding of MFA and federation patterns: SAML, OIDC, OAuth2, conditional access concepts, and step-up authentication
  • Hands-on experience across AWS, Azure, and GCP
  • Understanding of Zero Trust, least-privilege, and JIT access principles
  • Strong troubleshooting skills across Windows Server, Linux/Unix, and networking layers
  • Experience in a DevSecOps - CI/CD environment/ Secrets Management would be an asset
  • Strong ethical principles and understanding of business and information security ethics
  • IDIRA/CyberArk certifications: CDE- CPC is a must
  • Team player / good collaboration skills set
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to communicate complex security concepts to both technical and non-technical stakeholders
  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country
  • No Canadian work experience required however must be eligible to work in Canada

#LI-Hybrid

Il s'agit d'un nouveau rôle au sein de notre équipe en pleine croissance | This role is a new member of our growing team.
Create a job alert for this search

Security Advisor PAM Specialist • Toronto, Ontario, CAN

Similar jobs

Security specialist

Flip retailToronto, ON, CA
Full-time

Security Specialist vacancy in Toronto Canada.Security Specialist mainframe - REMOTE.Duty: Safety Specialist data processor.Ability: Protection Specification: Rational Identity & Accessibility Mgmt... Show more

 • Promoted

OT Cyber Security Advisor

Hitachi Automotive Systems Americas, Inc.Toronto
Full-time

Location:Toronto, Ontario, CanadaJob ID:R1011402Date Posted:2026-07-07Company Name:Hitachi Rail Canada Inc.Profession (Job Category):IT, Telecom & InternetJob Schedule:Full timeRemote:NoAbout UsA c... Show more

 • Promoted

Security Specialist - $95,500 - $119,400 A Year

Beem Credit UnionEast York, Canada
Full-time

Security Specialist to enhance threat detection, incident response, and cloud security using Microsoft Azure technologies, SIEM, and automation.Responsible for SOC capabilities and MSSP oversight. Show more

 • Promoted

Specialist Offensive Security - $113,683 - $155,216 A Year

ipss inc.Toronto, Canada
Full-time

Conducts penetration testing, identifies security weaknesses, and assists with remediation.Develops ethical hacking capabilities, supports the CISO's mandate, and provides security reports. Show more

 • Promoted

Senior Security Advisor: Saas & Third-Party Risk - C$101,800 - C$124,400 A Year

Financial Services ProviderEast York, Canada
Full-time

Seeking a Senior Security Advisor in Toronto for a financial services provider to focus on SaaS and third-party risk, involving cybersecurity compliance and risk assessments. Show more

 • Promoted

Security Specialist - Senior_10+yrs

Maarut IncToronto, Ontario, Canada
Full-time

The Cyber Security Centre of Excellence (COE) is seeking one (1) Senior Cyber Security Specialist to support in strengthening Ontario’s cyber security infrastructure as the province collectively mo... Show more

 • Promoted

OT Cyber Security Advisor

Hitachi Vantara Corporationtoronto, on, Canada
Full-time

A career at Hitachi Rail will help create a legacy.With operations in every corner of the world, our work goes to the cutting‑edge of digital transformation and technology.From the multi‑cultural s... Show more

 • Promoted

Lead - Vulnerability Perimeter Protection Security Specialist

Covenant HRToronto, ON, CA
Full-time

Our esteemed client is a leading financial services organization operating in the banking sector, recognized for its commitment to innovation, cybersecurity excellence, and enterprise-scale technol... Show more

 • Promoted

Hybrid Physical Security Pm — Protect & Optimize Sites - $115,000 - $135,000 A Year

Beverage CompanyToronto County, Canada
Full-time

Oversees and enhances physical security operations and technologies for a beverage company, managing daily operations and vendor relations. Show more

 • Promoted

Senior Security Advisor - Saas Security And Cyber Supply Chain Risk - C$101,800 - C$124,400 A Year

Intact Financial CorporationEast York, Canada
Full-time

Seeking a Senior Security Advisor specializing in SaaS security and cyber supply chain risk.Responsibilities include conducting third-party risk assessments, evaluating SaaS security configurations... Show more

 • Promoted

Security Advisor Specialist, Offensive Security (Global Red Team)

IntactToronto, ON, CA
Full-time

The Security Specialist, Offensive Security is responsible for testing the security controls, networks, and threat response for Intact Financial globally across all regions and affiliate companies.... Show more

 • Promoted

Security Implementation SME - Azure and Palo Alto

Tech Talent InternationalToronto, ON, CA
Full-time

Security Implementation SME - Azure and Palo Alto.Job Openings Security Implementation SME - Azure and Palo Alto.About the job Security Implementation SME - Azure and Palo Alto.Fortune 100/500/1000... Show more

 • Promoted

Security Engineer (IAM)

Sentrytoronto, on, Canada
Full-time

Software runs the world and the pace is faster than ever.Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time build... Show more

 • Promoted

Security Specialist: Flexible Hours, Paid Training - $19.5 - $21 An Hour

Gaming ComplexEast York, Canada
Full-time

Seeking a Security Officer for a gaming complex to monitor safety, enforce policies, and maintain a secure environment for guests.Requires 2 years of experience and a first aid certificate. Show more

 • Promoted

Senior Security Specialist – Vulnerability & Mss Lead - $42 - $59 An Hour

IT solutions providerToronto County, Canada
Full-time

Seeking a Senior Security Specialist for Managed Security Services in Toronto, providing 2nd level support, mentoring, and managing technical issues.Requires degree or IT experience and security ce... Show more

 • Promoted

RQ08709 - Security Specialist - Senior

Rubicon Pathtoronto, on, Canada
Full-time

About the job RQ08709 - Security Specialist - Senior.Role: Senior Security Specialists.Support the development, UAT and Production of OPS Secure environments.Monitoring the health, performance, and... Show more

 • Promoted

Security Specialist -- Siem Technologies - $33.3 - $46.5 An Hour

CdwToronto County, Canada
Full-time

Provide second-level cybersecurity incident response and client support specializing in Microsoft Sentinel and Defender.Responsibilities include monitoring, investigation, remediation, and service ... Show more

 • Promoted

Senior Specialist in Cyber Security Strategies

Rubicon PathToronto, Ontario, Canada
Full-time

Enhance Ontario's cyber security infrastructure as a Senior Cyber Security Specialist.Leverage your expertise to implement security architectural best practices and expand cyber safety education in... Show more

 • Promoted

Senior Security Specialist – Vulnerability & Mss Lead - $42 - $59 An Hour

CDW CanadaEast York, Canada
Full-time

Senior Security Specialist needed to provide technical support, mentor staff and manage complex technical issues. Show more

 • Promoted

Presales Security Expert-Communications Service Providers

Fortinet, Inc.Toronto, Ontario, Canada
Full-time

Fortinet Canada is seeking a PreSales Security Expert to support direct (Sell-to) engagements with Canadian Communications Service Providers, working in close alignment with a Major Account Manager... Show more