Senior Iam Engineer — Oauth, Sso & Rbac (Hybrid) - C$137,000 - C$189,000 A Year
MongoDBToronto County, CanadaDesign and deliver secure services for internal and external users.Requires 5+ years of experience in backend systems. Show more
Job Title: IAM Engineer
Location: Toronto, ON
Work Mode: Onsite
Employment Type: Full-Time
Experience: 5+ Years
Job Description:
Design and implement Azure Entra ID identity governance frameworks and access management solutions
Configure and manage Privileged Identity Management (PIM) to enable just-in-time privileged access
Implement and enforce Conditional Access policies, MFA, FIDO2, Passkeys, and phishing-resistant authentication methods
Manage Azure RBAC role assignments across subscriptions, resource groups, and management groups
Review and remediate guest user accounts, stale identities, excessive permissions, and access-related risks
Configure, maintain, monitor, and secure Break Glass emergency access accounts
Implement monitoring and alerting for privileged and emergency access activities
Integrate Microsoft Defender for Cloud governance recommendations with ServiceNow ticketing workflows
Support cross-cloud IAM alignment and access governance across AWS IAM and OCI IAM environments
Participate in IAM audits, access reviews, identity governance assessments, and compliance reporting
Develop and maintain IAM runbooks, RBAC mapping documentation, access procedures, and onboarding guides
Support identity lifecycle management, access provisioning, deprovisioning, and access certification processes
Analyze and implement Microsoft Defender for Cloud and Secure Score recommendations related to identity security
Collaborate with security, infrastructure, application, compliance, and business teams to resolve IAM issues
Ensure IAM solutions align with Zero Trust, security, governance, and organizational access control standards
Required Qualifications:
5+ years of experience in Identity and Access Management, with 3+ years of hands-on Microsoft Azure / Entra ID experience
Strong knowledge of Azure RBAC, PIM, Conditional Access, Entra ID roles, and identity governance
Hands-on experience with MFA enforcement, authentication methods, access policies, and privileged access management
Strong understanding of identity lifecycle management and access certification processes
Experience with Microsoft Defender for Cloud and Secure Score recommendations
Experience with ServiceNow or similar ticketing system integrations for IAM workflows
Strong documentation, analytical, troubleshooting, and stakeholder communication skills
Microsoft Certified: Identity and Access Administrator Associate (SC-300) certification is preferred
Nice to Have:
Experience with AWS IAM, AWS Organizations, and Service Control Policies
Knowledge of OCI IAM compartments, policies, and access structures
Exposure to SASE and Zero Trust Network Access (ZTNA) frameworks
IAM Engineer • Toronto, ON, Canada