IAM Security Architect

  • Location: Ottawa, Ontario
  • Remote: Remote
  • Type: Contract
  • Job #35516

Our client, a leading Canadian financial institution, is seeking an experienced IAM Security Architect to join its Cyber Resilience Transformation Program.

This is an outstanding opportunity for a senior Identity & Access Management (IAM) professional to define and lead enterprise IAM strategy, Zero Trust identity architecture, identity governance, privileged access management, and next-generation identity capabilities supporting AI-enabled solutions.

The successful consultant will play a strategic role in shaping the organization’s long-term IAM roadmap while providing architectural leadership across cloud, infrastructure, applications, and cybersecurity initiatives.


Key Responsibilities

Reporting to the Program Manager, Cyber Resilience Transformation Program, you will:

  • Provide senior IAM architecture, advisory, and governance services across enterprise initiatives
  • Develop the Bank’s IAM strategy, target-state architecture, and multi-year roadmap
  • Lead the implementation of Zero Trust Identity principles across:
    • Users
    • Applications
    • Devices
    • Workloads
    • Services
    • AI-enabled solutions
  • Design enterprise IAM architectures and governance frameworks
  • Establish authentication, authorization, identity governance, and privileged access standards
  • Architect solutions leveraging:
    • Microsoft Entra ID
    • SailPoint
    • CyberArk
    • Azure Key Vault
  • Define enterprise standards for:
    • Identity Governance
    • Identity Lifecycle Management
    • Access Certification
    • Entitlement Management
    • Privileged Access Management (PAM)
  • Develop enterprise approaches for managing:
    • Service Accounts
    • Workload Identities
    • APIs
    • Secrets
    • Certificates
    • Machine-to-Machine Authentication
  • Lead the development of IAM governance for AI agents and emerging technologies
  • Review solution architectures and provide technical leadership across project teams
  • Identify IAM capability gaps, security risks, and governance deficiencies
  • Collaborate with cybersecurity, cloud, infrastructure, application, and enterprise architecture teams
  • Develop architecture standards, governance artifacts, executive presentations, and implementation roadmaps
  • Provide mentorship and knowledge transfer to internal teams

Required Qualifications

  • University degree or College diploma in Computer Science, Information Security, Engineering, or a related discipline
  • Minimum 5 years of recent experience in:
    • Identity & Access Management
    • Information Security
    • Cyber Security
  • Minimum 3 years of recent experience as:
    • IAM Security Architect
    • IAM Architect
    • Identity Security Consultant
  • Experience working within complex, highly regulated enterprise environments
  • Demonstrated experience:
    • Assessing enterprise IAM maturity
    • Designing target-state IAM architectures
    • Developing enterprise IAM roadmaps
    • Designing Identity Governance solutions
    • Implementing Zero Trust Identity
    • Designing Authentication & Authorization frameworks
    • Privileged Access Management
    • Identity Governance & Administration (IGA)
    • Developing IAM standards and governance frameworks

Technical Expertise

Strong experience with:

  • Microsoft Entra ID (Azure AD)
  • SailPoint
  • CyberArk
  • Azure Key Vault
  • Identity Governance
  • Identity Lifecycle Management
  • Access Certification
  • Authentication
  • Authorization
  • Zero Trust Architecture
  • Privileged Access Management (PAM)
  • Identity Governance & Administration (IGA)
  • Secrets Management
  • Federation
  • Enterprise IAM
  • Cloud Identity
  • API Security
  • Machine Identities
  • Workload Identities
  • Service Accounts

Nice-to-Have

Experience with:

  • Financial Services
  • Highly Regulated Environments
  • TOGAF
  • SABSA
  • Enterprise Architecture
  • AI Governance
  • AI Identity Management
  • Identity Threat Detection
  • Identity Monitoring
  • Identity Analytics

Preferred Certifications

One or more of:

  • CISSP
  • CISM
  • Microsoft Identity Certifications
  • SailPoint Certifications
  • CyberArk Certifications
  • TOGAF
  • SABSA

Work Arrangement

  • Fully Remote within Canada
  • Full-time (37.5 hours/week)

Mandatory Requirements

Candidates must:

  • Be eligible to obtain Bank of Canada Secret Security Clearance
  • Have resided in Canada for a minimum of 5 years
  • Possess excellent communication and stakeholder management skills
  • Be comfortable presenting architectural recommendations to both technical teams and executive leadership

Candidates must also have:

  • Windows 11 device capable of connecting through Azure Virtual Desktop
  • Smartphone capable of running Microsoft Authenticator
Attach a Resume file. Accepted file types are DOC, DOCX, PDF, HTML, and TXT.

We are uploading your application. It may take a few moments to read your resume. Please wait!