04 Aug
|
Socket.dev
|
Calgary
04 Aug
Socket.dev
Calgary
We are
We began life in 2001 as a small, self-funded team of technology specialists. Since then, we’ve grown our organization to 16,700 people, across 57 offices, in 22 countries, in key global markets.
Innovative tech solutions for business
We're now a leading global digital consulting firm, providing innovative technology solutions for business. As a trusted partner, we're always at the forefront of change as we lead digital optimization and modernization journeys for our clients.
Customized end-to-end solutions
Our expertise in AI, Consulting, Data, Digital, Cloud & DevOps and Software Engineering, delivers customized, end-to-end solutions that drive business value and growth.
Our challenge
We are seeking experienced Senior Application Security / Identity Security Engineer with strong experience in authentication, authorization, and modern identity protocols. This role will focus on designing, implementing, and securing identity integrations across internal and external systems, ensuring secure access management and alignment with security best practices and audit requirements.
The ideal candidate will have hands-on experience with MFA, TOTP, SSO/SAML, OAuth, and OpenID Connect (OIDC), along with a strong understanding of AuthN/AuthZ patterns, secure integration architecture, and application security principles. Experience supporting regulated environments, external system integrations, and security or compliance frameworks such as SOC 2 is highly valued.
The Role - Senior Application Security / Identity Security Engineer
Responsibilities:
- Design, implement, and support secure authentication and authorization solutions across enterprise applications and external integrations
- Build and maintain identity and access management integrations using protocols such as SAML, OAuth 2.0, OIDC, and SSO
- Implement and enhance multi-factor authentication (MFA) solutions, including TOTP-based authentication
- Collaborate with engineering, infrastructure, and security teams to ensure secure access controls are embedded into application and platform design
- Review application and system integrations to ensure proper AuthN/AuthZ controls are in place when external systems are invoked
- Apply secure development and architecture best practices across authentication flows, APIs, and third-party integrations
- Conduct security reviews and support remediation of vulnerabilities identified through assessments, testing, or tooling
- Partner with internal stakeholders on security governance, risk reviews, and audit preparedness, including work related to SOC 2 and similar controls
- Support threat modeling, security design reviews, and risk assessments for identity-related implementations
- Recommend and implement security tooling and controls to improve visibility and reduce application and identity-related risk
- Contribute to documentation, standards, and operational procedures related to identity security and application access management
Requirements:
- 5+ years of experience in application security, identity security, IAM, or security engineering
- Strong hands-on experience with:
- Multi-Factor Authentication (MFA)
- TOTP
- Single Sign-On (SSO)
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- Strong understanding of authentication and authorization concepts and how they apply to enterprise applications, APIs, and external system integrations
- Experience implementing or reviewing secure integrations where external systems or services are invoked
- Knowledge of security best practices for application and identity architecture
- Experience supporting or participating in security audits, compliance reviews, or control assessments such as SOC 2
- Ability to work cross-functionally with technical and non-technical stakeholders
- Strong communication, documentation, and problem-solving skills
Preferred Qualifications
- Experience in financial services, fintech, or other regulated industries
- Familiarity with OWASP security principles and secure coding best practices
- Experience with application security and vulnerability management tools such as Snyk
- Relevant certifications such as:
- CISSP
- CCSP
- Security+
- Identity-related or cloud security certifications
- Experience with API security, federation, and identity lifecycle management
- Exposure to cloud identity platforms and enterprise IAM tooling
- Experience conducting or supporting risk assessments, control testing, or security architecture reviews
We can offer you
- A multinational organization with 57 offices in 22 countries and the possibility to work abroad
- 15 days (3 weeks) of paid annual leave plus an additional 10 days of personal leave (floating days and sick days)
- A comprehensive insurance plan including: medical, dental, vision, life insurance, and long term disability
- Flexible hybrid policy to fit your schedule
- RRSP with employer’s contribution up to 4%
- A higher education certification policy
- On-demand Udemy for Business for all Synechron employees with free access to more than 5000 curated courses
- Coaching opportunities with experienced colleagues from our Financial Innovation Labs (FinLabs) and Center of Excellences (CoE) groups
SYNECHRON’S DIVERSITY & INCLUSION STATEMENT
Diversity & Inclusion are fundamental to our culture, and Synechron is proud to be an equal opportunity workplace and is an affirmative action employer. Our Diversity, Equity, and Inclusion (DEI) initiative ‘Synclusive’ is committed to fostering an inclusive culture – promoting equality, diversity and an setting that is respectful to all. We strongly believe that a diverse workforce helps build stronger, successful businesses as a global company. We encourage applicants from across diverse backgrounds, race, ethnicities, religion, age, marital status, gender, sexual orientations, or disabilities to apply. We empower our global workforce by offering flexible workplace arrangements, mentoring, internal mobility, learning and development programs, and more.
All employment decisions at Synechron are based on business needs, job requirements and individual qualifications, without regard to the applicant’s gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law.
📌 Senior Application Security / Identity Security Engineer (Calgary)
🏢 Socket.dev
📍 Calgary