07 Aug
|
Intact Financial
|
Mississauga
07 Aug
Intact Financial
Mississauga
About the roleWe are seeking a Senior PAM Specialist with deep hands‐on expertise in IDIRA (formerly CyberArk) to lead the design and architecture of our PAM program and to build advanced integrations, including custom CPM plugins, PSM connectors for MFA‐enabled applications, and forward‐leaning capabilities such as Agentic AI vaulting and JIT (Just‐in‐time) implementation.What you'll do hereOwn solution architecture for IDIRA Privileged Cloud including tenant design, setting segregation (prod/non‐prod), network connectivity patterns, identity federation/SSO, and operational hardeningDefine onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidenceEstablish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information‐related risksDevelop and maintain custom CPM plugins for systems and applications not supported out‐of‐the‐boxEngineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportabilityCreate standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycleDesign and build custom PSM connectors for: Web applications (including complex flows), thick clients/legacy applications, and administrative tools requiring step‐up authenticationEngineer solutions for MFA‐enabled apps, balancing automation and security (e.G., brokered sessions, step‐up patterns, conditional access alignment, approved MFA handling approaches)Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break‐glass procedures)Lead deployment and adoption of SIA capabilities to enable just‐in‐time access and zero‐standing privilege for infrastructure and cloud workloadsDefine end‐to‐end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocationIntegrate SIA patterns into operational processes (incident response, privileged break‐glass,
platform engineering standards)Implement automation using APIs and event‐driven patterns to reduce manual effort while maintaining strict auditability and change controlDesign privileged access patterns across AWS, Azure, and GCP, including privileged roles, automation identities, and administrative access modelsSecure cloud administrative sessions and credentials for: cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, managed services (databases, secrets services, CI/CD runners, serverless)Design and implement vaulting strategies for Agentic AI identities—autonomous AI agents, LLM orchestrators, robotic process automation (RPA) bots, and AI‐driven pipelines that require privileged credentialsEnforce least‐privilege principles for AI agents accessing sensitive systems, databases, and cloud servicesParticipate in the development of organizational standards for AI agent identity governance and credential hygieneIdentify and remediate security gaps, misconfigurations, and over‐privileged accounts across the PAM estateServe as senior escalation for complex Privileged Cloud onboarding and runtime issues (connectivity, session issues, rotation failures, connector behavior)Participate in incident response activities involving privileged account compromise or misuseWhat you bring to the table7+ years in IAM/Security Engineering with 5+ years in PAM engineering and demonstrable experience with IDIRA Privileged Cloud (CyberArk Privilege Cloud)Strong expertise in CPM concepts and custom plugin development and PSM session brokering and custom connector developmentDevelopment/scripting skills: PowerShell, Python, CyberArk REST APIs (as applicable to connectors/plugins/automation)Experience with the CyberArk REST API for programmatic platform managementDeep understanding of MFA and federation patterns: SAML, OIDC, OAuth2, conditional access concepts, and step‐up authenticationHands‐on experience across AWS, Azure, and GCPUnderstanding of Zero Trust,
least‐privilege, and JIT access principlesStrong troubleshooting skills across Windows Server, Linux/Unix, and networking layersExperience in a DevSecOps – CI/CD environment/Secrets Management would be an assetStrong ethical principles and understanding of business and information security ethicsIDIRA/CyberArk certifications: CDE‐CPC is a mustTeam player / good collaboration skills setStrong analytical and problem‐solving skills with attention to detailAbility to communicate complex security concepts to both technical and non‐technical stakeholdersFor candidates located in Quebec, bilingualism is requiredNo Canadian work experience required however must be eligible to work in CanadaBenefitsFlexible work arrangements and hybrid work modelPossibility to purchase up to 5 extra days off per yearMultiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account, and moreShare plan and other savings up to 12% of salary or more (ask how you could earn guaranteed income for life)Salary range (based on 35‐hour workweek): 118,700 – 145,100 CADAnnual bonus target 15% of base salary, with potential payout up to double the targetEmployee Share Purchase Plan (ESPP) – Intact matching 50% of your net sharesPension offerings providing flexibility and long‐term security, including a defined benefit pension plan with guaranteed income for lifeRewards for high performance, such as tax‐free bonus and profit sharingEqual Opportunity EmployerWe are an equal opportunity employer. We strive to create an accessible workplace where employees feel valued, included, and encouraged to share their unique perspectives. We encourage applications from individuals who are members of equity‐deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community. As part of Intact's commitment to reconciliation, we acknowledge that we work, meet and travel across Canada, originally inhabited by First Nations, Metis and Inuit people. We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). #J-18808-Ljbffr
📌 Security Advisor Pam Specialist (Mississauga)
🏢 Intact Financial
📍 Mississauga