17 Aug
|
AceStack
|
Toronto
Job Title: IAM Engineer Location: Toronto, ON Work Mode: Onsite Employment Type: Full-Time Experience: 5+ Years Job Description: Design and implement Azure Entra ID identity governance frameworks and access management solutions Configure and manage Privileged Identity Management (PIM) to enable just-in-time privileged access Implement and enforce Conditional Access policies, MFA, FIDO2, Passkeys, and phishing-resistant authentication methods Manage Azure RBAC role assignments across subscriptions, resource groups, and management groups Review and remediate guest user accounts, stale identities, excessive permissions, and access-related risks Configure, maintain, monitor, and secure Break Glass emergency access accounts Implement monitoring and alerting for privileged and emergency access activities Integrate Microsoft Defender for Cloud governance recommendations with Service
Now ticketing workflows Support cross-cloud IAM alignment and access governance across AWS IAM and OCI IAM environments Participate in IAM audits, access reviews, identity governance assessments, and compliance reporting Develop and maintain IAM runbooks, RBAC mapping documentation, access procedures, and onboarding guides Support identity lifecycle management, access provisioning, deprovisioning,
and access certification processes Analyze and implement Microsoft Defender for Cloud and Secure Score recommendations related to identity security Collaborate with security, infrastructure, application, compliance, and business teams to resolve IAM issues Ensure IAM solutions align with Zero Trust, security, governance, and organizational access control standards Required Qualifications: 5+ years of experience in Identity and Access Management, with 3+ years of hands-on Microsoft Azure / Entra ID experience Solid knowledge of Azure RBAC, PIM, Conditional Access, Entra ID roles, and identity governance Hands-on experience with MFA enforcement, authentication methods, access policies, and privileged access management Strong understanding of identity lifecycle management and access certification processes Experience with Microsoft Defender for Cloud and Secure Score recommendations Experience with Service
Now or similar ticketing system integrations for IAM workflows Strong documentation, analytical, troubleshooting, and stakeholder communication skills Microsoft Certified: Identity and Access Administrator Associate (SC-300) certification is preferred Nice to Have: Experience with AWS IAM, AWS Organizations, and Service Control Policies Knowledge of OCI IAM compartments, policies, and access structures Exposure to SASE and Zero Trust Network Access (ZTNA) frameworks
📌 IAM Engineer (Toronto)
🏢 AceStack
📍 Toronto