23 Aug
|
AceStack
|
Toronto
Job Title: IAM Engineer
Location: Toronto, ON
Work Model: Onsite
Employment Type: Full time (FTE)
Experience: 8 - 10 Years
Salery: 110K
Job Summary
"Key Responsibilities
•
Design and implement Azure Entra ID (formerly Azure AD) identity governance frameworks.
•
Configure and manage Privileged Identity Management (PIM) for just-in-time privileged access.
•
Implement and enforce Conditional Access policies, MFA, and phishing-resistant authentication (FIDO2, Passkeys).
•
Manage RBAC role assignments across Azure subscriptions, resource groups, and management groups.
•
Remediate guest user accounts, stale identities, and excessive permission assignments.
•
Configure and maintain Break Glass (emergency access) accounts with monitoring and alerting.
•
Integrate Microsoft Defender for Cloud governance rules with ServiceNow for ticketing workflows.
•
Support cross-cloud IAM alignment across AWS IAM and OCI IAM where applicable.
•
Participate in IAM audits, access reviews, and compliance reporting.
•
Develop IAM runbooks,
RBAC mapping documentation, and onboarding guides.
Required Qualifications
•
5+ years of IAM experience, with 3+ years in Microsoft Azure / Entra ID.
•
Deep knowledge of Azure RBAC, PIM, Conditional Access, and Entra ID roles.
•
Experience with MFA enforcement, authentication methods, and access policies.
•
Understanding of identity lifecycle management and access certification processes.
•
Familiarity with Microsoft Defender for Cloud and Secure Score recommendations.
•
Experience with ServiceNow or ticketing system integrations for IAM workflows.
•
Microsoft Certified: Identity and Access Administrator (SC-300) preferred.
•
Strong documentation and stakeholder communication skills.
Nice to Have
•
Experience with AWS IAM, Organizations, and SCPs.
•
Knowledge of OCI IAM compartments and policy structures.
•
Exposure to SASE or Zero Trust Network Access (ZTNA) frameworks."
📌 IAM Engineer : Toronto, ON (Hybrid): Full time
🏢 AceStack
📍 Toronto