03 Oct
|
Intact Financial
|
Mississauga
03 Oct
Intact Financial
Mississauga
Together, we help people, businesses, and society prosper in valuable times and be resilient in bad times. In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us. Flexible wellbeing, including telemedicine, Wellness account and much more Annual bonus the target (subject to personal and company performance):
Win As A Team , we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares. Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.
Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. Senior PAM Specialist and JIT (Just-in-time) implementation. Own solution architecture for IDIRA Privileged Cloud including tenant design, environment segregation (prod/non-prod), network connectivity patterns, identity federation/SSO, and operational hardening
Define onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidence
Establish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)
Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information-related risks for systems and applications not supported out-of-the-box
Engineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportability
Create standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycle for:
Web applications (including complex flows),Thick clients / legacy applications and Administrative tools requiring step-up authentication
MFA-enabled apps , balancing automation and security (e.g., Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break-glass procedures)
Lead deployment and adoption of SIA Define end-to-end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocation
Integrate SIA patterns into operational processes (incident response, privileged break-glass, platform engineering standards)
Implement automation using APIs and event-driven patterns to reduce manual effort while maintaining strict auditability and change control
AWS, Azure, and GCP , including privileged roles, automation identities, and administrative access models.
Secure cloud administrative sessions and credentials for: Cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, Managed services (databases, secrets services, CI/CD runners, serverless)
Design and implement vaulting strategies for Agentic AI identities — autonomous AI agents, LLM orchestrators, robotic process automation (RPA) bots, and AI-driven pipelines that require privileged credentials
Enforce least-privilege principles for AI agents accessing sensitive systems, databases, and cloud services
Participate in the development of organizational standards for AI agent identity governance and credential hygiene
Identify and remediate security gaps, misconfigurations, and over-privileged accounts across the PAM estate
Serve as senior escalation for complex Privileged Cloud onboarding and runtime issues (connectivity, session issues, rotation failures, connector behavior)
Participate in incident response activities involving privileged account compromise or misuse 7+ years in IAM/Security Engineering with 5+ years in PAM engineering PowerShell / Python/CyberArk REST APIs (Hands-on experience across AWS, Azure, and GCP
Solid troubleshooting skills across Windows Server, Linux/Unix, and networking layers
Experience in a DevSecOps - CI/CD environment/ Secrets Management would be an asset
Strong ethical principles and understanding of business and information security ethics
Ability to communicate complex security concepts to both technical and non-technical stakeholders For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country
No Canadian work experience required however must be eligible to work in Canada #At Intact, our Value of respect is founded on seeing diversity as a strength. We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community. As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people.
We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). A copy of applicable policies is available on request. Please note that Intact does not provide sponsorship or other support for immigration-related matters including but not limited to employer-specific closed work permits.
If you are an employee of Intact or belairdirect, please apply for this role on Internal Career Site.
📌 Security Testing Specialist (Mississauga)
🏢 Intact Financial
📍 Mississauga