Cybersecurity Engineer – DevSecOps, IAM, PAM
- Toronto, ON
- Hybride
- Publié 28 août 2026
- 1 poste
Ouvre un site externe
- Type d’emploi
- Temps plein
- Niveau d’expérience
- Expérimenté · 5+ ans
- Postuler avant le
- 27 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Présence au bureau
- 4 jours par semaine
- Niveau d’expérience
- Mid-Senior level
- Mode de candidature
- La candidature directe est offerte
Résumé du poste
Manage identity and access lifecycles, including PAM and NPID governance, to enhance the organization's cybersecurity posture. Integrate security controls into CI/CD pipelines and develop Python-based automation to streamline security operations and risk reporting.
Détails du poste
Job Description: Cybersecurity Engineer – DevSecOps / IAM / PAM Location: Toronto, ON Work Arrangement: Hybrid – 4 Days Work From Office (WFO) Duration: 6–12 Months Role Overview We are seeking an experienced Cybersecurity Engineer with strong expertise in IAM, PAM, CyberArk, Active Directory, Entra ID, Python, and DevSecOps. The successful candidate will support and enhance RBC's cybersecurity posture by managing identity and access lifecycles, Non-Personal IDs (NPIDs), risk and control frameworks, and DevSecOps security integration, while driving process automation through Python-based tooling. Key Responsibilities 1. Identity & Access Management (IAM) Onboard applications and services into IAM platforms, including SailPoint, CyberArk, and Active Directory. Manage access provisioning, recertification, and deprovisioning workflows. Enforce Least Privilege and Role-Based Access Control (RBAC) policies. Support Privileged Access Management (PAM) onboarding and credential vaulting. Manage identity lifecycle processes in Azure AD / Microsoft Entra ID. 2. Non-Personal ID (NPID) Management Create, maintain, and retire Non-Personal IDs, including service accounts, shared accounts, and system IDs. Ensure NPIDs comply with password policies, rotation schedules, and ownership requirements. Conduct periodic reviews and attestations of NPID inventories. Identify and remediate orphaned, stale, or non-compliant NPIDs. Support audit and compliance activities related to service-account governance. 3. DevSecOps Security Embed security controls into CI/CD pipelines using tools such as: Jenkins Azure DevOps GitHub Actions Advise development teams on secrets management using: HashiCorp Vault Azure Key Vault Support integration and implementation of: SAST DAST SCA Work with security and development teams on tools such as Veracode, Snyk, and Checkmarx. Participate in secure code reviews and threat modeling for new applications and services. 4. Risk & Controls Management Own and track cybersecurity risk controls across assigned application portfolios. Identify, raise, manage, and remediate security risk findings and exceptions. Monitor compliance with cybersecurity policies and control requirements. Prepare risk and control reporting for audits, regulators, and senior management. Support evidence collection and remediation activities for internal and external audits. 5. Automation & Tooling Develop Python-based automation to streamline IAM workflows, NPID audits, vulnerability reporting, and other security operations. Develop integrations with internal APIs and platforms such as: Confluence ServiceNow Tableau Maintain and enhance automation pipelines for recurring security operations tasks. Use Python libraries such as pandas, requests, openpyxl, and Selenium. Develop scheduled jobs, automated data extraction, and reporting solutions to reduce manual effort. Required Skills & Qualifications Strong experience in Cybersecurity Engineering, IAM, PAM, and DevSecOps. Hands-on experience with: CyberArk Active Directory Microsoft Entra ID / Azure AD SailPoint Strong understanding of Identity & Access Management (IAM) and Privileged Access Management (PAM). Experience with Non-Personal IDs (NPIDs), service accounts, and identity governance. Strong scripting and automation skills using Python. Experience with Python libraries including pandas, requests, openpyxl, and Selenium. Working knowledge of PowerShell. Familiarity with DevSecOps practices and CI/CD security. Knowledge of Jenkins, Azure DevOps, and GitHub Actions. Experience with application security tools such as Veracode, Snyk, and Checkmarx. Knowledge of secrets-management technologies such as HashiCorp Vault and Azure Key Vault. Understanding of cybersecurity risk, controls, compliance, and audit requirements. Strong analytical, communication, and problem-solving skills. Ability to work effectively with cybersecurity, infrastructure, application development, and DevOps teams. Key Technology Stack IAM / PAM: SailPoint, CyberArk, Active Directory, Microsoft Entra ID Automation: Python, pandas, requests, openpyxl, Selenium, PowerShell DevSecOps: Jenkins, Azure DevOps, GitHub Actions Secrets Management: HashiCorp Vault, Azure Key Vault Application Security: Veracode, Snyk, Checkmarx Enterprise Tools: ServiceNow, Confluence, Tableau
Ce que vous ferez
Manage identity and access lifecycles, including PAM and NPID governance, to enhance the organization's cybersecurity posture. Integrate security controls into CI/CD pipelines and develop Python-based automation to streamline security operations and risk reporting.
Exigences
Requires strong expertise in Cybersecurity Engineering with hands-on experience in IAM tools like CyberArk and SailPoint. Proficiency in Python automation and familiarity with DevSecOps tools and risk management frameworks are essential.
Compétences indiquées
- Active Directory · Souhaitée
- Python · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- IAM
- PAM
- CyberArk
- Active Directory
- Entra ID
- Python
- DevSecOps
- SailPoint
- Azure DevOps
- Jenkins
- GitHub Actions
- HashiCorp Vault
- Veracode
- Snyk
- Checkmarx
- PowerShell
Domaines d’emploi
- Technology
- Security & Safety
- Software
- Engineering
- Consulting
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 17 sept. 2026
Connectability Inc.
Technical Sales Specialist
Employeur directCandidature simplifiée- Hybride
- Publié 5 sept. 2026
Government of Ontario
Analyste principal de gestion; analyste principale de gestion
CommanditéEmployeur directCandidature simplifiée- Sur place
- Toronto, ON
- Publié 31 août 2026