Identity & Access Management (IAM) Specialist (Temporary)
Offre en anglaisThe specialist is responsible for assessing, designing, and implementing enterprise identity and access management capabilities across hybrid environments. This includes managing identity lifecycles, privileged access, and ensuring alignment with security and compliance requirements.
- Sur place
- Toronto, ON
- Publié 14 août 2026
- Postuler avant le 13 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Résumé du poste
Position Description * This role is a 3-month temporary position with the possibility of extension* The Identity & Access Management (IAM) Specialist is responsible for assessing, designing, implementing, and improving enterprise identity and access management capabilities. The specialist works with security, infrastructure, application, cloud, and business teams to ensure that identities are securely authenticated, appropriately authorized, governed throughout their lifecycle, and aligned with organizational security and compliance requirements.The role requires strong knowledge of Microsoft Active Directory and Entra ID, authentication and authorization technologies, Identity Governance and Administration (IGA), Privileged Access Management (PAM), federation, Single Sign On (SSO), Multi Factor Authentication (MFA), Conditional Access, and Zero Trust principles. Your future duties and responsibilities Conduct current-state assessments of enterprise IAM environments, processes, technologies, and security controls. Review IAM architecture, policies, standards, procedures, and operating models. Assess authentication and authorization mechanisms across applications, infrastructure, cloud platforms, and enterprise services. Identify IAM security gaps, technical risks, process deficiencies, and control weaknesses. Evaluate IAM capabilities against recognized security frameworks, industry best practices, and Zero Trust principles. Develop prioritized recommendations, remediation plans, and IAM maturity roadmaps. Facilitate workshops and stakeholder interviews with security, infrastructure, application, architecture, and business teams. Identity Architecture & Authentication Assess and design enterprise identity architectures across on-premises, cloud, and hybrid environments. Review Active Directory and Microsoft Entra ID architecture, configuration, trust relationships, synchronization, and identity flows. Assess authentication technologies including password-based authentication, MFA, passwordless authentication, and FIDO2/passkeys. Review Single Sign-On (SSO) and federation architectures. Evaluate implementations of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, and LDAP. Review Conditional Access policies and risk-based authentication controls. Identify and recommend remediation for legacy and weak authentication mechanisms. Assess authentication flows for users, administrators, service accounts, applications, APIs, and workload identities. Identity Governance & Administration (IGA) Assess Joiner, Mover, and Leaver (JML) lifecycle processes. Review user provisioning, modification, deprovisioning, and termination processes. Evaluate Role-Based Access Control (RBAC) and other access control models. Review access request and approval workflows. Assess access certification and periodic access review processes. Review segregation of duties (SoD) controls and identify excessive or conflicting access. Evaluate entitlement management and application onboarding processes. Support IAM/IGA solutions including SailPoint, Saviynt, Microsoft Entra ID Governance, and comparable platforms. Privileged Access Management (PAM) Assess privileged accounts, administrative identities, and elevated access processes. Review Privileged Access Management (PAM) and Privileged Identity Management (PIM) controls. Evaluate privileged account discovery, credential vaulting, credential rotation, and session management processes. Review Just-in-Time (JIT) and Just Enough Administration (JEA) approaches. Assess emergency and break-glass account controls. Review privileged access to Active Directory, Microsoft Entra ID, servers, databases, applications, and cloud platforms. Support CyberArk, Microsoft Entra PIM, BeyondTrust, and equivalent PAM solutions. Service, Application & Machine Identities Assess service accounts, application identities, API identities, and machine-to-machine authentication mechanisms. Review service principals, managed identities, certificates, API keys, and application secrets. Identify unmanaged or excessive permissions assigned to non-human identities. Recommend secure credential, certificate, and secrets management practices. Assess workload identity lifecycle and governance controls. Security Monitoring & Operations Review IAM-related logging, monitoring, and alerting capabilities. Assess detection capabilities for identity-based attacks including credential compromise, privilege escalation, password spraying, and anomalous authentication activities. Review integration between IAM platforms and SIEM/SOC capabilities. Define and recommend IAM security metrics, KPIs, and KRIs. Support investigation, response, and remediation of identity-related security incidents. Recommend improvements to IAM operational monitoring and continuous security practices. Required Qualifications To Be Successful In This Role 5+ years of cybersecurity, identity and access management (IAM), infrastructure security, or related experience, with significant hands-on IAM expertise. Strong knowledge of Microsoft Active Directory and Microsoft Entra ID. Strong understanding of authentication and authorization concepts and technologies. Experience with Multi-Factor Authentication (MFA), Conditional Access, Single Sign-On (SSO), federation, and passwordless authentication. Working knowledge of SAML, OAuth 2.0, OpenID Connect (OIDC), Kerberos, and LDAP. Experience with Identity Governance and Administration (IGA) concepts and technologies. Experience with Privileged Access Management (PAM) concepts, processes, and solutions. Strong understanding of identity lifecycle management and Joiner, Mover, Leaver (JML) processes. Knowledge of Role-Based Access Control (RBAC), least privilege principles, segregation of duties (SoD), and access certification processes. Understanding of hybrid identity environments and cloud IAM architectures. Knowledge of service accounts, workload identities, application authentication, and non-human identity management. Understanding of Zero Trust security principles and identity-centric security architectures. Ability to assess complex IAM environments and translate findings into practical, risk-based remediation recommendations. Strong technical documentation, stakeholder interviewing, workshop facilitation, communication, and presentation skills. Preferred Technology Experience Microsoft Entra ID (Azure AD) Microsoft Entra ID Governance Microsoft Entra Privileged Identity Management (PIM) Microsoft Active Directory SailPoint Saviynt CyberArk BeyondTrust Okta Ping Identity Microsoft Defender for Identity Microsoft Sentinel ServiceNow Preferred Certifications Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Security certifications Microsoft Azure certifications SailPoint certifications Saviynt certifications CyberArk certifications Okta certifications Certified Information Systems Security Professional (CISSP) Certified Cloud Security Professional (CCSP) Vendor-neutral IAM, Identity Governance, or Cybersecurity certifications. CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $95,000-$145,000. This role is an existing vacancy. Together, as owners, let’s turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because… You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction. Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. At CGI, we value the strength that diversity brings and are committed to fostering a workplace where everyone belongs. We collaborate with our clients to build more inclusive communities and empower all CGI partners to thrive. As an equal-opportunity employer, being able to perform your best during the recruitment process is important to us. If you require an accommodation, please inform your recruiter. That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals. To learn more about accessibility at CGI, contact us via email. Please note that this email is strictly for accessibility requests and cannot be used for application status inquiries. Come join our team—one of the largest IT and business consulting services firms in the world.
Ce que vous ferez
The specialist is responsible for assessing, designing, and implementing enterprise identity and access management capabilities across hybrid environments. This includes managing identity lifecycles, privileged access, and ensuring alignment with security and compliance requirements.
Exigences
Requires over 5 years of experience in cybersecurity or IAM with deep expertise in Microsoft Active Directory and Entra ID. Candidates must have strong knowledge of authentication protocols, IGA, PAM, and Zero Trust principles.
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Identity And Access Management
- Microsoft Entra ID
- Active Directory
- Identity Governance And Administration
- Privileged Access Management
- Multi-Factor Authentication
- Single Sign-On
- Zero Trust
- SAML
- OAuth 2.0
- OpenID Connect
- Role-Based Access Control
- Conditional Access
- Identity Lifecycle Management
- Technical Documentation
- Stakeholder Management
Domaines d’emploi
- Security & Safety
- Technology
- Consulting
- Software
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Postuler avant le
- 13 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Entry level
- Mode de candidature
- La candidature directe est offerte