Security Advisor PAM Specialist
Job in
Montreal, Montréal, Province de Québec, Canada
Listing for:
Intact Financial Corporation
Full Time
position
Listed on 2026-07-27
Job specializations:
Job Description & How to Apply Below
Location: MontrealPay at Intact is about much more than just salary.
Flexible work arrangements and a hybrid work model
Possibility to purchase up to 5 extra days off per year
Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more
Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)
Salary range (but not limited to):
118,
Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):
15%
As part of our commitment to Win As A Team
, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.
Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.
Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.
About the role
We are seeking a Senior PAM Specialist with deep hands-on expertise in IDIRA (formerly Cyber Ark) to lead the design and architecture of our PAM program and to build advanced integrations, including custom CPM plugins, PSM connectors for MFA-enabled applications, and forward-leaning capabilities such as Agentic AI vaulting and JIT (Just-in-time) implementation.
What you'll do here:
Own solution architecture for IDIRA Privileged Cloud including tenant design, environment segregation (prod/non-prod), network connectivity patterns, identity federation/SSO, and operational hardeningDefine onboarding standards for privileged accounts, safes, platforms, rotation policies, session controls, approvals, and audit evidenceEstablish reusable reference architectures for common target types (Windows, Linux/Unix, databases, network devices, cloud consoles, SaaS admin portals)Ensure key risk metrics/indicators are developed and implemented to systematically measure and report information-related risksDevelop and maintain custom CPM plugins for systems and applications not supported out-of-the-boxEngineer rotation, verification, and reconciliation logic with robust error handling, logging, and supportabilityCreate standardized development practices (code reviews, versioning, testing harnesses, release process) for CPM plugin lifecycleDesign and build custom PSM connectors for:
Web applications (including complex flows),Thick clients / legacy applications and Administrative tools requiring step-up authenticationEngineer solutions for MFA-enabled apps, balancing automation and security (e.g., brokered sessions, step-up patterns, conditional access alignment, approved MFA handling approaches)Provide technical guidance to app teams on requirements to enable rotation (API enablement, service accounts, least privilege, break-glass procedures)Lead deployment and adoption of SIA capabilities to enable just-in-time access and zero-standing privilege for infrastructure and cloud workloadsDefine end-to-end SIA workflows: request/approval, entitlement mapping, session initiation, auditing, and revocationIntegrate SIA patterns into operational processes (incident response, privileged break-glass, platform engineering standards)Implement automation using APIs and event-driven patterns to reduce manual effort while maintaining strict auditability and change controlDesign privileged access patterns across AWS, Azure, and GCP, including privileged roles, automation identities, and administrative access models.Secure cloud administrative sessions and credentials for:
Cloud consoles and CLI access, Kubernetes (EKS/AKS/GKE) administrative workflows, Managed services (databases, secrets services, CI/CD runners, serverless)Design…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here: