×
Register Here to Apply for Jobs or Post Jobs. X

Principal Identity & Access Management (IAM) Engineer

Job in Toronto, Ontario, C6A, Canada
Listing for: Aviso
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 130000 - 140000 CAD Yearly CAD 130000.00 140000.00 YEAR
Job Description & How to Apply Below

Aviso: At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso' culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at

The Opportunity

We're looking to fill an opening for a Principal Identity & Access Management (IAM) Engineer to join our Technology Ops & Support Partners team.

Reporting to the Director, Technology Support Services, the Principal IAM Engineer is responsible for IAM end-to-end: defining the policies, standards, target-state architecture and building.

This is not a slideware role. You'll design the model and then implement it — configuring tooling, writing automation, integrating applications, and standing up the governance that lets us prove who has access to what, for both internal users and external partners.

The Principal IAM Engineer will also monitor adherence to change governance requirements, support the end-to-end lifecycle of standard, normal, and emergency changes, and escalate exceptions, risks, and control gaps as required.

As oneaviso
  • We Care
    - You do the right thing for clients, partners and colleagues. You build trusted relationships, champion service excellence, and contribute to a culture where people feel valued and supported
  • We Dare
    -You challenge the status quo with bold ideas and fresh perspectives. You embrace change, seek opportunities to innovate and are comfortable exploring new ways of working
  • We Share
    - You collaborate openly and build meaningful relationships. You seek out diverse perspectives, share your knowledge and work together to help colleagues, clients and partners succeed
  • We Deliver
    - You take ownership of your work, honour your commitments and focus on delivering meaningful results. You hold yourself accountable and continuously look for ways to improve
What your day looks like
  • Own and continuously evolve the enterprise Identity & Access Management (IAM) strategy, policies, and standards across authentication, authorization, lifecycle, and access governance, mapped to NIST CSF 2.0, CIRO, PIPEDA, and SOC/ITGC obligations, and translated into business-level risk for leadership
  • Oversee the end-to-end identity architecture across workforce SSO/MFA, IGA, PAM, directory/federation, and B2B partner identity; guide the ongoing optimization of the toolset (e.g., Entra , Okta/Ping, SailPoint/Saviynt, Cyber Ark) and advance federation and provisioning patterns (SAML, OIDC, OAuth 2.0, SCIM, FIDO2) within a Zero Trust model
  • Drive continuous improvement of the joiner-mover-leaver lifecycle for internal users and the onboarding/offboarding experience for external partner firms and advisors, expanding delegated administration, B2B federation, and least-privilege scoping through automated, auditable workflows
  • Grow and improve the access review and recertification program across internal and external populations, refine the entitlement catalogue and SoD controls, and strengthen reporting so we can consistently demonstrate who has access to what, why, and when it was last reviewed with audit-ready evidence
  • Implement what you design: configure platforms, build connectors and app onboarding, and automate with Power Shell/Microsoft Graph, Python, and Terraform/Bicep; partner with Security/CISO, Technology Ops, application owners, and external partner firms to support audits and regulatory reviews
Requirements Your experience and skills
  • 8+ years of experience in IAM, with deep, demonstrated coverage of authentication, authorization, federation, identity governance, and directory services
  • Hands‑on experience across the stack: at least one IGA platform (e.g., SailPoint, Saviynt, or Entra ), a workforce identity platform (Entra /or Okta), and a PAM solution
  • Proven design of RBAC/ABAC models, entitlement catalogues, SoD controls, and access certification / recertification…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary