×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Engineer – DevSecOps, IAM, PAM

Job in Toronto, Ontario, M5A, Canada
Listing for: Astra North Infoteck Inc.
Full Time position
Listed on 2026-08-29
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations, Systems Engineer
Job Description & How to Apply Below
Job Description

Job Description:

Cybersecurity Engineer – Dev Sec Ops  / IAM / PAM

Location: Toronto, ON

Work Arrangement: Hybrid – 4 Days Work From Office (WFO)

Duration: 6–12 Months

Role Overview

We are seeking an experienced Cybersecurity Engineer with strong expertise in IAM, PAM, Cyber Ark, Active Directory, Entra , Python, and Dev Sec Ops .

The successful candidate will support and enhance RBC's cybersecurity posture by managing identity and access lifecycles, Non-Personal IDs (NPIDs), risk and control frameworks, and Dev Sec Ops  security integration, while driving process automation through Python-based tooling.

Key Responsibilities
1. Identity & Access Management (IAM)
  • Onboard applications and services into IAM platforms, including SailPoint, Cyber Ark, and Active Directory
    .
  • Manage access provisioning, recertification, and deprovisioning workflows.
  • Enforce Least Privilege and Role-Based Access Control (RBAC) policies.
  • Support Privileged Access Management (PAM) onboarding and credential vaulting.
  • Manage identity lifecycle processes in Azure AD / Microsoft Entra .
2. Non-Personal  (NPID) Management
  • Create, maintain, and retire Non-Personal IDs, including service accounts, shared accounts, and system IDs.
  • Ensure NPIDs comply with password policies, rotation schedules, and ownership requirements.
  • Conduct periodic reviews and attestations of NPID inventories.
  • Identify and remediate orphaned, stale, or non-compliant NPIDs.
  • Support audit and compliance activities related to service-account governance.
3. Dev Sec Ops  Security
  • Embed security controls into CI/CD pipelines using tools such as:
    • Jenkins
    • Azure Dev Ops
    • Git Hub Actions
  • Advise development teams on secrets management using:
    • Hashi Corp Vault
    • Azure Key Vault
  • Support integration and implementation of:
    • SAST
    • DAST
    • SCA
  • Work with security and development teams on tools such as Veracode, Snyk, and Checkmarx
    .
  • Participate in secure code reviews and threat modeling for new applications and services.
4. Risk & Controls Management
  • Own and track cybersecurity risk controls across assigned application portfolios.
  • Identify, raise, manage, and remediate security risk findings and exceptions.
  • Monitor compliance with cybersecurity policies and control requirements.
  • Prepare risk and control reporting for audits, regulators, and senior management.
  • Support evidence collection and remediation activities for internal and external audits.
5. Automation & Tooling
  • Develop Python-based automation to streamline IAM workflows, NPID audits, vulnerability reporting, and other security operations.
  • Develop integrations with internal APIs and platforms such as:
    • Confluence
    • Service Now
    • Tableau
  • Maintain and enhance automation pipelines for recurring security operations tasks.
  • Use Python libraries such as pandas, requests, openpyxl, and Selenium
    .
  • Develop scheduled jobs, automated data extraction, and reporting solutions to reduce manual effort.
Required

Skills & Qualifications
  • Strong experience in Cybersecurity Engineering, IAM, PAM, and Dev Sec Ops .
  • Hands-on experience with:
    • Cyber Ark
    • Active Directory
    • Microsoft Entra  / Azure AD
    • Sail Point
  • Strong understanding of Identity & Access Management (IAM) and Privileged Access Management (PAM).
  • Experience with Non-Personal IDs (NPIDs), service accounts, and identity governance
    .
  • Strong scripting and automation skills using Python
    .
  • Experience with Python libraries including pandas, requests, openpyxl, and Selenium
    .
  • Working knowledge of Power Shell
    .
  • Familiarity with Dev Sec Ops  practices and CI/CD security.
  • Knowledge of Jenkins, Azure Dev Ops, and Git Hub Actions
    .
  • Experience with application security tools such as Veracode, Snyk, and Checkmarx
    .
  • Knowledge of secrets-management technologies such as Hashi Corp Vault and Azure Key Vault
    .
  • Understanding of cybersecurity risk, controls, compliance, and audit requirements.
  • Strong analytical, communication, and problem-solving skills.
  • Ability to work effectively with cybersecurity, infrastructure, application development, and Dev Ops teams.
Key Technology Stack

IAM / PAM: SailPoint, Cyber Ark, Active Directory, Microsoft Entra

Automation: Python, pandas, requests, openpyxl, Selenium, Power Shell

Dev Sec Ops : Jenkins, Azure Dev Ops, Git Hub Actions

Secrets Management: Hashi Corp Vault, Azure Key Vault

Application Security: Veracode, Snyk, Checkmarx

Enterprise Tools: Service Now, Confluence, Tableau

Requirements
60-70
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary