HM Note: This hybrid contract role is three 3 days in office. Candidates resume must include first and last name.
Description
Project Overview:
Supply Ontario is implementing a modern cyber security program to strengthen our defenses and manage digital risk. A core pillar of this program is the development of a secure and scalable Identity and Access Management (IAM) framework that supports zero trust principles enhances user experience and protects sensitive assets.
The Senior IAM Specialist will be responsible for establishing and managing user identity lifecycle processes access governance privileged access controls and integration of IAM tools across the agencys platforms.
Experience required:
- Minimum 7 years of handson experience in IAMfocused roles within enterprise environments.
- Deep understanding of IAM principles protocols (SAML OAuth2 OpenID Connect) and technologies.
- Proven experience with leading IAM platforms such as Azure Active Directory Okta Ping Identity ForgeRock SailPoint CyberArk or similar.
- Experience designing and implementing RBAC ABAC and JustInTime (JIT) access models.
- Knowledge of zero trust architecture and secure access best practices.
- Familiarity with regulatory standards and frameworks (NIST 80063 ISO 27001 SOC 2 CIS).
- Experience conducting IAMrelated risk assessments and remediating audit findings.
- Strong documentation skills and ability to produce clear and actionable technical and business content.
- Effective communicator with ability to collaborate with both technical and nontechnical stakeholders.
Deliverables
The Senior IAM Specialist is expected to play a pivotal role in the successful of a robust IAM practice.
Their responsibilities and expectations encompass the following:
- Design and implement a robust IAM strategy aligned with Supply Ontarios risk profile regulatory requirements and business needs.
- Support the design and evolution of IAM architecture to ensure scalability security and alignment with enterprise infrastructure.
- Define and manage identity lifecycle processes (provisioning deprovisioning recertification).
- Develop and enforce access control policies and rolebased access models (RBAC).
- Manage and integrate IAM solutions (e.g. Azure AD Okta Etc. across cloud and onprem environments.
- Implement and support multifactor authentication (MFA) single signon (SSO) and privileged access management (PAM) solutions.
- Monitor and audit accessrelated events; respond to IAMrelated incidents and vulnerabilities.
- Conduct access reviews segregation of duties (SoD) checks and periodic user entitlement audits.
- Collaborate with infrastructure application and external teams/vendors to align IAM practices across systems.
- Develop documentation including policies procedures standards and guidelines.
- Contribute to the broader cyber security program by supporting governance compliance and incident response efforts as needed.
Desirable Qualifications:
- Bachelors degree in Computer Science Information Security or related field.
- Certifications such as Certified Identity and Access Manager (CIAM) Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM)
- Experience in public sector or regulated environments is a plus.
and nbsp;
Must Haves:
and nbsp; and nbsp; and nbsp; and nbsp; and nbsp; and nbsp; and nbsp; and nbsp;3 years experience IAM principles protocols (SAML OAuth2 OpenID Connect) and technologies.
- 3 years experience and nbsp;Proven experience with leading IAM platforms such as Azure Active Directory Okta
- 3 years experience designing and implementing RBAC ABAC and JustInTime (JIT) access model