Cloud Identity & Access Management (IAM) Engineer
Quick Summary
-Hybrid Flexibility: Enjoy a hybrid model with three days per week in our Toronto office. -Downtown Toronto Office: Work in the heart of the city. -Comprehensive Benefits: We cover 100% of health,
We are seeking a Cloud Identity & Access Management (IAM) Engineer to own, secure, and streamline access across our enterprise systems. In this role, you will architect our identity infrastructure, enforce Single Sign-On (SSO) across all applications, automate employee access lifecycles, and strictly govern application-level permissions.
Because this role oversees core identity infrastructure across our multi-cloud and SaaS environments, we require hands-on technical experience with identity protocols, cloud access policies, and security automation.
Access Administration: Serve as the technical lead for all central Identity and Access Management (IAM) operations.
SSO Architecture: Implement and enforce Single Sign-On (SSO) across all internal systems and third-party SaaS platforms.
Cloud Security: Architect cloud IAM policies, manage service accounts, and secure OAuth consent screens across multi-cloud infrastructure.
Application Governance: Audit third-party application integrations, track shadow IT, and conduct periodic access reviews with department leads to eliminate excess permissions.
Lifecycle Automation: Build automated onboarding and offboarding pipelines using SCIM, APIs, or scripts to ensure day-one access and immediate termination revocations.
Policy & Monitoring: Apply Zero Trust and Least Privilege principles to existing setups, while monitoring identity logs for anomalous activity.
Experience: 4+ years in Cybersecurity, IT Engineering, or Cloud Infrastructure, with a primary focus on IAM.
Identity Protocols: Technical proficiency in SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and SCIM.
Cloud Infrastructure: Direct experience configuring access controls, role-based policies, organizational policies, and OAuth consent pages across enterprise cloud platforms.
SaaS & Workspace: Administration experience with enterprise workspace tools and centralized Identity Providers (such as Okta, Entra ID, or Google Cloud Identity).
Automation & Code: Scripting experience in Python, Bash, Go, or PowerShell, alongside experience using REST APIs or Infrastructure as Code (Terraform) for access management.
Security Controls: Hands-on experience implementing Privileged Access Management (PAM), Just-In-Time (JIT) access, and centralized audit logging.
Location & Eligibility
Listing Details
- Posted
- September 9, 2026
- First seen
- September 10, 2026
- Last seen
- September 10, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 81%
- Scored at
- September 10, 2026
Signal breakdown
Please let Shyftlabs know you found this job on Jobera.
3 other jobs at Shyftlabs
View all →Explore open roles at Shyftlabs.
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
