Cloud Identity & Access Management (IAM) Engineer
Quick Summary
-Hybrid Flexibility: Enjoy a hybrid model with three days per week in our Toronto office. -Downtown Toronto Office: Work in the heart of the city. -Comprehensive Benefits: We cover 100% of health,
We are seeking a Cloud Identity & Access Management (IAM) Engineer to own, secure, and streamline access across our enterprise systems. In this role, you will architect our identity infrastructure, enforce Single Sign-On (SSO) across all applications, automate employee access lifecycles, and strictly govern application-level permissions.
Because this role oversees core identity infrastructure across our multi-cloud and SaaS environments, we require hands-on technical experience with identity protocols, cloud access policies, and security automation.
Access Administration: Serve as the technical lead for all central Identity and Access Management (IAM) operations.
SSO Architecture: Implement and enforce Single Sign-On (SSO) across all internal systems and third-party SaaS platforms.
Cloud Security: Architect cloud IAM policies, manage service accounts, and secure OAuth consent screens across multi-cloud infrastructure.
Application Governance: Audit third-party application integrations, track shadow IT, and conduct periodic access reviews with department leads to eliminate excess permissions.
Lifecycle Automation: Build automated onboarding and offboarding pipelines using SCIM, APIs, or scripts to ensure day-one access and immediate termination revocations.
Policy & Monitoring: Apply Zero Trust and Least Privilege principles to existing setups, while monitoring identity logs for anomalous activity.
Experience: 4+ years in Cybersecurity, IT Engineering, or Cloud Infrastructure, with a primary focus on IAM.
Identity Protocols: Technical proficiency in SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and SCIM.
Cloud Infrastructure: Direct experience configuring access controls, role-based policies, organizational policies, and OAuth consent pages across enterprise cloud platforms.
SaaS & Workspace: Administration experience with enterprise workspace tools and centralized Identity Providers (such as Okta, Entra ID, or Google Cloud Identity).
Automation & Code: Scripting experience in Python, Bash, Go, or PowerShell, alongside experience using REST APIs or Infrastructure as Code (Terraform) for access management.
Security Controls: Hands-on experience implementing Privileged Access Management (PAM), Just-In-Time (JIT) access, and centralized audit logging.
Location & Eligibility
Listing Details
- Posted
- September 9, 2026
- First seen
- September 10, 2026
- Last seen
- September 10, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 81%
- Scored at
- September 10, 2026
Signal breakdown
Please let Shyftlabs know you found this job on Jobera.
3 other jobs at Shyftlabs
View all →Explore open roles at Shyftlabs.
Similar Iam Engineer jobs
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
