SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Aviso, a leading Canadian wealth management organization, is seeking a Principal Identity & Access Management (IAM) Engineer to join the Technology Ops & Support Partners team, reporting to the Director of Technology Support Services.
This is a hands-on, architecture-and-implementation role. You will own the enterprise IAM strategy, policies, and standards across authentication, authorization, lifecycle management, and access governance. Your work will be mapped to regulatory frameworks including NIST CSF 2.0, CIRO, PIPEDA, and SOC/ITGC obligations, and translated into business-level risk communication for leadership.
Key responsibilities include:
- Designing and evolving the end-to-end identity architecture across workforce SSO/MFA, identity governance and administration (IGA), privileged access management (PAM), directory services, and federation. You will guide optimization of the toolset (Entra ID, Okta/Ping, SailPoint/Saviynt, CyberArk) and advance federation and provisioning patterns (SAML, OIDC, OAuth 2.0, SCIM, FIDO2) within a Zero Trust model.
- Driving continuous improvement of joiner-mover-leaver lifecycle processes for internal users and onboarding/offboarding for external partner firms and advisors. You will expand delegated administration, B2B federation, and least-privilege scoping through automated, auditable workflows.
- Growing and improving the access review and recertification program across internal and external populations. You will refine the entitlement catalogue, strengthen segregation-of-duties (SoD) controls, and build reporting to demonstrate who has access to what, why, and when it was last reviewed—with audit-ready evidence.
- Implementing what you design: configuring platforms, building connectors and app onboarding, and automating with PowerShell/Microsoft Graph, Python, and Terraform/Bicep. You will partner with Security/CISO, Technology Ops, application owners, and external partner firms to support audits and regulatory reviews.
- Monitoring adherence to change governance, supporting the end-to-end lifecycle of standard, normal, and emergency changes, and escalating exceptions, risks, and control gaps.
Required experience:
- 8+ years in IAM with deep, demonstrated coverage of authentication, authorization, federation, identity governance, and directory services.
- Hands-on experience across the stack: at least one IGA platform (SailPoint, Saviynt, or Entra ID Governance), a workforce identity platform (Entra ID and/or Okta), and a PAM solution.
- Proven design of RBAC/ABAC models, entitlement catalogues, SoD controls, and access certification/recertification programs.
- Strong capability with federation and provisioning protocols: SAML, OIDC, OAuth 2.0, SCIM.
- Proven scripting and automation ability—you can build, not just specify (PowerShell + Graph API, Python; Infrastructure as Code a plus).
- Experience governing external/B2B partner identity, including federation with partner identity providers, delegated administration, and lifecycle/reviews for external users.
- Track record in a regulated environment, with financial services strongly preferred. Audit and compliance fluency required.
- Ability to translate technical access risk into clear business and executive-level risk language.
- Fluent English communication; French bilingual skills are an asset.
Aviso values leadership, innovation, partnership, responsibility, and community. The company culture emphasizes caring for clients and colleagues, daring to challenge the status quo, sharing knowledge and diverse perspectives, and delivering meaningful results with accountability.