Principal Identity & Access Management (IAM) Engineer at Aviso Wealth | Canada | Rezi

Principal Identity & Access Management (IAM) Engineer at Aviso Wealth

Principal Identity & Access Management (IAM) Engineer

Aviso Wealth · Canada

4 days ago

Principal Identity & Access Management (IAM) Engineer

Aviso Wealth · Canada

4 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Aviso is seeking a Principal Identity & Access Management (IAM) Engineer to join the Technology Ops & Support Partners team. This role is responsible for the end-to-end IAM lifecycle, including defining policies, standards, and target-state architecture, as well as implementing solutions through configuration, automation, and integration.

Responsibilities

  • Own and continuously evolve the enterprise Identity & Access Management (IAM) strategy, policies, and standards across authentication, authorization, lifecycle, and access governance, mapped to NIST CSF 2.0, CIRO, PIPEDA, and SOC/ITGC obligations.
  • Oversee the end-to-end identity architecture across workforce SSO/MFA, IGA, PAM, directory/federation, and B2B partner identity; guide the ongoing optimization of the toolset and advance federation and provisioning patterns within a Zero Trust model.
  • Drive continuous improvement of the joiner-mover-leaver lifecycle for internal users and the onboarding/offboarding experience for external partner firms and advisors.
  • Grow and improve the access review and recertification program across internal and external populations, refine the entitlement catalogue and SoD controls, and strengthen reporting.
  • Implement designed solutions: configure platforms, build connectors and app onboarding, and automate with PowerShell/Microsoft Graph, Python, and Terraform/Bicep.
  • Partner with Security/CISO, Technology Ops, application owners, and external partner firms to support audits and regulatory reviews.
  • Monitor adherence to change governance requirements, support the end-to-end lifecycle of standard, normal, and emergency changes, and escalate exceptions, risks, and control gaps as required.

Requirements

  • 8+ years of experience in IAM, with deep, demonstrated coverage of authentication, authorization, federation, identity governance, and directory services.
  • Hands-on experience across the stack: at least one IGA platform (e.g., SailPoint, Saviynt, or Entra ID Governance), a workforce identity platform (Entra ID and/or Okta), and a PAM solution.
  • Proven design of RBAC/ABAC models, entitlement catalogues, SoD controls, and access certification / recertification programs.
  • Strong capability with federation and provisioning protocols: SAML, OIDC, OAuth 2.0, SCIM.
  • Proven scripting/automation ability — you can build, not just specify (PowerShell + Graph API, Python; IaC a plus).
  • Experience with governing external / B2B partner identity — federation with partner IdPs, delegated administration, and lifecycle/reviews for external users.
  • Track record in a regulated environment (financial services strongly preferred) with audit and compliance fluency.
  • Able to translate technical access risk into clear business and executive-level risk language.
  • Fluent communication skills in English are required.
  • Bilingual skills in French are an asset.

Skills

  • Identity & Access Management (IAM)
  • Authentication
  • Authorization
  • Federation
  • Identity Governance
  • Directory Services
  • IGA platforms (SailPoint, Saviynt, Entra ID Governance)
  • Workforce identity platforms (Entra ID, Okta)
  • PAM solutions
  • RBAC/ABAC models
  • Entitlement catalogues
  • SoD controls
  • Access certification / recertification programs
  • SAML
  • OIDC
  • OAuth 2.0
  • SCIM
  • PowerShell
  • Microsoft Graph API
  • Python
  • Terraform/Bicep
  • IaC
  • B2B partner identity governance
  • NIST CSF 2.0
  • CIRO
  • PIPEDA
  • SOC/ITGC
  • Zero Trust model

Location

  • Toronto
  • Vancouver
  • Montreal

Work Type

  • Full-time

Experience Level

  • Principal

Salary/Compensations

  • $130,000 - $140,000 CAD annually

Benefits

  • Competitive compensation package
  • Excellent health, dental and insurance benefits
  • Generous vacation time
  • Fitness benefit
  • Parental leave top-up options
  • Matching contributions to our retirement program
  • Continuous improvement through learning & development
  • Education assistance program
  • Regular social events

About the Company

  • Aviso is a leading wealth management and investment services provider for the Canadian financial industry, with approximately $145 billion in total assets under administration and management, and over 1,000 employees.
  • We’re building a comprehensive, technology-enabled, client-centric wealth services ecosystem.
  • Our clients include our partners, advisors, and investors.
  • We’re a trusted partner for nearly all credit unions across Canada, in addition to a wide range of portfolio managers, investment dealers, insurance and trust companies, and introducing brokers.
  • Our investment dealer and mutual fund dealer and our insurance services support thousands of investment advisors.
  • Our asset manager, NEI Investments, specializes in investing responsibly.
  • Our online brokerage, Qtrade Direct Investing®, empowers self-directed investors, and our fully automated investing service, Qtrade Guided Portfolios®, serves investors who prefer a hands-off approach.
  • Aviso Correspondent Partners provides custodial and carrying broker services to a wide range of firms.
  • We have offices in Toronto, Vancouver, and Montreal.
  • Aviso is backed by the collective strength of our owners: the credit union Centrals, Co-operators/CUMIS, and Desjardins.
  • We’re proud to power businesses that empower investors.
  • A career with Aviso means being part of a group of talented, energetic professionals who live their values every day, and belonging to an organization dedicated to your success and career development.

Equal Opportunity

  • Aviso welcomes and encourages applications from all qualified individuals including persons with disabilities. If you require an accommodation, we will work with you to meet your needs in all stages of the hiring process.