Architect, implement, and maintain automated IAM solutions spanning on-premises and cloud environments with focus on enterprise Active Directory and SailPoint integrations
Develop and optimize automation scripts, workflows, and connectors (PowerShell, BeanShell, Python, etc.) for provisioning, deprovisioning, group management, access reviews, and certifications
Lead integration projects between SailPoint (IdentityNow/IdentityIQ), Active Directory (including Azure AD), and cloud security solutions (Zscaler, Okta, AWS IAM, Azure Security, etc.)
Design, deploy, and manage automated access controls and RBAC policies ensuring compliance with security and privacy regulations (SOX, GDPR, HIPAA)
Serve as subject matter expert for Active Directory including schema management, GPOs, privileged access, domain trust relationships, and hybrid identity synchronization
Automate and orchestrate processes across cloud security tools for secure onboarding/offboarding, privilege management, and audit trail generation
Troubleshoot complex IAM and directory synchronization issues and lead root-cause analysis for identity/access incidents
Partner with IT, cloud, and security engineering teams to drive automation best practices and cross-platform security initiatives
Maintain comprehensive documentation for architectures, workflows, procedures, and configuration changes in the IAM ecosystem
Lead IAM-related audit support, evidence collection, and remediation activities using automated tools and reporting
Requirements
Bachelor's or master's degree in computer science, Information Security, or a related technical field
7+ years of progressively responsible experience in enterprise IAM engineering, with significant automation responsibility
Expert-level knowledge of Active Directory (user and group management, GPO, delegation, AD security, hybrid/cloud sync)
Advanced, hands-on experience with SailPoint (IdentityNow or IdentityIQ), including identity lifecycle automation, custom connector development, and policy enforcement
Proven ability to automate IAM and security administration via scripting (PowerShell, Python, BeanShell, or similar)
Demonstrated experience automating tasks within leading cloud security platforms (AWS IAM, Azure AD, Zscaler, Okta, Google Workspace, etc.)
Strong understanding of identity protocols (LDAP, SAML, OIDC, OAuth2.0, SCIM) and cloud/on-prem integration patterns
Solid grasp of RBAC, least-privilege approaches, and regulatory/compliance drivers (SOX, GDPR, HIPAA)
Excellent analytical, troubleshooting, and communication skills
Experience with Infrastructure as Code (IaC), CI/CD pipelines, or SOAR platforms is a plus
SailPoint Certified Engineer (IdentityNow or IdentityIQ) and Microsoft Certified: Identity and Access Administrator or equivalent is a plus
Experience with identity governance, privileged access management (PAM), and multi-cloud IAM strategies is a plus
Knowledge of French is required for permanent positions in Quebec
Fluency in English is required
Benefits
Comprehensive health benefits, life and disability insurance, and fertility and family-forming support programs
Generous paid time off, paid holidays, volunteer time off, and quarterly self-care days and no meeting days
Tuition and reading reimbursement programs to support continuous learning and professional growth
Thrive Global Wellness Program, confidential Employee Assistance Program (EAP), and One to One Wellness Coaching
Employee programs—including Employee Resource Groups (ERGs), GoTo Gives, and charitable matching program
Registered Retirement Savings Plan (RRSP)
Gym reimbursement programs
Access to telemedicine services
GoTo performance bonus program
Monthly remote work stipend to support home office expenses
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Active DirectorySailPointPowerShellPythonBeanShellRBACidentity protocolsInfrastructure as CodeCI/CD pipelinesidentity governance