Cyber Security Engineer specializing in IAM and application security at a company developing its cyber security program. Engage in multiple domains, including governance and vulnerability management.
Responsibilities
Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.
Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.
Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.
Design, deploy, and manage IAM lifecycle processes, ensuring principles of least privilege and zero trust are applied across the organization.
Leverage the Microsoft environment (e.g., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).
Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.
Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.
Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.
Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.
Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.
Requirements
Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.
Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.
Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.
Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.
Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.
Excellent ability to translate complex cyber risks into clear, actionable business recommendations for non-technical stakeholders.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.