Cyber Security Engineer specializing in IAM and application security at a company developing its cyber security program. Engage in multiple domains, including governance and vulnerability management.
Responsibilities
Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.
Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.
Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.
Design, deploy, and manage IAM lifecycle processes, ensuring principles of least privilege and zero trust are applied across the organization.
Leverage the Microsoft environment (e.g., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).
Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.
Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.
Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.
Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.
Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.
Requirements
Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.
Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.
Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.
Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.
Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.
Excellent ability to translate complex cyber risks into clear, actionable business recommendations for non-technical stakeholders.
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.