Cloud Identity & Access Management (IAM) Engineer
Summary
ShyftLabs is hiring a Cloud IAM Engineer in Toronto (hybrid, 3 days/week in-office) to architect identity infrastructure: enforcing SSO, governing application permissions, automating employee onboarding/offboarding, and securing multi-cloud access. Core stack includes SAML/OIDC/OAuth/SCIM, IdPs like Okta or Entra ID, and automation with Python/Terraform.
Role Overview
We are seeking a Cloud Identity & Access Management (IAM) Engineer to own, secure, and streamline access across our enterprise systems. In this role, you will architect our identity infrastructure, enforce Single Sign-On (SSO) across all applications, automate employee access lifecycles, and strictly govern application-level permissions.
Because this role oversees core identity infrastructure across our multi-cloud and SaaS environments, we require hands-on technical experience with identity protocols, cloud access policies, and security automation.
What You'll Do
-
Access Administration: Serve as the technical lead for all central Identity and Access Management (IAM) operations.
-
SSO Architecture: Implement and enforce Single Sign-On (SSO) across all internal systems and third-party SaaS platforms.
-
Cloud Security: Architect cloud IAM policies, manage service accounts, and secure OAuth consent screens across multi-cloud infrastructure.
-
Application Governance: Audit third-party application integrations, track shadow IT, and conduct periodic access reviews with department leads to eliminate excess permissions.
-
Lifecycle Automation: Build automated onboarding and offboarding pipelines using SCIM, APIs, or scripts to ensure day-one access and immediate termination revocations.
-
Policy & Monitoring: Apply Zero Trust and Least Privilege principles to existing setups, while monitoring identity logs for anomalous activity.
What You'll Bring
-
Experience: 4+ years in Cybersecurity, IT Engineering, or Cloud Infrastructure, with a primary focus on IAM.
-
Identity Protocols: Technical proficiency in SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and SCIM.
-
Cloud Infrastructure: Direct experience configuring access controls, role-based policies, organizational policies, and OAuth consent pages across enterprise cloud platforms.
-
SaaS & Workspace: Administration experience with enterprise workspace tools and centralized Identity Providers (such as Okta, Entra ID, or Google Cloud Identity).
-
Automation & Code: Scripting experience in Python, Bash, Go, or PowerShell, alongside experience using REST APIs or Infrastructure as Code (Terraform) for access management.
-
Security Controls: Hands-on experience implementing Privileged Access Management (PAM), Just-In-Time (JIT) access, and centralized audit logging.
Salary Range
- $90,000 - $110,000 (CAD)
Skills
As published by lever · 3 questions
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, GitHub URL, Portfolio URL
Short answers (1)
- How soon can you join after receiving an offer?
Pick from a list (2)
- Are you authorized to work for any employer in Canada? optional
- Will you require sponsorship now or in the future? optional