Staff Security Engineer, IAM in Canada Creek, Nova Scotia at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Engineer, IAM based in Canada .
As a Staff Security Engineer, IAM, you’ll serve as a senior technical leader shaping how a global workforce securely accesses critical tools, platforms, and emerging AI technologies. You’ll tackle complex identity challenges across enterprise IAM, cloud environments, infrastructure-as-code, and non-human identities. This role combines deep hands-on engineering with architectural thinking, technical strategy, and cross-functional leadership. You’ll help move identity operations from manual configuration toward secure, automated, peer-reviewed code and engineered services. You’ll influence technical roadmaps while partnering with Security, IT, Engineering, Compliance, and other business teams. You’ll also mentor experienced engineers and help establish modern practices for identity and AI security. The environment is highly autonomous, remote-first, fast-moving, and designed for engineers who enjoy solving ambiguous, high-impact problems.
- Design scalable identity and access solutions, including AI agent governance, privileged access workflows, just-in-time provisioning, and least-privilege frameworks.
- Replace low-code and manual automation with engineered Python services deployed through serverless infrastructure, incorporating source control, testing, CI/CD, and observability.
- Codify identity platforms and critical configurations using Terraform, OpenTofu, or Pulumi, leading migrations from click-based administration to peer-reviewed infrastructure-as-code.
- Help re-architect identity and access across GCP and AWS environments, including resource hierarchies, organization policies, SCPs, permission boundaries, and workload identity federation.
- Lead identity and access engineering for enterprise AI platforms, covering administration, SSO, SCIM, audit logging, data controls, and policy enforcement.
- Pioneer non-human identity governance covering service accounts, API keys, certificates, AI agents, and MCP integrations, while supporting the deployment and operationalization of NHI management capabilities.
- Drive cross-functional security initiatives by translating ambiguous business requirements into clear technical specifications and actionable solutions.
- Develop technical proposals and architectural recommendations that influence engineering roadmaps and long-term security strategy.
- Conduct design and code reviews, establish engineering best practices, and raise the technical quality of identity and security solutions.
- Mentor senior and intermediate engineers, supporting their technical growth and helping build expertise in modern IAM and AI security practices.
- Extensive experience designing and implementing enterprise-scale Identity and Access Management solutions, with demonstrated experience operating at Staff or senior individual-contributor level.
- Expert-level experience with Okta, including Identity Engine, advanced authentication policies, lifecycle workflows, and API automation.
- Strong infrastructure-as-code expertise with Terraform, OpenTofu, or Pulumi, including experience managing SaaS identity platforms declaratively and migrating manual configurations into code.
- Strong Python engineering skills, with experience developing modular, tested, code-reviewed services deployed through GCP Cloud Run or comparable serverless environments.
- Deep knowledge of cloud identity within GCP and/or AWS, including organizational design, IAM policy models, workload identity federation, organization policies, SCPs, and permission boundaries.
- Hands-on experience administering or governing enterprise AI platforms such as Anthropic Claude, OpenAI ChatGPT Enterprise, Google Gemini Enterprise, or comparable technologies.
- Understanding of AI-specific security risks, including prompt injection, MCP attack surfaces, AI agent identity, and data leakage.
- Demonstrated daily use of AI-assisted engineering tools such as Claude Code, Cursor, or similar platforms, with the ability to incorporate evolving AI capabilities into engineering workflows.
- Experience with Identity Governance and Administration platforms such as Lumos, ConductorOne, or similar solutions, ideally with a declarative management approach.
- Experience working in regulated environments and familiarity with frameworks such as FedRAMP, SOC 2, and SOX, including change management, evidence collection, and audit support.
- Strong interest in emerging identity challenges such as AI agent governance, non-human identity management, zero-trust architecture, and behavioral analytics is highly valued.
- Experience leading cloud organization restructuring, including migration execution and stakeholder coordination, is an asset.
- Strong communication, technical leadership, problem-solving, and mentoring skills, with the ability to operate effectively in ambiguous and rapidly evolving environments.
- Base salary range of $168,000–$238,000 USD, with the final level and compensation determined based on experience, skills, qualifications, market data, equity considerations, and geographic location.
- Equity compensation and employee stock purchase plan.
- Comprehensive benefits supporting health, finances, and overall well-being.
- Flexible paid time off.
- Growth and Development Fund to support ongoing learning and professional development.
- Parental leave.
- Team Member Resource Groups supporting connection, inclusion, and community.
- Fully remote work environment with location-based eligibility depending on the role and country.
- Opportunity to work on high-impact identity, cloud security, AI governance, and non-human identity challenges at global scale.
- A culture that emphasizes autonomy, continuous learning, knowledge sharing, and practical use of AI as an engineering productivity multiplier.