Description and Requirements
Work Location: Toronto, ON
Position Type: Contract, 6 Months
Compensation Range: 53-72 per hour
Our client, a multinational technology company, is seeking an " IAM Architect". The position is responsible for leading and overseeing the onboarding of vendor applications to use Entra ID authentication via SAML 2.0, establishing secure and reliable Single Sign-On (SSO) across applications. The candidate will design, implement, and document IAM architecture with a focus on SSO for applications, maintaining alignment with security and compliance standards. Also, he/she will configure, manage, and troubleshoot SAML-based authentication flows within Entra ID, including assertion handling, response/request management, and integration with external vendor systems. He/she will collaborate with internal teams, vendors, and stakeholders to assess IAM requirements and implement solutions that enhance user experience and security.
He/she will develop and maintain technical documentation for IAM architecture, including design diagrams, SSO workflows, and data flows tailored for technical and non-technical audiences.
Responsibilities:
- Identity and Access Management (IAM): o Expertise in IAM concepts, especially in implementing Single Sign-On (SSO) for simplified and secure access management. Strong knowledge of identity lifecycle management, including provisioning, de-provisioning, and recertification.
- Entra ID (formerly Azure AD): o Extensive experience in configuring Entra ID, including application registration, SSO configurations, user/group management, and policy administration. Proficiency in managing SAML 2.0 authentication flows within Entra ID and integrating these with various applications to support seamless SSO.
- Kerberos and Token-Based Authentication: o In-depth understanding of Kerberos authentication mechanisms, including the Ticket-Granting Ticket (TGT) and Service Ticket processes for secure access management. Expertise in configuring and troubleshooting Kerberos and token-based authentication for applications within enterprise environments.
- Security Protocols and Standards: o Proficiency in SAML 2.0, along with familiarity in OAuth 2.0 and OpenID Connect, for broad expertise in authentication standards. Knowledge of secure token handling and assertion management practices in support of SSO configurations.
- Documentation and Technical Writing: o Ability to create clear, concise, and organized technical documentation for IAM architecture, workflows, and integration patterns, using tools like Microsoft Visio and Lucidchart. Experience developing standardized templates for consistent, professional documentation across IAM projects.
- Architecture and Implementation Patterns: Experience with architecture and design patterns such as just-in-time (JIT) provisioning, role-based access control (RBAC), and zero trust. Knowledge of policy design and compliance requirements, including NIST, ISO 27001, and GDPR.
Qualifications:
- Stakeholder Communication: Strong ability to explain IAM and SSO concepts to both technical and non-technical audiences, including engaging with vendors and internal teams. Skill in creating end-user and training materials to support SSO implementation and user adoption.
- Project Management and Documentation: Experience documenting requirements, tracking project milestones, and managing version control for IAM documentation as systems evolve. Familiarity with risk assessment and change management processes to ensure IAM systems align with organizational security policies.
- Cross-Functional Collaboration: Proven experience in working closely with IT, security, and compliance teams to ensure IAM solutions meet business needs and adhere to internal policies.
All interested applicants who meet the qualifications listed above are invited to submit a resume by clicking "Apply Now".
The indicated pay range for this position is a good-faith estimate based on the qualifications necessary for the position, including experience, training, and other considerations permitted by law. Additionally, it is emphasized that the pay band mentioned herein is the one established by the client company. Factors that may be used when making an offer may include a candidate’s skills, experience and geographic location, the expected quality and quantity of work. Most candidates will start at the bottom half of the pay range, with the upper end reserved for candidates with extensive experience and skills and who live in geographic markets commanding a higher starting pay. An employee’s pay history will not be a contributing factor where prohibited by local law.
This information is subject to change and serves as a general guideline for compensation discussions. Actual offers may vary based on specific circumstances and company policies.