Senior Identity Governance and Access Management Specialist
Job Description:
Role: Senior Identity Governance and Access Management Specialist ( x 2)
Contract work: 37.7 hours (1950 hours + Optional Extension Hrs. 975)
Location: Hybrid (Ottawa, Montréal or Toronto)
Terme: 12 months with the possibility of 6-month extension
Security Clearance: Reliability
Language: English Essential, bilingual (French and English) is considered a strong asset but is not mandatory.
Scope:
Our client is seeking two (2) Senior Identity Governance and Access Management Specialists to support strategic initiatives focused on strengthening access governance, identity controls, and compliance across critical business applications.
The consultants will provide expertise in Identity and Access Management (IAM), Identity Governance and Administration (IGA), access review processes, entitlement management, service account governance, and non-human identity management. The role will focus on designing, implementing, operationalizing, and continuously improving access management controls supporting our client's financial and business-critical applications.
The consultants will contribute to remediation initiatives arising from audits, risk assessments, compliance reviews, and internal control improvements related to access governance and identity management practices. The mandate supports ongoing initiatives associated with ITSG guidance, enterprise security modernization, and the organization's access management remediation plan.
Context
Our client continues to strengthen its identity governance and access management capabilities in response to evolving cybersecurity threats, regulatory expectations, audit observations, and internal control requirements.
Recent assessments and reviews have identified opportunities to improve access governance practices across several critical financial and business applications. Particular focus has been placed on strengthening access review processes, entitlement governance, segregation of duties controls, privileged access oversight, and the governance of service accounts and non-human identities.
As part of ongoing remediation and modernization efforts, they are implementing improvements to ensure that access rights are appropriately granted, reviewed, maintained, monitored, and removed throughout the identity lifecycle.
The consultants will support initiatives related to access governance, identity lifecycle management, service account governance, non-human identity controls, and application access management processes while working closely with business owners, application custodians, cybersecurity teams, compliance stakeholders, and technology teams.
Key Responsibilities
Access Governance and Access Reviews
Design, implement, and improve access review and access certification processes.
Establish governance models for periodic access reviews across financial and business-critical applications.
Define access ownership and accountability models.
Collaborate with business owners, application custodians, and support teams to conduct access reviews.
Develop and document procedures supporting access certification activities.
Establish governance controls for entitlement management and role-based access models.
Support segregation of duties (SoD) assessments and remediation activities.
Develop metrics and reporting capabilities supporting access governance oversight.
Service Account and Non-Human Identity Governance
Assess current service account and non-human identity management practices.
Develop governance frameworks for service accounts, application accounts, APIs, automation accounts, and other non-human identities.
Define ownership, accountability, lifecycle management, and review requirements for non-human identities.
Establish processes for provisioning, approval, recertification, monitoring, and decommissioning of service accounts.
Support the implementation of privileged access controls protecting service and application accounts.
Identify and remediate risks associated with orphaned, shared, excessive, or unmanaged privileged accounts.
Identity Governance and Compliance
Support implementation of identity governance controls and standards.
Contribute to remediation activities resulting from audits, assessments, and compliance reviews.
Ensure alignment with CMHC security policies, ITSG guidance, and industry best practices.
Automation and Process Improvement
Identify opportunities to automate access review, certification, provisioning, and de-provisioning activities.
Improve operational efficiency while maintaining appropriate security controls and auditability.
Advisory and Stakeholder Engagement
Develop recommendations and implementation roadmaps to improve IAM maturity.
Support change management and adoption activities associated with new governance processes.
Technical Knowledge
Strong expertise in:
Identity and Access Management (IAM)
Identity Governance and Administration (IGA)
Access Review and Access Certification Processes
Service Account Governance
Non-Human Identity Management
Role-Based Access Control (RBAC)
Segregation of Duties (SoD)
Identity Lifecycle Management
Joiner-Mover-Leaver (JML) Processes
Microsoft Entra ID
Active Directory
Authentication and Authorization Technologies
Federation Services and Single Sign-On (SSO)
Least Privilege and Zero Trust Principles
Experience with the following technologies is considered an asset:
CyberArk
Microsoft Entra ID Governance
Microsoft Sentinel
PowerShell
Workflow Automation Platforms
Expected Deliverables
Deliverables may include:
Access governance framework recommendations.
Access review and certification processes and procedures.
Non-human identity governance standards.
Access ownership and accountability models.
Segregation of Duties assessment reports.
Remediation plans and implementation roadmaps.
Governance policies, standards, and operational procedures.
Automation recommendations and workflow designs.
Audit and compliance support documentation.
Success Criteria
Access review and certification processes are implemented and operationalized across targeted applications.
Access ownership and accountability models are formally established.
Service account and non-human identity governance processes are implemented and consistently applied.
Risks associated with excessive, orphaned, dormant, shared, or unmanaged access are significantly reduced.
Audit observations and remediation objectives related to access governance are successfully addressed.
Governance processes are adopted by business and technology stakeholders.
Compliance and audit readiness related to identity governance and access management are measurably improved.