Strategy Advisor, Identity

1 day ago

Toronto ON, Toronto Census Division, ON; Ontario, Canada Clear Destination Inc. Full-time €170,000 - €185,000 Temporary
Paid vacation, personal, and sick days for work-life balance Work-life balance in a hybrid environment with at least 3 days in office Career growth and development opportunities Opportunities to contribute to community causes We’re looking for our next Strategy Advisor, Identity & Access Management. The Advisor, Identity & Access Management Strategy owns the enterprise identity strategy across Questrade Financial Group’s regulated entities. The role sets direction, standards and the multi-year roadmap for workforce identity, privileged access, identity governance and administration, and non-human identity (including Agentic Identity), and leads the IAM team that delivers them. It is accountable for the identity control environment meeting business, security and regulatory requirements in each QFG entity, and for the vendor decisions, governance and evidence that keep it there. deep technical execution is led by the Principal Engineer, Identity & Access Management, and other IAM team members, under this role’s direction. This role operates within a CIRO-regulated dealer and an OSFI-regulated federal financial institution (FRFI) environment. Candidates must understand that entity segregation between Questrade Inc. and Questbank is a foundational architectural constraint. Client identity (CIAM): this role defines and represents the security requirements, standards and controls that client-facing identity platforms must meet, and contributes to policy engine design to minimize account takeover risks. aligning with business, technology and security strategy; Leading requirements-first selection of identity platforms and vendors: defining control requirements before evaluating products, running trade-off analysis, and recording decisions. No platform is adopted or retired without a documented decision. Entity governance and regulatory Owning the identity control and compliance posture of each QFG regulated entity separately, including entity-scoped design, evidence and reporting. Maintaining the identity dimensions of OSFI Guideline B-13, third-party access expectations under OSFI Guideline B-10, resilience considerations under OSFI Guideline E-21, and CIRO cybersecurity expectations, producing evidence in the form of auditors and regulators can test. Setting standards for access, authentication and authorization across the workforce: single sign-on, personal password management, MFA and authentication escalation, risk-based access, and the joiner-mover-leaver lifecycle. Owning privileged access program outcomes: vault coverage, credential rotation, JIT/JEA, session accountability and emergency access, with measurable targets and quarterly reporting. Owning the IGA strategy: authoritative attribute sourcing from HR systems, the role and entitlement model, automated provisioning and deprovisioning, and access certification across all enterprise platforms, with check-and-balance controls for data quality, integrity and timeliness. Owning governance of non-human identity: service accounts, agentic identities, workload identities, API keys and secrets across on-premises, GCP, AWS, Azure and Microsoft Entra, including inventory, ownership, rotation and least privilege. Directing effort by risk, not evenly. People management addressing performance in a timely manner. Building succession depth and cross-training so that no identity capability depends on a single person. Partnering with Enterprise Architecture, cloud and data leadership, DevSecOps, JSOC, Enterprise Fraud, GRC, Privacy, Legal, People & Culture and User Experience; Sponsoring identity-related change programs across entities and building adoption through clear communication at executive and technical levels. So are YOU our next Strategy Advisor, Identity & Access Management? Have deep experience working across privileged access management (Delinea), identity governance and administration (SailPoint), Microsoft Entra and the EMS E5 security stack, and identity threat detection (CrowdStrike Identity Protection): enough to set direction, challenge designs and hold vendors to account Have demonstrated proficiency in Hybrid Identity Architecture: governing complex identity environments spanning Active Directory (AD), Microsoft Entra (formerly Azure AD), and GCP federation Have experience governing non-human identity at scale: service accounts, secrets and workload identity across cloud providers Have strong experience with budget planning and financial management for technology programs Possess Executive and Board-level verbal and written communication skills, at a standard suitable for regulator-facing documentation Have strong stakeholder management skills in a matrixed organization with ability to influence without direct authority and hold people to committed dates addressing performance early; building morale, belonging and succession Are Bilingual
- written and verbal fluency in English and French Ho