Strategy Advisor, Identity
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Questrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure.
At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work.
Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG.
What's in it for you as an employee of QFG?
Health & wellbeing resources and programs
Paid vacation, personal, and sick days for work-life balance
Competitive compensation and benefits packages
Work-life balance in a hybrid environment with at least 3 days in office
Career growth and development opportunities
Opportunities to contribute to community causes
Work with diverse team members in an inclusive and collaborative environment
This job posting is for an existing vacancy.
We're looking for our next Strategy Advisor, Identity & Access Management. Could It Be You?
The Advisor, Identity & Access Management Strategy owns the enterprise identity strategy across Questrade Financial Group's regulated entities. The role sets direction, standards and the multi-year roadmap for workforce identity, privileged access, identity governance and administration, and non-human identity (including Agentic Identity), and leads the IAM team that delivers them. It is accountable for the identity control environment meeting business, security and regulatory requirements in each QFG entity, and for the vendor decisions, governance and evidence that keep it there. This is a strategy and leadership role; deep technical execution is led by the Principal Engineer, Identity & Access Management, and other IAM team members, under this role's direction.
This role operates within a CIRO-regulated dealer and an OSFI-regulated federal financial institution (FRFI) environment. Candidates must understand that entity segregation between Questrade Inc. and Questbank is a foundational architectural constraint.
Need more details? Keep reading...
In this role, responsibilities include but are not limited to:
Scope and boundaries
Owning enterprise identity strategy, standards, roadmap and governance for workforce identity life-cycle, privileged access, IGA and non-human identity across all QFG entities.
Delegating hands-on design and engineering execution to the Principal Engineer, IAM, and the IAM team. This role directs, prioritizes and is accountable for outcomes.
Client identity (CIAM): this role defines and represents the security requirements, standards and controls that client-facing identity platforms must meet, and contributes to policy engine design to minimize account takeover risks. Platform delivery ownership follows the enterprise architecture decision on the CIAM target state.
Strategy and roadmap
Owning the Enterprise and Client IAM vision, strategy and multi-year roadmap across all QFG entities; aligning with business, technology and security strategy; secure executive approval and funding.
Leading requirements-first selection of identity platforms and vendors: defining control requirements before evaluating products, running trade‐off analysis, and recording decisions. No platform is adopted or retired without a documented decision.
Entity governance and regulatory
Owning the identity control and compliance posture of each QFG regulated entity separately, including entity‐scoped design, evidence and reporting.
Maintaining the identity dimensions of OSFI Guideline B‐13, third‐party access expectations under OSFI Guideline B‐10, resilience considerations under OSFI Guideline E‐21, and CIRO cybersecurity expectations, producing evidence in the form of auditors and regulators can test.
Supporting OSFI supervisory reviews, CIRO examinations, SOC 2 examinations and internal audits for identity domains; driving remediation of identity findings to closure with named owners and committed dates.
Workforce and privileged identity
Setting standards for access, authentication and authorization across the workforce: single sign‐on, personal password management, MFA and authentication escalation, risk‐based access, and the joiner‐mover‐leaver lifecycle.
Owning privileged access program outcomes: vault coverage, credential rotation, JIT/JEA, session accountability and emergen