astra-north

Senior IAM Engineer (Azure Entra ID, Identity Governance , RBAC, PIM)

astra-north

Toronto, Ontario, CanadaPermanentPosted Jul 28, 2026

Job description

Job Title: Senior IAM Engineer (Azure Entra ID, Identity Governance, PIM, RBAC) Key Responsibilities

  • Design and implement Azure Entra ID (formerly Azure AD) identity governance frameworks
  • Configure and manage Privileged Identity Management (PIM) for just-in-time privileged access
  • Implement and enforce Conditional Access policies, MFA, and phishing-resistant authentication (FIDO2, Passkeys)
  • Manage RBAC role assignments across Azure subscriptions, resource groups, and management groups
  • Remediate guest user accounts, stale identities, and excessive permission assignments
  • Configure and maintain Break Glass (emergency access) accounts with monitoring and alerting
  • Integrate Microsoft Defender for Cloud governance rules with Service. Now for ticketing workflows
  • Support cross-cloud IAM alignment across AWS IAM and OCI IAM where applicable
  • Participate in IAM audits, access reviews, and compliance reporting
  • Develop IAM runbooks, RBAC mapping documentation, and onboarding guides Required Qualifications
  • 5+ years of IAM experience, with 3+ years in Microsoft Azure / Entra ID
  • Deep knowledge of Azure RBAC, PIM, Conditional Access, and Entra ID roles
  • Experience with MFA enforcement, authentication methods, and access policies
  • Understanding of identity lifecycle management and access certification processes
  • Familiarity with Microsoft Defender for Cloud and Secure Score recommendations
  • Experience with Service. Now or ticketing system integrations for IAM workflows
  • Microsoft Certified: Identity and Access Administrator (SC-300) preferred
  • Strong documentation and stakeholder communication skills Nice to Have
  • Experience with AWS IAM, Organizations, and SCPs
  • Knowledge of OCI IAM compartments and policy structures
  • Exposure to SASE or Zero Trust Network Access (ZTNA) frameworks