Back to job search
J&M Group logo
J&M GroupVerified Job Source

Cybersecurity Engineer

  • Toronto, ON
  • On-site
  • Posted Aug 28, 2026
  • 1 position

Opens an external site

Sign in to save this job
Employment type
Contract
Experience level
Senior · 5+ years
Apply by
Feb 24, 2027
Posting language
English
Working hours
40 hours per week
Seniority
Mid-Senior level
Application method
Direct apply is available

Job summary

Manage the identity and access lifecycle, including NPID governance and PAM onboarding, to enhance the organization's security posture. Integrate security controls into DevOps pipelines and develop Python-based automation for security operations and risk reporting.

Job details

Support and enhance the organization s cybersecurity posture by managing identity and access lifecycle, non-personal IDs (NPIDs), risk control frameworks, and DevOps security integration while driving process automation through Python-based tooling. Key Responsibilities Identity & Access Management (IAM) Onboard applications and services into IAM platforms (SailPoint, CyberArk, Active Directory) Manage access provisioning, recertification, and deprovisioning workflows Enforce least-privilege and role-based access control (RBAC) policies Support PAM (Privileged Access Management) onboarding and credential vaulting NPID Management Create, maintain, and retire Non-Personal IDs (service accounts, shared accounts, system IDs) Ensure NPIDs comply with organizational password policy, rotation schedules, and ownership accountability Conduct periodic reviews and attestations of NPID inventory Remediate orphaned or stale NPIDs flagged during audits DevOps Security Support Embed security controls into CI/CD pipelines (Jenkins, Azure DevOps, GitHub Actions) Advise development teams on secrets management (HashiCorp Vault, Azure Key Vault) Support SAST/DAST/SCA tool integration (Veracode, Snyk, Checkmarx) Collaborate on secure code reviews and threat modeling for new services Risk & Controls Management Own and track risk controls across assigned application portfolios Raise, manage, and remediate risk findings and exceptions Prepare risk reporting for audits, regulators, and senior management Automation & Tooling (Python) Develop Python scripts to automate IAM workflows, NPID audits, and vulnerability reporting Build integrations with internal APIs, Confluence, ServiceNow, and Tableau Maintain and enhance automation pipelines for recurring security operations tasks Reduce manual effort through scheduled jobs, data extraction, and automated reporting Required Skills IAM/PAM platforms: CyberArk, Active Directory, Azure AD/Entra ID Scripting: Python (pandas, requests, openpyxl, Selenium), PowerShell DevSecOps toolchain familiarity Understanding of NPID/service account governance

What you’ll do

Manage the identity and access lifecycle, including NPID governance and PAM onboarding, to enhance the organization's security posture. Integrate security controls into DevOps pipelines and develop Python-based automation for security operations and risk reporting.

Requirements

Requires proficiency in IAM/PAM platforms like CyberArk and Active Directory, along with strong Python scripting skills for automation. Candidates should have experience with DevSecOps toolchains and a solid understanding of service account governance.

Listed skills

  • Active Directory · Preferred
  • Python · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Identity & Access Management
  • Privileged Access Management
  • Python
  • DevSecOps
  • CyberArk
  • Active Directory
  • Azure AD
  • SailPoint
  • CI/CD Pipelines
  • Risk Control Frameworks
  • Secrets Management
  • SAST/DAST/SCA
  • PowerShell
  • RBAC
  • NPID Management
  • Threat Modeling

Job areas

  • Security & Safety
  • Technology
  • Software
  • Engineering
  • Consulting

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Browse all Easy Apply jobs