Lead Advisor Identity & Access Management

VIA Rail CanadaMontreal, QC
CA$102,816 - CA$127,000Remote

About The Position

As Lead Advisor, Identity & Access Management (IAM), you lead the evolution of VIA Rail's enterprise identity, access and privileged access capabilities. You define direction, guide architecture and enable secure, compliant and efficient access for workforce, partner, application and non-human identities across hybrid and cloud environments. Working closely with Cybersecurity, GRC, IT, HR, Legal and business stakeholders, you translate identity risks and business needs into practical standards, roadmaps and solutions that support VIA Rail's security governance, audit obligations and Zero Trust direction.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, Information Systems, or a related field.
  • Seven (7) or more years of progressive IT experience, including at least five (5) years focused on Identity & Access Management in complex enterprise environments.
  • Demonstrated experience designing, deploying and managing IAM, IGA, PAM, authentication and federation capabilities across on-premises, cloud and hybrid environments.
  • Hands-on experience with Active Directory and Microsoft Entra ID, including hybrid identity, directory services, conditional access, Privileged Identity Management and identity protection.
  • Experience with IGA and PAM platforms, automated provisioning/de-provisioning, access certifications, role and entitlement management, and privileged account controls.
  • Proficiency in certificate management and Public Key Infrastructure (PKI), including internal PKI operations such as Active Directory Certificate Services; certificate lifecycle automation experience is an asset.
  • Solid understanding of encryption, TLS configuration, identity security risks, IT audit, regulatory and compliance requirements, including segregation of duties and financial reporting controls.
  • One or more recognized certifications considered an asset: CISSP, CISM, CIAM, CISA, SC-300 (Microsoft Identity & Access Administrator), SC-900, SC-400, vendor-specific IGA / PAM / PKI certifications, and certifications in a major public cloud platform (Azure, AWS or Google Cloud).

Nice To Haves

  • Expert knowledge of IAM domains, including IGA, PAM, Access Management, federation, credential management, identity verification and identity protection.
  • Strong administration experience with Active Directory and Microsoft Entra ID, including hybrid identity, conditional access, Privileged Identity Management and identity protection.
  • Hands-on experience with IGA and PAM tooling, automated lifecycle management, access certifications, SoD, role modeling, vaulting, session management and just-in-time access.
  • Strong understanding of authentication and federation protocols, including OIDC, OAuth 2.0, SAML 2.0, Kerberos, SCIM, WS-Fed and FIDO2/WebAuthn.
  • Certificate management, PKI and cryptography knowledge, including TLS, certificate trust chains, key management and post-quantum cryptography awareness.
  • Knowledge of cloud identity, workload identities, managed identities, least privilege, Zero Trust and identity-centric threats and mitigations
  • Ability to design end-to-end identity, access and cryptographic solutions that balance security, usability, compliance and operational cost.
  • Ability to translate business strategies, audit requirements and risk drivers into architecture, standards, roadmaps and technical controls.
  • Strong analytical, troubleshooting and root-cause analysis skills for complex hybrid identity and certificate-related issues.
  • Sound judgment, tact and diplomacy when managing risk-based decisions, trade-offs and challenging stakeholder situations.
  • Demonstrated ability to lead initiatives across multi-disciplinary teams, external service providers and business stakeholders.
  • Ability to mentor team members, influence peers without direct authority and provide guidance to IT staff and business users.
  • Excellent written and verbal communication in both English and French, with the ability to explain security matters clearly to technical, operational and executive audiences.
  • Strong stakeholder management, documentation discipline and client-oriented mindset, with consistent alignment to organizational mission, values and goals.

Responsibilities

  • Own and evolve VIA Rail's IAM strategy, including PAM, IGA and Access Management, aligned with cybersecurity objectives, business priorities and Zero Trust principles.
  • Define the IAM architecture roadmap, future-state capabilities and implementation plans for identity security initiatives and technology investments.
  • Lead evaluation, selection and optimization of IAM-related technologies and services, ensuring scalable and effective identity security solutions.
  • Partner with GRC and cybersecurity teams to manage identity-related risks, strengthen controls and compliance, provide program reporting and drive continuous improvement.
  • Manage and evolve IGA capabilities for workforce, application and non-human identities across hybrid and cloud environments.
  • Oversee joiner-mover-leaver lifecycle processes, provisioning, de-provisioning, role models, entitlement catalogs and access certification campaigns.
  • Improve identity data quality and source-of-truth alignment with HR, application owners, GRC, Internal Audit and third-party providers.
  • Support application and service integrations with IGA capabilities, including lifecycle management, federation and privileged access patterns.
  • Manage and evolve PAM capabilities such as vaulting, session management, password rotation, credential brokering and just-in-time access.
  • Discover, classify and onboard privileged accounts across on-premises and cloud environments.
  • Define privileged access standards and procedures, including tiered administration, break-glass access, approvals and monitoring.
  • Partner with infrastructure, application and cloud teams to reduce standing privileges and enforce least privilege.
  • Operate and evolve access management capabilities including SSO, MFA, passwordless authentication, federation and adaptive access.
  • Design and enforce conditional access and modern authentication policies aligned with VIA Rail cybersecurity standards.
  • Define secure identity verification and access journeys for workforce, customer and partner scenarios.
  • Support integration of applications and services across on-premises, cloud and SaaS environments.
  • Own the lifecycle of digital certificates across servers, applications, devices and non-human identities.
  • Operate and evolve VIA Rail's internal PKI, including AD CS, certificate templates, auto-enrollment and revocation services.
  • Govern public Certificate Authority relationships and support code-signing, S/MIME and TLS certificate programs.
  • Support cryptographic standards, certificate lifecycle automation and post-quantum cryptography readiness planning.
  • Act as IAM subject-matter expert and provide security guidance to technology teams, projects and business stakeholders.
  • Support identity threat detection, incident response, hardening activities and root-cause analysis for recurring IAM issues.
  • Own IAM platform lifecycle, operational monitoring, documentation, metrics and management reporting.
  • Support audits, control assessments and remediation activities in coordination with GRC, while mentoring team members and acting as an escalation point.

Benefits

  • employment-equity employer
  • inclusive and equitable work environment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service