Toronto Recruitment and Staffing

   +1 416.368.4000

Software Engineer

Story Behind the Need:

• Business group: CIAM Security Engineering
• Engineering function by ensuring that engineering initiatives, delivery plans, and strategic goals are executed effectively.
• The role ensures compliance with regulatory and internal policy requirements while championing customer-focused engineering and reliable identity services across the enterprise.

Candidate Value Proposition:

• Join bank as a strategic leader shaping the future of Customer Identity & Access Management (CIAM) across the enterprise.
• In this role, you will have the opportunity to influence the Bank’s digital identity strategy, modernize core CIAM capabilities, and ensure secure, seamless customer experiences across all channels. You will work at the intersection of security, engineering, architecture, and customer experience, driving initiatives that directly impact millions of users.

Typical Day in Role:

• Provide strategic leadership and direction for CIAM engineering and platform delivery, ensuring alignment with enterprise security strategy, reliability standards, and digital identity modernization initiatives.
• Own the CIAM capability roadmap, overseeing the design, evolution, and continuous improvement of CIAM platforms and services to meet current and future business and security needs.
• Establish and govern CIAM architecture and frameworks, ensuring alignment with organizational security standards, regulatory obligations, and industry best practices.
• Set technical standards and best practices for identity federation, SSO, MFA, OAuth2/OIDC flows, adaptive authentication, and API‑based integrations across digital channels.
• Ensure CIAM solutions meet regulatory, compliance, and security requirements across geographies, customer segments, and channels, working closely with risk and assurance partners.
• Oversee onboarding and expansion of digital channels onto CIAM platforms, ensuring consistent, secure, and scalable implementations through well‑defined patterns and controls.
• Lead risk assessments and technical security reviews for CIAM integrations, approving design decisions and ensuring that appropriate mitigation strategies are identified and implemented.
• Drive continuous improvement of engineering and delivery processes, including deployment models, onboarding workflows, implementation guidelines, and operational readiness.
• Collaborate with senior stakeholders across engineering, product, security, architecture, and operations to enable smooth adoption of CIAM services and resolve complex cross‑team dependencies.
• Provide thought leadership, coaching, and technical oversight to CIAM engineers and partner teams, enabling high‑quality solutions without the need for direct hands‑on execution.
• Ensure high‑quality technical documentation and guidance is available and maintained, including architectures, standards, runbooks, and troubleshooting procedures.
• Build and maintain strong working relationships with technology partners, delivery teams, and business stakeholders to support successful program and platform outcomes.
• Embed the Bank’s risk appetite and risk culture into CIAM decisions, ensuring proactive risk identification, escalation, and informed decision‑making.
• Champion a customer‑centric, inclusive, and collaborative engineering culture, fostering accountability, continuous learning, and strong engagement across the CIAM organization.

Candidate Requirements/Must Have Skills:

• 10+ years of progressive experience leading and overseeing the design, implementation, and modernization of enterprise‑scale platforms built on Java/J2EE, Spring Framework, Node.js, RESTful APIs, event‑driven architectures (Kafka), and cloud‑based data services.
• 5+ years of deep experience providing technical leadership for CIAM platforms, including ForgeRock (AM, IDM, DS) and Ping Identity (PingFederate, PingAccess, PingDirectory), with exposure to Okta and other SaaS IAM providers considered an asset.
• Expert‑level understanding of identity and access management protocols and standards, including OAuth 2.0, OpenID Connect, SAML, LDAP, and their application across enterprise and customer identity use cases.
• Demonstrated ability to define IAM and CIAM architectures for hybrid and cloud environments (AWS, Azure, GCP), ensuring scalability, resilience, and alignment with enterprise security strategy.
• Strong foundation in cybersecurity principles, risk management, and regulatory compliance, with the ability to align IAM decisions to the Bank’s risk appetite and control frameworks.

Nice-To-Have Skills:

• Strategic oversight of identity federation, SSO, MFA, and adaptive authentication solutions, ensuring secure, consistent implementations across channels and regions.
• Leadership experience in DevOps and Infrastructure‑as‑Code practices (e.g., Terraform), enabling standardized, repeatable, and secure IAM deployments.
• Proven leadership in CI/CD and deployment automation, governing engineering standards and release practices using Jenkins, cloud‑native deployment frameworks (GCP/Azure/AWS), and DevOps tooling.

Soft Skills Required:

• Exceptional communication, prioritization, and time‑management skills, with a track record of operating effectively in fast‑paced, regulated environments.
• Experience enabling capability uplift through training and knowledge transfer, including delivery of technical training sessions using virtual collaboration platforms.
• Oversight of high‑quality technical documentation, including enterprise architecture diagrams, standards, configuration guidelines, operational procedures, and runbooks.
• Proven ability to prepare executive‑level communications, including technical briefings, decision papers, and risk summaries tailored for senior leadership, governance forums, and regulators.
• Extensive experience operating within a matrix organization, influencing across engineering, product, security, risk, operations, and business stakeholders to drive outcomes without direct authority.
• Strong leadership competencies in planning, analytics, presentation, project and change management, coupled with effective relationship‑building at all organizational levels.
• Proven capability to guide teams through complex IAM integration challenges, providing escalation support, architectural direction, and resolution of high‑impact issues.

Education:

• Bachelor’s degree in Cybersecurity, Computer science, Engineering, or any other related.

Best VS. Average Candidate:

• The best candidate is someone with experience in Java development and in ForgeRock and Ping Identity. Someone with knowledge of application security fundamentals and coding skills.

Candidate review and selection:

• 2 rounds
• 1st – Hiring manager and technical panel– 1 hr – MS Teams video call – experience check and role overview and technical questions on experience and requirements.
• 2nd (Optional) – Hiring manager and team– 1 hr – in-person– situational questions + assess interest in role and cultural fit.

Please note:

• AI is not used to screen, assess, or select candidates.
• This role reflects an existing vacancy at the time of posting.
Job Details

14790

Contract

3 months

Toronto


Recruiter
Pranshu Gupta

Pranshu Gupta |