Job Description: Cybersecurity Engineer – DevSecOps / IAM / PAM
Location:Toronto, ON
Work Arrangement:Hybrid – 4 Days Work From Office (WFO)
Duration:6–12 Months
Role Overview
We are seeking an experiencedCybersecurity Engineerwith strong expertise inIAM, PAM, CyberArk, Active Directory, Entra ID, Python, and DevSecOps.
The successful candidate will support and enhance RBC's cybersecurity posture by managing identity and access lifecycles, Non-Personal IDs (NPIDs), risk and control frameworks, and DevSecOps security integration, while driving process automation through Python-based tooling.
Key Responsibilities
1. Identity & Access Management (IAM)
- Onboard applications and services into IAM platforms, includingSailPoint, CyberArk, and Active Directory.
- Manage access provisioning, recertification, and deprovisioning workflows.
- EnforceLeast PrivilegeandRole-Based Access Control (RBAC)policies.
- SupportPrivileged Access Management (PAM)onboarding and credential vaulting.
- Manage identity lifecycle processes inAzure AD / Microsoft Entra ID.
2. Non-Personal ID (NPID) Management
- Create, maintain, and retire Non-Personal IDs, including service accounts, shared accounts, and system IDs.
- Ensure NPIDs comply with password policies, rotation schedules, and ownership requirements.
- Conduct periodic reviews and attestations of NPID inventories.
- Identify and remediate orphaned, stale, or non-compliant NPIDs.
- Support audit and compliance activities related to service-account governance.
3. DevSecOps Security
- Embed security controls into CI/CD pipelines using tools such as:
- Jenkins
- Azure DevOps
- GitHub Actions
- Jenkins
- Advise development teams on secrets management using:
- HashiCorp Vault
- Azure Key Vault
- HashiCorp Vault
- Support integration and implementation of:
- SAST
- DAST
- SCA
- SAST
- Work with security and development teams on tools such asVeracode, Snyk, and Checkmarx.
- Participate in secure code reviews and threat modeling for new applications and services.
4. Risk & Controls Management
- Own and track cybersecurity risk controls across assigned application portfolios.
- Identify, raise, manage, and remediate security risk findings and exceptions.
- Monitor compliance with cybersecurity policies and control requirements.
- Prepare risk and control reporting for audits, regulators, and senior management.
- Support evidence collection and remediation activities for internal and external audits.
5. Automation & Tooling
- DevelopPython-based automationto streamline IAM workflows, NPID audits, vulnerability reporting, and other security operations.
- Develop integrations with internal APIs and platforms such as:
- Confluence
- ServiceNow
- Tableau
- Confluence
- Maintain and enhance automation pipelines for recurring security operations tasks.
- Use Python libraries such aspandas, requests, openpyxl, and Selenium.
- Develop scheduled jobs, automated data extraction, and reporting solutions to reduce manual effort.
Required Skills & Qualifications
- Strong experience inCybersecurity Engineering, IAM, PAM, and DevSecOps.
- Hands-on experience with:
- CyberArk
- Active Directory
- Microsoft Entra ID / Azure AD
- SailPoint
- CyberArk
- Strong understanding ofIdentity & Access Management (IAM)andPrivileged Access Management (PAM).
- Experience withNon-Personal IDs (NPIDs), service accounts, and identity governance.
- Strong scripting and automation skills usingPython.
- Experience with Python libraries includingpandas, requests, openpyxl, and Selenium.
- Working knowledge ofPowerShell.
- Familiarity with DevSecOps practices and CI/CD security.
- Knowledge ofJenkins, Azure DevOps, and GitHub Actions.
- Experience with application security tools such asVeracode, Snyk, and Checkmarx.
- Knowledge of secrets-management technologies such asHashiCorp Vault and Azure Key Vault.
- Understanding of cybersecurity risk, controls, compliance, and audit requirements.
- Strong analytical, communication, and problem-solving skills.
- Ability to work effectively with cybersecurity, infrastructure, application development, and DevOps teams.
Key Technology Stack
IAM / PAM:SailPoint, CyberArk, Active Directory, Microsoft Entra ID
Automation:Python, pandas, requests, openpyxl, Selenium, PowerShell
DevSecOps:Jenkins, Azure DevOps, GitHub Actions
Secrets Management:HashiCorp Vault, Azure Key Vault
Application Security:Veracode, Snyk, Checkmarx
Enterprise Tools:ServiceNow, Confluence, Tableau
- Locations
- Toronto, Ontario, Canada