jobify_logo ×
  • מִשׁתַמֵשׁ
  • התחברות/הרשמה111
  • עמוד הבית
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות
קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service work_office המקום
jobify_logo
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
דילוג לתוכן

עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!

במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

Principal Engineer, Identity & Access Management

Questrade Financial Group

Questrade Financial Group Questrade Financial Group

  • תל אביב - יפו
  • LinkedIn
LinkedIn

Principal Engineer, Identity & Access Management

Questrade Financial Group

Questrade Financial Group Questrade Financial Group

  • תל אביב - יפו
  • bag_icon מלאה
  • coins_icon 45,000-49,000 ₪ (הערכה מבוססת AI)
    הערכה מבוססת AI ולא שכר של המעסיק
  • LinkedIn
LinkedIn


Questrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure.

At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work.

Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG.

What’s in it for you as an employee of QFG?

  • Health & wellbeing resources and programs
  • Paid vacation, personal, and sick days for work-life balance
  • Competitive compensation and benefits packages
  • Work-life balance in a hybrid environment with at least 3 days in office
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy.

We’re looking for our next Strategy Advisor, Identity & Access Management. Could It Be You?

The Advisor, Identity & Access Management Strategy owns the enterprise identity strategy across Questrade Financial Group’s regulated entities. The role sets direction, standards and the multi-year roadmap for workforce identity, privileged access, identity governance and administration, and non-human identity (including Agentic Identity), and leads the IAM team that delivers them. It is accountable for the identity control environment meeting business, security and regulatory requirements in each QFG entity, and for the vendor decisions, governance and evidence that keep it there. This is a strategy and leadership role; deep technical execution is led by the Principal Engineer, Identity & Access Management, and other IAM team members, under this role’s direction.

This role operates within a CIRO-regulated dealer and an OSFI-regulated federal financial institution (FRFI) environment. Candidates must understand that entity segregation between Questrade Inc. and Questbank is a foundational architectural constraint.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

Scope and boundaries

  • Owning enterprise identity strategy, standards, roadmap and governance for workforce identity life-cycle, privileged access, IGA and non-human identity across all QFG entities.
  • Delegating hands-on design and engineering execution to the Principal Engineer, IAM, and the IAM team. This role directs, prioritizes and is accountable for outcomes.
  • Client identity (CIAM): this role defines and represents the security requirements, standards and controls that client-facing identity platforms must meet, and contributes to policy engine design to minimize account takeover risks. Platform delivery ownership follows the enterprise architecture decision on the CIAM target state.

Strategy and roadmap

  • Owning the Enterprise and Client IAM vision, strategy and multi-year roadmap across all QFG entities; aligning with business, technology and security strategy; secure executive approval and funding.
  • Leading requirements-first selection of identity platforms and vendors: defining control requirements before evaluating products, running trade-off analysis, and recording decisions. No platform is adopted or retired without a documented decision.

Entity governance and regulatory

  • Owning the identity control and compliance posture of each QFG regulated entity separately, including entity-scoped design, evidence and reporting.
  • Maintaining the identity dimensions of OSFI Guideline B-13, third-party access expectations under OSFI Guideline B-10, resilience considerations under OSFI Guideline E-21, and CIRO cybersecurity expectations, producing evidence in the form of auditors and regulators can test.
  • Supporting OSFI supervisory reviews, CIRO examinations, SOC 2 examinations and internal audits for identity domains; driving remediation of identity findings to closure with named owners and committed dates.

Workforce and privileged identity

  • Setting standards for access, authentication and authorization across the workforce: single sign-on, personal password management, MFA and authentication escalation, risk-based access, and the joiner-mover-leaver lifecycle.
  • Owning privileged access program outcomes: vault coverage, credential rotation, JIT/JEA, session accountability and emergency access, with measurable targets and quarterly reporting.

Identity governance and administration

  • Owning the IGA strategy: authoritative attribute sourcing from HR systems, the role and entitlement model, automated provisioning and deprovisioning, and access certification across all enterprise platforms, with check-and-balance controls for data quality, integrity and timeliness.

Non-human and cloud identity

  • Owning governance of non-human identity: service accounts, agentic identities, workload identities, API keys and secrets across on-premises, GCP, AWS, Azure and Microsoft Entra, including inventory, ownership, rotation and least privilege.

Metrics and reporting

  • Owning identity KPI and KRI targets and reporting to executive and Board audiences, using the measurement library maintained by the IAM team. Directing effort by risk, not evenly.

People management

  • Leading, developing and retaining the IAM team; setting goals aligned to strategy; addressing performance in a timely manner.
  • Forecasting resourcing against the roadmap and presenting evidence-based cases for changes.
  • Acting as the team’s advocate: removing blockers and securing the tools, processes and organizational support the team needs.
  • Building succession depth and cross-training so that no identity capability depends on a single person.

Collaboration and change

  • Partnering with Enterprise Architecture, cloud and data leadership, DevSecOps, JSOC, Enterprise Fraud, GRC, Privacy, Legal, People & Culture and User Experience; resolving conflicting priorities and negotiating outcomes.
  • Sponsoring identity-related change programs across entities and building adoption through clear communication at executive and technical levels.

So are YOU our next Strategy Advisor, Identity & Access Management? You are if you…

  • Have 10+ years of experience in cybersecurity with substantial IAM leadership, including ownership of an enterprise IAM strategy and leadership of multidisciplinary teams in financial services
  • Have proven experience with end-to-end delivery of complex IAM programs — strategy through operationalization — in regulated environments
  • Have deep experience working across privileged access management (Delinea), identity governance and administration (SailPoint), Microsoft Entra and the EMS E5 security stack, and identity threat detection (CrowdStrike Identity Protection): enough to set direction, challenge designs and hold vendors to account
  • Have demonstrated proficiency in Hybrid Identity Architecture: governing complex identity environments spanning Active Directory (AD), Microsoft Entra (formerly Azure AD), and GCP federation
  • Have experience governing non-human identity at scale: service accounts, secrets and workload identity across cloud providers
  • Have working knowledge of OSFI Guidelines B-13, B-10 and E-21, CIRO cybersecurity expectations, PIPEDA and Quebec Law 25, or demonstrated ability to learn a new prudential regime quickly
  • Have experience producing audit-ready evidence and interacting directly with auditors and regulators
  • Have strong experience with budget planning and financial management for technology programs
  • Possess Executive and Board-level verbal and written communication skills, at a standard suitable for regulator-facing documentation
  • Have strong stakeholder management skills in a matrixed organization with ability to influence without direct authority and hold people to committed dates
  • Have proven leadership experience to develop, coach and retain talent; addressing performance early; building morale, belonging and succession
  • Are comfortable navigating ambiguity, separating relevant trends from hype and making sound decisions with incomplete information

Additional Kudos If You…

  • Are Bilingual - written and verbal fluency in English and French
  • Hold CISSP, CISM, IDPro CIDPRO, or vendor certifications (Delinea, SailPoint, Microsoft Entra)

Compensation Information:

  • Base salary range: $170,000 - $185,000
  • The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

Sounds like you? Click below to apply!

At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us.

Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review.

Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.


במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

שאלות ותשובות עבור משרת Principal Engineer, Identity & Access Management

המהנדס הראשי, ניהול זהויות וגישה ב-Questrade Financial Group, אחראי על ביצוע תכנון והנדסה טכניים מעמיקים בתחום ה-IAM. תפקיד זה כולל יישום ההנחיות והתקנים שנקבעו על ידי יועץ האסטרטגיה לניהול זהויות וגישה, וכן תמיכה באסטרטגיה הכוללת של זהויות ארגוניות בכל הישויות המוסדרות של הקבוצה.

תפקיד המהנדס הראשי, ניהול זהויות וגישה, תורם באופן משמעותי לאבטחה על ידי הבטחת עמידה בדרישות אבטחה ורגולציה מחמירות. הוא אחראי על יישום בקרות זהות, ניהול גישה מועדפת, וניהול זהויות לא-אנושיות, תוך עבודה בסביבה מוסדרת על ידי CIRO ו-OSFI, מה שמבטיח הגנה חזקה על נכסי החברה ונתוני הלקוחות.

לתפקיד מהנדס ראשי, ניהול זהויות וגישה, נדרשים כישורים טכניים עמוקים בניהול גישה מועדפת (כגון Delinea), ניהול זהויות וגישה (כגון SailPoint), Microsoft Entra, חבילת האבטחה EMS E5, וזיהוי איומי זהות (כגון CrowdStrike Identity Protection). כמו כן, נדרשת מומחיות בארכיטקטורת זהויות היברידית, כולל Active Directory, Microsoft Entra ופדרציית GCP, וכן ניסיון בניהול זהויות לא-אנושיות בקנה מידה גדול בסביבות ענן שונות.

משרות נוספות מומלצות עבורך
  • רשימת משאלות

    Principal Engineer, Identity & Access Management

    • map_icon תל אביב - יפו
    Questrade Financial Group

    Questrade Financial Group

לכל המשרות של IAM Strategy Lead

ניתן לצפות במשרות שסימנת בכל שלב תחת התפריט הראשי בקטגוריית 'משרות שאהבתי'

המקום קרן עזריאלי טקסט בעברית עם סמל אינסוף
  • מי אנחנו
  • מעסיקים מובילים
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות

2026 Ⓒ ג'וביפיי - כל הזכויות שמורות

קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service israel_innovation_authority work_office המקום
המערכת בונה את הפרופיל התעסוקתי שלך

עוד רגע...

המערכת זיהתה ששינית את הנתונים באזור האישי ומעדכנת את ההמלצות על תפקידים ומשרות בהתאם.

מצטערים, לא הצלחנו לנתח בהצלחה את הנתונים שהזנת.
אתם מוזמנים לנסות להזין שוב או להעלות קובץ קורות חיים במידה ויש לכם.
בהצלחה

הגעת להגבלה היומית של שלושה עדכונים בפרופיל האישי ביום

loader

הבקשה שלך נשלחה בהצלחה!

יש באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות מיועצת קריירה.

באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות

  • בעיה טכנית

  • סיוע בכתיבת קורות חיים או בהכנה לראיון עבודה

  • התאמה של משרות

  • אחר:

פנייתך נשלחה בהצלחה. נציג מטעם ארגון נכי צהל ייצור איתך קשר בהקדם