Access Full Position Posting
Purpose:
The Identity & Access Management Designer is a technology and solution subject matter expert with deep pragmatic experience and passion for the Identity and Access domain as well as other relevant information security domains. Reporting to the Senior Manager, Identity and Access Management, this role serves as an expert technical resource for the planning, design, configuration, integration, testing and ongoing evolution of IAM solutions and services. The role provides guidance on IAM standards, solution design, workflows, controls, technical patterns and best practices to support secure, scalable and sustainable identity services, improving the user experience, and supporting the long-term evolution of IAM services at the University. The IAM Designer collaborates closely with both technical and non-technical partners across the University to effectively translate the IAM objectives into specific identity and access management workflows enabled by York University's IAM technologies and services.
Education:
Bachelor's degree in a relevant discipline, such as Computer Science, Information Systems, or Cybersecurity or an equivalent of 4 years recent experience (defined as within the last five years) working at York University and performing the same or similar tasks. This education equivalency is in addition to the experiential requirements outlined below.
Experience:
7 years related experience with the development, implementation, and operation of identity management systems and related technologies.
Extensive experience designing, implementing, maintaining, administering and troubleshooting SailPoint IdentityIQ solutions, including complex workflows, integrations and identity lifecycle processes.
Experience integrating SailPoint with directories, applications, and cloud platforms using REST/SOAP APIs.
Experience with enterprise identity platforms such as Microsoft Entra ID (Azure AD), including authentication, authorization, and identity governance capabilities.
Experience scripting using Beanshell, Java, SQL, XML, JSON.
Experience with Linux/UNIX systems and LDAP directories.
Experience with user provisioning, de-provisioning, and access certification workflows.
Skills:
Effective communication skills.
Ability to present complex technical materials to non-technical business partners and executives.
Ability to work closely with business and IT teams to align IAM strategies with organizational goals.
Ability to work with operating systems and middleware security software/tools.
Ability to solve large complex IT and business problems that are often ambiguous, conceptual and/or ill-defined.
Effective project coordination skills.
Ability to apply judgment, discretion, technical problem-solving, and analytical skills.
Ability to work as a team member and establish effective working relationships.
Ability to build relationships and bring together individuals with different perspectives and opinions toward a common goal.
Commitment to continuous learning and skill building in DEDI and cultural competence.
Effective interpersonal skills, including listening and questioning skills.
Ability to maintain strict confidentiality.
Ability to accomplish goals through influence without direct authority.
Ability to navigate and work effectively in a dynamic work environment with frequent change.
Ability to interpret regulatory standards and technical specifications.
Ability to design scalable and secure IAM frameworks, procedures, and best practices.
Expertise in implementing and managing role-based and attribute-based access models.
Proficiency in Java, XML, SQL, JSON and Beanshell, for custom connector deployments.
Effective knowledge of IAM principles, practices, and standards as applicable in a multi-faceted organization supported by multi-platform technical environments.
Deep understanding of IAM architecture, lifecycle events, workflows, and connectors.
Familiarity with NIST, CIS, and industry IAM frameworks.
Knowledge of identity threats, zero-trust models, and IAM risk mitigation strategies.
Awareness of IT infrastructure, cloud security, and hybrid IAM deployment models.
Knowledge of relational databases (SQL) and directory services (Active Directory, LDAP) in IAM implementations.
Effective knowledge of Active Directory, LDAP, SSO, MFA, and authentication protocols (SAML, OAuth, OpenID Connect).
Knowledge of managing CI/CD pipelines and automating tasks using tools such as Ansible
Additional Notes:
Please note: This position requires the candidate to produce a verification of degree(s), credentials(s), or equivalencies from accredited institutions and/or international equivalents at the time of interview. Hours of work: Monday to Friday 8:30am to 4:30pmSummer: SamePeak periods for this position: Variable depending on project life cycles. Vacation restriction: Depending on critical milestones on project.
Access Full Position Posting
If you are a current York University employee in the YUSA-1 bargaining unit and/or are using your job posting rights under the collective agreement to view and apply for jobs, you must apply through the Employee Career Portal - YU Hire to be considered an internal applicant.
As per Article 12.02(f) of the YUSA-1 Collective Agreement, to be considered an internal applicant, employees in the YUSA-1 bargaining unit must submit the application 5 working days following the first day of posting. This is referred to as the 'Posted Date' on the job posting. Please refer to the 'Posting Intent' on the job posting.
The University welcomes applications from all qualified individuals, including, but not limited to women, persons with disabilities, visible minorities (racialized), Indigenous Peoples and persons of any gender identity and sexual orientation. York University is committed to a positive, supportive and inclusive environment.
York University offers accommodation for applicants with disabilities in its recruitment processes. If you are contacted by York University regarding a job opportunity or testing, please advise if you require accommodation.
We are committed to enhancing our environmentally and socially responsible practices for the benefit of all members of the York community. Our long term perspective recognizes our responsibility to be innovators and to continually work as a community to reduce our ecological impact.
York University employees must apply to jobs through the Employee Career Portal - YU Hire. If you are a current York University employee and/or are using your rights under a collective agreement to view and/or apply to jobs, you MUST log into YU Hire to access the York University Employee Career Portal.
PLEASE NOTE: This job posting is for an existing vacancy. Applications must be received by 11:55 pm EST on the posted deadline date, if applicable. Posting deadlines can be updated, or modified, at any time based on hiring needs. Please refer to the York U Career Portal when confirming posting deadlines.