Skip to content

Open nowPosted 7 days ago

Strategy Advisor, Identity & Access Management

qfg70 open roles

Where
North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStrategy Advisor, Identity & Access Managementqfg · North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on qfg's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 7 days ago

The posting

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs 

Paid vacation, personal, and sick days for work-life balance

Competitive compensation and benefits packages

Work-life balance in a hybrid environment with at least 3 days in office

Career growth and development opportunities

Opportunities to contribute to community causes

Work with diverse team members in an inclusive and collaborative environment

  This job posting is for an existing vacancy.   We’re looking for our next Strategy Advisor, Identity & Access Management. Could It Be You? The Advisor, Identity & Access Management Strategy owns the enterprise identity strategy across Questrade Financial Group’s regulated entities. The role sets direction, standards and the multi-year roadmap for workforce identity, privileged access, identity governance and administration, and non-human identity (including Agentic Identity), and leads the IAM team that delivers them. It is accountable for the identity control environment meeting business, security and regulatory requirements in each QFG entity, and for the vendor decisions, governance and evidence that keep it there. This is a strategy and leadership role; deep technical execution is led by the Principal Engineer, Identity & Access Management, and other IAM team members, under this role’s direction. This role operates within a CIRO-regulated dealer and an OSFI-regulated federal financial institution (FRFI) environment. Candidates must understand that entity segregation between Questrade Inc. and Questbank is a foundational architectural constraint.   Need more details? Keep reading… In this role, responsibilities include but are not limited to: Scope and boundaries

Owning enterprise identity strategy, standards, roadmap and governance for workforce identity life-cycle, privileged access, IGA and non-human identity across all QFG entities.

Delegating hands-on design and engineering execution to the Principal Engineer, IAM, and the IAM team. This role directs, prioritizes and is accountable for outcomes.

Client identity (CIAM): this role defines and represents the security requirements, standards and controls that client-facing identity platforms must meet, and contributes to policy engine design to minimize account takeover risks. Platform delivery ownership follows the enterprise architecture decision on the CIAM target state.

Strategy and roadmap

Owning the Enterprise and Client IAM vision, strategy and multi-year roadmap across all QFG entities; aligning with business, technology and security strategy; secure executive approval and funding.

Leading requirements-first selection of identity platforms and vendors: defining control requirements before evaluating products, running trade-off analysis, and recording decisions. No platform is adopted or retired without a documented decision.

Entity governance and regulatory

Owning the identity control and compliance posture of each QFG regulated entity separately, including entity-scoped design, evidence and reporting.

Maintaining the identity dimensions of OSFI Guideline B-13, third-party access expectations under OSFI Guideline B-10, resilience considerations under OSFI Guideline E-21, and CIRO cybersecurity expectations, producing evidence in the form of auditors and regulators can test.

Supporting OSFI supervisory reviews, CIRO examinations, SOC 2 examinations and internal audits for identity domains; driving remediation of identity findings to closure with named owners and committed dates.

Workforce and privileged identity

Setting standards for access, authentication and authorization across the workforce: single sign-on, personal password management, MFA and authentication escalation, risk-based access, and the joiner-mover-leaver lifecycle.

Owning privileged access program outcomes: vault coverage, credential rotation, JIT/JEA, session accountability and emergency access, with measurable targets and quarterly reporting.

Identity governance and administration

Owning the IGA strategy: authoritative attribute sourcing from HR systems, the role and entitlement model, automated provisioning and deprovisioning, and access certification across all enterprise platforms, with check-and-balance controls for data quality, integrity and timeliness.

Non-human and cloud identity

Owning governance of non-human identity: service accounts, agentic identities, workload identities, API keys and secrets across on-premises, GCP, AWS, Azure and Microsoft Entra, including inventory, ownership, rotation and least privilege.

Metrics and reporting

Owning identity KPI and KRI targets and reporting to executive and Board audiences, using the measurement library maintained by the IAM team. Directing effort by risk, not evenly.

People management

Leading, developing and retaining the IAM team; setting goals aligned to strategy; addressing performance in a timely manner.

Forecasting resourcing against the roadmap and presenting evidence-based cases for changes.

Acting as the team’s advocate: removing blockers and securing the tools, processes and organizational support the team needs.

Building succession depth and cross-training so that no identity capability depends on a single person.

Collaboration and change

Partnering with Enterprise Architecture, cloud and data leadership, DevSecOps, JSOC, Enterprise Fraud, GRC, Privacy, Legal, People & Culture and User Experience; resolving conflicting priorities and negotiating outcomes.

Sponsoring identity-related change programs across entities and building adoption through clear communication at executive and technical levels.

  So are YOU our next Strategy Advisor, Identity & Access Management? You are if you…

Have 10+ years of experience in cybersecurity with substantial IAM leadership, including ownership of an enterprise IAM strategy and leadership of multidisciplinary teams in financial services

Have proven experience with end-to-end delivery of complex IAM programs — strategy through operationalization — in regulated environments

Have deep experience working across privileged access management (Delinea), identity governance and administration (SailPoint), Microsoft Entra and the EMS E5 security stack, and identity threat detection (CrowdStrike Identity Protection): enough to set direction, challenge designs and hold vendors to account

Have demonstrated proficiency in Hybrid Identity Architecture: governing complex identity environments spanning Active Directory (AD), Microsoft Entra (formerly Azure AD), and GCP federation

Have experience governing non-human identity at scale: service accounts, secrets and workload identity across cloud providers

Have working knowledge of OSFI Guidelines B-13, B-10 and E-21, CIRO cybersecurity expectations, PIPEDA and Quebec Law 25, or demonstrated ability to learn a new prudential regime quickly

Have experience producing audit-ready evidence and interacting directly with auditors and regulators

Have strong experience with budget planning and financial management for technology programs

Possess Executive and Board-level verbal and written communication skills, at a standard suitable for regulator-facing documentation

Have strong stakeholder management skills in a matrixed organization with ability to influence without direct authority and hold people to committed dates

Have proven leadership experience to develop, coach and retain talent; addressing performance early; building morale, belonging and succession

Are comfortable navigating ambiguity, separating relevant trends from hype and making sound decisions with incomplete information

  Additional kudos if you…

Are Bilingual - written and verbal fluency in English and French

Hold CISSP, CISM, IDPro CIDPRO, or vendor certifications (Delinea, SailPoint, Microsoft Entra)

  Compensation Information:

Base salary range: $170,000 - $185,000

The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

  Sounds like you? Click below to apply! #LI-NP1 #LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against qfg's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on qfg's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    qfg's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.