Lead Advisor Identity & Access Management

Location: 

MONTREAL, Quebec, CA, H3B 2C9

Reference Number : 1424 

Status : Permanent - Full-time  

Annual Salary / Hourly Rate : $102,816 - $127,000

Number of positions to be filled : 1 

Application Deadline : 08/28/2026

 

Did you know that VIA Rail is carrying out ambitious projects to modernize its services and infrastructure? From our new ultramodern train fleet to ongoing improvement of our infrastructure, we’re building the future of transportation in Canada. Working for VIA Rail is being a part of a collective effort in sustainable mobility. 

 

POSITION:
As Lead Advisor, Identity & Access Management (IAM), you lead the evolution of VIA Rail's enterprise identity, access and privileged access capabilities. You define direction, guide architecture and enable secure, compliant and efficient access for workforce, partner, application and non-human identities across hybrid and cloud environments. Working closely with Cybersecurity, GRC, IT, HR, Legal and business stakeholders, you translate identity risks and business needs into practical standards, roadmaps and solutions that support VIA Rail's security governance, audit obligations and Zero Trust direction.

 

RESPONSIBILITIES: 

IAM Strategy, Architecture & Roadmap

  • Own and evolve VIA Rail's IAM strategy, including PAM, IGA and Access Management, aligned with cybersecurity objectives, business priorities and Zero Trust principles.
  • Define the IAM architecture roadmap, future-state capabilities and implementation plans for identity security initiatives and technology investments.
  • Lead evaluation, selection and optimization of IAM-related technologies and services, ensuring scalable and effective identity security solutions.
  • Partner with GRC and cybersecurity teams to manage identity-related risks, strengthen controls and compliance, provide program reporting and drive continuous improvement.

 

Identity Governance & Lifecycle Management (IGA)

  • Manage and evolve IGA capabilities for workforce, application and non-human identities across hybrid and cloud environments.
  • Oversee joiner-mover-leaver lifecycle processes, provisioning, de-provisioning, role models, entitlement catalogs and access certification campaigns.
  • Improve identity data quality and source-of-truth alignment with HR, application owners, GRC, Internal Audit and third-party providers.
  • Support application and service integrations with IGA capabilities, including lifecycle management, federation and privileged access patterns.

 

Privileged Access Management (PAM)

  • Manage and evolve PAM capabilities such as vaulting, session management, password rotation, credential brokering and just-in-time access.
  • Discover, classify and onboard privileged accounts across on-premises and cloud environments.
  • Define privileged access standards and procedures, including tiered administration, break-glass access, approvals and monitoring.
  • Partner with infrastructure, application and cloud teams to reduce standing privileges and enforce least privilege.

 

Access Management, Authentication & Federation

  • Operate and evolve access management capabilities including SSO, MFA, passwordless authentication, federation and adaptive access.
  • Design and enforce conditional access and modern authentication policies aligned with VIA Rail cybersecurity standards.
  • Define secure identity verification and access journeys for workforce, customer and partner scenarios.
  • Support integration of applications and services across on-premises, cloud and SaaS environments.

 

Certificate Management, PKI & Cryptography

  • Own the lifecycle of digital certificates across servers, applications, devices and non-human identities.
  • Operate and evolve VIA Rail's internal PKI, including AD CS, certificate templates, auto-enrollment and revocation services.
  • Govern public Certificate Authority relationships and support code-signing, S/MIME and TLS certificate programs.
  • Support cryptographic standards, certificate lifecycle automation and post-quantum cryptography readiness planning.

 

Identity Security, Operations, Audit & Advisory

  • Act as IAM subject-matter expert and provide security guidance to technology teams, projects and business stakeholders.
  • Support identity threat detection, incident response, hardening activities and root-cause analysis for recurring IAM issues.
  • Own IAM platform lifecycle, operational monitoring, documentation, metrics and management reporting.
  • Support audits, control assessments and remediation activities in coordination with GRC, while mentoring team members and acting as an escalation point.

 

WHAT WE ARE LOOKING FOR:

REQUIREMENTS:

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, Information Systems, or a related field.
  • Seven (7) or more years of progressive IT experience, including at least five (5) years focused on Identity & Access Management in complex enterprise environments.
  • Demonstrated experience designing, deploying and managing IAM, IGA, PAM, authentication and federation capabilities across on-premises, cloud and hybrid environments.
  • Hands-on experience with Active Directory and Microsoft Entra ID, including hybrid identity, directory services, conditional access, Privileged Identity Management and identity protection.
  • Experience with IGA and PAM platforms, automated provisioning/de-provisioning, access certifications, role and entitlement management, and privileged account controls.
  • Proficiency in certificate management and Public Key Infrastructure (PKI), including internal PKI operations such as Active Directory Certificate Services; certificate lifecycle automation experience is an asset.
  • Solid understanding of encryption, TLS configuration, identity security risks, IT audit, regulatory and compliance requirements, including segregation of duties and financial reporting controls.
  • One or more recognized certifications considered an asset: CISSP, CISM, CIAM, CISA, SC-300 (Microsoft Identity & Access Administrator), SC-900, SC-400, vendor-specific IGA / PAM / PKI certifications, and certifications in a major public cloud platform (Azure, AWS or Google Cloud).

 

COMPETENCIES

  • Expert knowledge of IAM domains, including IGA, PAM, Access Management, federation, credential management, identity verification and identity protection.
  • Strong administration experience with Active Directory and Microsoft Entra ID, including hybrid identity, conditional access, Privileged Identity Management and identity protection.
  • Hands-on experience with IGA and PAM tooling, automated lifecycle management, access certifications, SoD, role modeling, vaulting, session management and just-in-time access.
  • Strong understanding of authentication and federation protocols, including OIDC, OAuth 2.0, SAML 2.0, Kerberos, SCIM, WS-Fed and FIDO2/WebAuthn.
  • Certificate management, PKI and cryptography knowledge, including TLS, certificate trust chains, key management and post-quantum cryptography awareness.
  • Knowledge of cloud identity, workload identities, managed identities, least privilege, Zero Trust and identity-centric threats and mitigations
  • Ability to design end-to-end identity, access and cryptographic solutions that balance security, usability, compliance and operational cost.
  • Ability to translate business strategies, audit requirements and risk drivers into architecture, standards, roadmaps and technical controls.
  • Strong analytical, troubleshooting and root-cause analysis skills for complex hybrid identity and certificate-related issues.
  • Sound judgment, tact and diplomacy when managing risk-based decisions, trade-offs and challenging stakeholder situations.
  • Demonstrated ability to lead initiatives across multi-disciplinary teams, external service providers and business stakeholders.
  • Ability to mentor team members, influence peers without direct authority and provide guidance to IT staff and business users.
  • Excellent written and verbal communication in both English and French, with the ability to explain security matters clearly to technical, operational and executive audiences.
  • Strong stakeholder management, documentation discipline and client-oriented mindset, with consistent alignment to organizational mission, values and goals.

 

 

At VIA Rail, we are proud to be an employment-equity employer and we strive to form teams that reflect the diversity of Canadian society. We aim to remove barriers to employment accessibility and aspire to provide an inclusive and equitable work environment where everyone is valued, regardless of their identity or differences, to enable them to reach their full potential.

 

If you need assistance in making the recruitment process or the position you are applying for more accessible, please let us know. Alternate arrangements may be offered to individuals who request them at any stage of the recruitment process. All information received in relation to arrangements will be kept confidential.

 

Note that we will only contact those who are selected for an interview.

Join our 3,000 other employees in helping provide Canadians with a safe, accessible, environmentally sustainable way to travel!