Questrade Financial Group
Strategy Advisor, Identity & Access Management
Toronto, Ontario · Posted today
Opens jobs.dayforcehcm.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Not specified
- Work mode
- Not specified
- Source
- Dayforce (employer's hiring system)
Skills mentioned
IAM, Cybersecurity, Azure, GCP, AWS, SOC 2, French, Bilingual
About the role
What’s in it for you as an employee of QFG?
Health & wellbeing resources and programs
Paid vacation, personal, and sick days for work-life balance
Competitive compensation and benefits packages
Work-life balance in a hybrid environment with at least 3 days in office
Career growth and development opportunities
Opportunities to contribute to community causes
Work with diverse team members in an inclusive and collaborative environment
This job posting is for an existing vacancy.
We’re looking for our next Strategy Advisor, Identity & Access Management. Could It Be You?
The Advisor, Identity & Access Management Strategy owns the enterprise identity strategy across Questrade Financial Group’s regulated entities. The role sets direction, standards and the multi-year roadmap for workforce identity, privileged access, identity governance and administration, and non-human identity (including Agentic Identity), and leads the IAM team that delivers them. It is accountable for the identity control environment meeting business, security and regulatory requirements in each QFG entity, and for the vendor decisions, governance and evidence that keep it there. This is a strategy and leadership role; deep technical execution is led by the Principal Engineer, Identity & Access Management, and other IAM team members, under this role’s direction.
This role operates within a CIRO-regulated dealer and an OSFI-regulated federal financial institution (FRFI) environment. Candidates must understand that entity segregation between Questrade Inc. and Questbank is a foundational architectural constraint.
Need more details? Keep reading…
In this role, responsibilities include but are not limited to:
Scope and boundaries
Owning enterprise identity strategy, standards, roadmap and governance for workforce identity life-cycle, privileged access, IGA and non-human identity across all QFG entities.
Delegating hands-on design and engineering execution to the Principal Engineer, IAM, and the IAM team. This role directs, prioritizes and is accountable for outcomes.
Client identity (CIAM): this role defines and represents the security requirements, standards and controls that client-facing identity platforms must meet, and contributes to policy engine design to minimize account takeover risks. Platform delivery ownership follows the enterprise architecture decision on the CIAM target state.
Strategy and roadmap
Owning the Enterprise and Client IAM vision, strategy and multi-year roadmap across all QFG entities; aligning with business, technology and security strategy; secure executive approval and funding.
Leading requirements-first selection of identity platforms and vendors: defining control requirements before evaluating products, running trade-off analysis, and recording decisions. No platform is adopted or retired without a documented decision.
Entity governance and regulatory
Owning the identity control and compliance posture of each QFG regulated entity separately, including entity-scoped design, evidence and reporting.
Maintaining the identity dimensions of OSFI Guideline B-13, third-party access expectations under OSFI Guideline B-10, resilience considerations under OSFI Guideline E-21, and CIRO cybersecurity expectations, producing evidence in the form of auditors and regulators can test.
Supporting OSFI supervisory reviews, CIRO examinations, SOC 2 examinations and internal audits for identity domains; driving remediation of identity findings to closure with named owners and committed dates.
Workforce and privileged identity
Setting standards for access, authentication and authorization across the workforce: single sign-on, personal password management, MFA and authentication escalation, risk-based access, and the joiner-mover-leaver lifecycle.
Owning privileged access program outcomes: vault coverage, credential rotation, JIT/JEA, session accountability and emergency access, with measurable targets and quarterly reporting.
Identity governance and administration
Owning the IGA strategy: authoritative attribute sourcing from HR systems, the role and entitlement model, automated provisioning and deprovisioning, and access certification across all enterprise platforms, with check-and-balance controls for data quality, integrity and timeliness.
Non-human and cloud identity
Owning governance of non-human identity: service accounts, agentic identities, workload identities, API keys and secrets across on-premises, GCP, AWS, Azure and Microsoft Entra, including inventory, ownership, rotation and least privilege.
Metrics and reporting
Owning identity KPI and KRI targets and reporting to executive and Board audiences, using the measurement library maintained by the IAM team. Directing effort by risk, not evenly.
People management
Leading, developing and retaining the IAM team; setting goals aligned to strategy; addressing performance in a timely manner.
Forecasting resourcing against the roadmap and presenting evidence-based cases for changes.
Acting as the team’s advocate: removing blockers and securing the tools, processes and organizational support the team needs.
Building succession depth and cross-training so that no identity capability depends on a single person.
Collaboration and change
Partnering with Enterprise Architecture, cloud and data leadership, DevSecOps, JSOC, Enterprise Fraud, GRC, Privacy, Legal, People & Culture and User Experience; resolving conflicting priorities and negotiating outcomes.
Sponsoring identity-related change programs across entities and building adoption through clear communication at executive and technical levels.
So are YOU our next Strategy Advisor, Identity & Access Management? You are if you…
Have 10+ years of experience in cybersecurity with substantial IAM leadership, including ownership of an enterprise IAM strategy and leadership of multidisciplinary teams in financial services
Have proven experience with end-to-end delivery of complex IAM programs — strategy through operationalization — in regulated environments
Have deep experience working across privileged access management (Delinea), identity governance and administration (SailPoint), Microsoft Entra and the EMS E5 security stack, and identity threat detection (CrowdStrike Identity Protection): enough to set direction, challenge designs and hold vendors to account
Have demonstrated proficiency in Hybrid Identity Architecture: governing complex identity environments spanning Active Directory (AD), Microsoft Entra (formerly Azure AD), and GCP federation
Have experience governing non-human identity at scale: service accounts, secrets and workload identity across cloud providers
Have working knowledge of OSFI Guidelines B-13, B-10 and E-21, CIRO cybersecurity expectations, PIPEDA and Quebec Law 25, or demonstrated ability to learn a new prudential regime quickly
Have experience producing audit-ready evidence and interacting directly with auditors and regulators
Have strong experience with budget planning and financial management for technology programs
Possess Executive and Board-level verbal and written communication skills, at a standard suitable for regulator-facing documentation
Have strong stakeholder management skills in a matrixed organization with ability to influence without direct authority and hold people to committed dates
Have proven leadership experience to develop, coach and retain talent; addressing performance early; building morale, belonging and succession
Are comfortable navigating ambiguity, separating relevant trends from hype and making sound decisions with incomplete information
Additional kudos if you…
Are Bilingual - written and verbal fluency in English and French
Hold CISSP, CISM, IDPro CIDPRO, or vendor certifications (Delinea, SailPoint, Microsoft Entra)
Compensation Information:
Base salary range: $170,000 - $185,000
The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.
Sounds like you? Click below to apply!
#LI-NP1
#LI-Hybrid
Job ID df-qfg-candidateportal-17904 · Original posting ↗