Sunrisefarms
Cyber Security Engineer / IAM Specialist
Surrey, BC
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- CA
- Work mode
- On-site / unstated
- First seen by hirly
- 22 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
About the Role
We are looking for a versatile and highly skilled Cyber Security Engineer / IAM Specialist to play a pivotal role in securing our business and IT operations. As we are actively building and maturing our cyber security program, this role offers a unique opportunity to make a foundational impact.
You will serve as our subject matter expert for Identity and Access Management (IAM) and application security, ensuring that all third-party business and IT applications are implemented with a security-first mindset. Because our cyber program is evolving, this is a highly dynamic, cross-functional role. You will have your hands in multiple domains, including security governance, vulnerability management, operational technology (OT) security, and overarching cyber architecture.
Key Responsibilities
Application Security & Risk Management
Secure Implementation: Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.
Threat Modeling: Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.
Risk Mitigation: Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.
Identity & Access Management (IAM)
Lifecycle Management: Design, deploy, and manage our IAM lifecycle processes, ensuring the principles of least privilege and zero trust are applied across the organization.
Microsoft Ecosystem Management: Leverage the Microsoft environment (e.g., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).
Access Auditing: Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.
Cyber Program Development & Engineering
Vulnerability Management: Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.
Operational Technology (OT) Security: Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.
Governance & Compliance: Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.
General Cyber Support: Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.
Required Qualifications
Experience: Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.
Microsoft Environment Expertise: Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.
Threat Modeling Skills: Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.
IAM Proficiency: Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.
Broad Security Knowledge: Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.
Communication: Excellent ability to translate complex cyber risks into clear, actionable business recommendations for non-technical stakeholders.
Why Join Us?
This is a builder’s role. You will not just be turning the crank on existing processes; you will be instrumental in defining how we approach security across the business. If you enjoy a dynamic environment where you can touch multiple architectural aspects of cyber security, from evaluating a new SaaS application to securing OT networks, we want to hear from you.
Similar jobs
- Security Engineer IIPantheon · Canada (Remote)First seen 2d agoremote
- Security EngineerCloudbedsthirdpartyboard · CanadaFirst seen 6d agoremote
- Security EngineerCloudbeds · CanadaFirst seen 6d agoremote
- Information Security Engineer (Cloud) - ContractNumeris · Toronto, OntarioFirst seen 8d ago
- Product Security Engineer, North SecurityCohere · CanadaFirst seen 8d agoremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job