View job listing
Apply to CIAM Technology Lead / Technical Architect
CIAM Technology Lead / Technical Architect
Access management architect with hands-on API security and application integration depth
The emphasis is specifically on customer access management, authentication and authorization. This is not an identity governance administration or privileged access management role. Candidates whose experience is limited primarily to SailPoint, Saviynt or CyberArk will not match the core requirement unless they also bring substantial CIAM and application access management depth.
Access management architect with hands-on API security and application integration depth
| Engagement | Initial four-month contract with a strong expectation of extension beyond one year |
| Location | Toronto, hybrid; two days per week onsite, with exact days to be confirmed |
| Start | ASAP |
| Core focus | CIAM architecture, authentication, authorization and secure application integration |
| Interview process | One interview with the consulting partner, followed by one end-client interview |
The Opportunity
We are seeking a senior CIAM Technology Lead / Technical Architect to help shape and lead a major customer access management initiative for a Canadian financial institution. This person will sit one level above the detailed development work, providing solution oversight while remaining technically hands-on enough to validate designs, integrate security protocols and build or compile application components when required.The emphasis is specifically on customer access management, authentication and authorization. This is not an identity governance administration or privileged access management role. Candidates whose experience is limited primarily to SailPoint, Saviynt or CyberArk will not match the core requirement unless they also bring substantial CIAM and application access management depth.
Key Responsibilities
- Own and guide the technical architecture for CIAM and customer access management capabilities.
- Translate business and security requirements into clear technical requirements, solution scope and delivery direction.
- Design and review authentication and authorization patterns using OIDC, OAuth 2.0, security tokens and secure API endpoints.
- Provide architectural guidance for API security, API access management, API gateways and REST API integrations.
- Lead application integration with Transmit Security or comparable CIAM platforms such as PING, ForgeRock or Microsoft Entra ID.
- Review solution designs, identify technical risks and establish practical implementation standards.
- Provide technical oversight across the onshore and offshore delivery team, including developers and other technology leads.
- Work effectively within Agile delivery, helping teams refine technical requirements and move from business need to executable scope.
- Remain hands-on enough to create Java modules and build or compile front-end and back-end applications when needed.
- Represent the technical solution confidently with client, consulting and delivery stakeholders.
Required Experience and Skills
- Senior experience delivering CIAM or access management programs in a technical architect, technology lead or comparable capacity.
- Deep understanding of authentication and authorization, including hands-on OIDC and OAuth 2.0 integration experience.
- Strong knowledge of API security, REST APIs, API gateways, access tokens and applications that consume protected API services.
- Working development knowledge of Java and the ability to understand, build and validate front-end and back-end applications.
- Experience converting business requirements into technical requirements, defining scope and guiding delivery teams.
- Strong leadership, consulting and client-facing communication skills.
- Eligibility to work in Canada and ability to attend the Toronto office two days per week.
Platform Experience
Direct Transmit Security experience is valuable but not required. Strong candidates may instead bring meaningful architecture and implementation experience with one or more of the following platforms:- PING / Ping Identity
- ForgeRock
- Microsoft Entra ID or another enterprise CIAM platform, provided the candidate can explain their hands-on contribution to a broader CIAM transformation program
Preferred Experience
- Banking, financial services or regulated enterprise delivery experience.
- Call-centre authentication, out-of-band authentication or customer identity verification experience.
- Practical understanding of modern full-stack application architecture, including Java/Spring Boot and Angular or React.
What Success Looks Like
- The candidate establishes a clear, secure and implementable CIAM architecture and translates business requirements into well-scoped technical work.
- Authentication, authorization and API security designs follow sound standards and withstand detailed client review.
- The delivery team receives credible technical leadership while the candidate remains capable of hands-on intervention when needed.
