Senior Specialist, Identity & Access Management

Job Requisition ID: 12037  

Position Status: Permanent Full Time 

Position Type: Hybrid 

Office Location: Ottawa (ON); Montreal (QC); Toronto (ON)

Travel Requirement: Limited 

Language Designation: English/French Optional 

Language Skill Levels (Read/Write/Speak): ZZZ 

Security Requirement:  Secret 

Salary: Our salaries generally range from $ 104,180.28 to $ 130,225.36 and are based on qualifications and experience. 

 

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

 

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

 

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

 

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Defined benefit pension plan.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more. 
  • An inclusive workplace culture and environment.
  • While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates. 

 

About the role

Join the IT Security Operations Team, in the Senior Specialist, Identity & Access Management position. In this role you will be responsible for designing, governing, and continuously improving the enterprise Identity and Access Management (IAM) program.  You will ensure that digital identities and access rights are appropriately defined, authorized, reviewed, and revoked in alignment with organizational risk tolerance, security policy, and regulatory obligations. The role provides expert-level advisory services to senior management and is accountable for the effectiveness and outcomes of IAM controls across the organization.

 

What you’ll do:

 

  • Lead IAM strategy, governance, and oversight by owning the enterprise Identity and Access Management (IAM) framework, including policies, standards, and control objectives.
  • Define and enforce core IAM principles, including identity lifecycle management, least privilege, role‑based access control (RBAC), segregation of duties, and access exception governance.
  • Ensure alignment with security, privacy, and compliance requirements, maintaining auditable and regulatory IAM practices across the enterprise.
  • Maintain accountability for IAM service effectiveness, including services delivered through internal teams and third‑party or managed service providers.
  • Assess and communicate identity‑ and access‑related risk, advising senior leadership on access risk acceptance, control design trade‑offs, and residual risk exposure.
  • Provide expert advisory support on IAM implications for new systems, cloud platforms, and third‑party integrations.
  • Define, monitor, and report on IAM KPIs and KRIs, producing executive‑ and board‑level reporting on access risk posture, control effectiveness, and compliance status.
  • Provide functional leadership and cross‑enterprise collaboration, mentoring IAM specialists, partnering with IT, security, audit, privacy, and business teams, and representing the organization in audits, regulatory reviews, and access‑related investigations.

 

What you should have:

 

  • A bachelor’s degree in information technology, Cybersecurity, or a related field. An equivalent combination of education and/or experience may be considered.
  • Advanced certification required (e.g., CISSP, CISM, or equivalent IAM certification).
  • 7 to 10 years of progressive experience in IAM, cybersecurity, or IT risk management.
  • Demonstrated experience advising senior leadership on enterprise‑level access risk.
  • Experience designing or governing IAM programs or control frameworks.

 

Posting closing date: Note, the competition will remain active until filled.  

 

Standby and Call Back duties are a requirement of this position and will be subject to CMHC policies, including the Standby and Call Back Pay Procedure.

 

Our commitment to diversity, equity, and inclusion 

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

 

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

 

Learn more about our commitment to diversity and inclusion 

 

What happens after you apply 

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process.  If you are selected for an interview or testing, please advise us if you require an accommodation.

 

If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!