CIAM Consultant or Senior Consultant
Deloitte View all jobs
- Toronto, ON
- Permanent
- Full-time
Work Model: Hybrid
Reference code: 132251
Primary Location: Toronto, ON
All Available Locations: Toronto, ONOur PurposeAt Deloitte, our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity. It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians.By living our Purpose, we will make an impact that matters.
- Have many careers in one Firm.
- Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
- Learn from deep subject matter experts through mentoring and on the job coaching
- Design, build, and implement CIAM solutions using platforms such as: Microsoft Entra ID (Azure AD B2C / External Identities), ForgeRock Identity Platform, Ping Identity (PingOne, PingFederate, PingAccess), Okta Customer Identity, Auth0
- Deliver end-to-end CIAM capabilities including: Customer registration and authentication flows, Social and federated identity integration, Adaptive and risk-based authentication, Consent and preference management, API security and token management (OAuth 2.0, OpenID Connect)
- Support solution architecture, technical design, and implementation across cloud and hybrid environments.
- Integrate CIAM platforms with customer-facing applications, APIs, and legacy systems.
- Engage with client stakeholders to understand business, security, and customer experience requirements.
- Translate business needs into technical CIAM solutions and roadmaps.
- Support workshops, requirement gathering, and design sessions.
- Produce high-quality deliverables including architecture diagrams, technical documentation, and implementation plans.
- Mentor junior team members and contribute to team capability development (Senior Consultant).
- Contribute to Deloitte CIAM assets, accelerators, and methodologies.
- Support pre-sales activities, proposals, and client demos.
- Stay current with emerging identity standards, threats, and CIAM platform innovations.
- 2–4+ years of experience in IAM or CIAM delivery
- Hands-on experience with at least one CIAM platform:
- Entra ID, ForgeRock, Ping Identity, Okta, or Auth0
- Working knowledge of: OAuth 2.0, OpenID Connect, SAML, REST APIs and JSON, Cloud platforms (Azure, AWS, or GCP)
- Experience supporting CIAM implementation projects or system integrations.
- Strong communication skills and ability to work in client-facing environments.
- 4–7+ years of IAM/CIAM experience with multiple platform implementations
- Strong hands-on expertise in CIAM architecture and solution design
- Experience leading workstreams or small delivery teams.
- Ability to advise clients on CIAM strategy, platform selection, and roadmap definition.
- Proven experience balancing security, usability, and regulatory requirements.
- Experience with Azure B2C / Entra External Identities migrations
- ForgeRock AM/IDM or PingFederate/PingOne advanced configuration
- Okta/Auth0 extensibility (rules, actions, custom flows)
- CIAM in high-scale consumer environments (millions of users)
- DevOps / CI-CD pipelines for IAM platforms
- Knowledge of Zero Trust and digital identity standards
- Relevant certifications (e.g. Azure, Okta, ForgeRock, Ping Identity)