
Senior Consultant - Cyber Customer Identity & Access Management
- Toronto, ON
- $72,000-138,000 per year
- Permanent
- Full-time
Work Model: Hybrid
Reference code: 128886
Primary Location: Toronto, ON
All Available Locations: Toronto, ONOur PurposeAt Deloitte, our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity. It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians.By living our Purpose, we will make an impact that matters.
- Have many careers in one Firm.
- Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
- Learn from deep subject matter experts through mentoring and on the job coaching
Our IAM offering advises our clients and implements and operates secure identity and access management solutions that leverage the leading-edge technologies of today’s access management requirements and needs.What will your typical day look like?Key Responsibilities
- Design and develop comprehensive CIAM architectures encompassing identity lifecycle management, authentication, authorization, consent management, and data privacy compliance.
- Lead CIAM initiatives by evaluating, selecting, customizing, and integrating CIAM platforms such as Okta, Auth0, Ping Identity.
- Collaborate cross-functionally with product owners, UX designers, security teams, engineers, and enterprise architects to define user identity journeys and translate business requirements into technical solutions.
- Produce detailed architectural documentation including sequence diagrams, threat models, data flow diagrams, and security controls.
- Integrate CIAM solutions with backend systems, APIs, gateways, analytics platforms, and CI/CD pipelines to enable secure and scalable identity services.
- Implement advanced authentication technologies such as adaptive authentication, identity proofing, MFA, federation protocols (SAML, OIDC, OAuth).
- Stay current with CIAM market trends, zero trust security models, passwordless authentication, and evolving regulatory requirements (GDPR, CCPA, HIPAA, PCI-DSS).
- 5+ years of experience in Identity and Access Management (IAM), with a minimum of 2 years specializing in CIAM solutions.
- Proven expertise with one or more CIAM platforms: Okta, Auth0, PingOne Advanced Identity Cloud, PingOne, Entra ID, or equivalent.
- Deep understanding of authentication and authorization protocols, including OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and Financial-grade API (FAPI).
- Experience with identity federation, single sign-on (SSO), multi-factor authentication (MFA), risk-based and adaptive authentication mechanisms.
- Hands-on proficiency with RESTful APIs, JSON Web Tokens (JWT), and modern web technologies.
- Excellent collaboration, communication, and documentation skills to articulate complex architectural concepts.