NES Fircroft is a leading global technical recruitment company providing professional contract and permanent staff to a diverse worldwide client base within the oil & gas industry.
Job Title: IAM Specialist
Location: Calgary, AB
Length: 1 Year (with potential extension)
Rotation: Monday - Friday
Role Summary
Provides Identity and Access Management (IAM) expertise across enterprise projects, supporting requirements review, solution design, access model validation, privileged access considerations, and identity integration activities. Acts as a subject matter expert to ensure project solutions align with IAM standards, cybersecurity policies, regulatory requirements, and access control objectives.
Identifies IAM-related risks, control gaps, and compliance impacts while recommending practical mitigation strategies and supporting successful project delivery.
Key Responsibilities
- Serve as the IAM subject matter expert for enterprise projects, providing both advisory and hands-on technical support across identity, access management, privileged access, authentication, authorization, and cross-application/system identity integration requirements.
- Review project requirements, solution designs, application onboarding approaches, role models, access workflows, and integration patterns to ensure alignment with IAM standards, cybersecurity policies, regulatory requirements, and access control objectives.
- Configure and maintain IAM-related controls in Active Directory and Microsoft Entra ID, including users, groups, roles, enterprise applications, app registrations, service principals, authentication settings, administrative roles, and access assignments.
- Design, create, test, and maintain Microsoft Entra Conditional Access policies supporting MFA enforcement, device compliance, location-based controls, guest and service account restrictions, and other risk-based access requirements.
- Develop, review, and maintain automation and scripting solutions, including PowerShell, to support access reporting, user and group management, role validation, policy analysis, bulk updates, and data remediation activities.
- Assess access models for least privilege, segregation of duties (SoD), privileged access controls, lifecycle management, approval workflows, and auditability requirements.
- Identify IAM-related risks, control gaps, compliance impacts, and operational dependencies; recommend mitigation strategies and support issue resolution with project teams and stakeholders.
- Support the definition, configuration, and validation of access requirements for applications, systems, integrations, and business processes, including roles, entitlements, groups, privileged access, service accounts, and identity lifecycle events.
- Partner with Cybersecurity Architecture teams, application owners, business stakeholders, project managers, vendors, and technical teams to ensure IAM requirements are incorporated early into project planning and implementation.
- Provide input into testing scope and acceptance criteria for IAM-related capabilities, including provisioning, deprovisioning, role assignment, privileged access, authentication controls, Conditional Access policies, and certification readiness.
- Support implementation readiness activities, documentation, knowledge transfer, operational handover, and post-implementation reviews to ensure IAM controls remain sustainable and supportable.
Role Scope
- Ensures project solutions comply with IAM standards, cybersecurity policies, regulatory requirements, and enterprise access control objectives.
- Provides IAM leadership and guidance throughout project lifecycles, from requirements gathering through implementation and operational transition.
- Supports risk management, control validation, audit readiness, and compliance initiatives.
- Improves identity security posture through effective access governance, privileged access management, and automation.
- Influences project teams and business stakeholders on IAM-related design, security, and operational decisions.
Qualifications
- Hands-on experience with Active Directory and Microsoft Entra ID (Azure AD).
- Strong understanding of IAM principles, including authentication, authorization, access governance, role-based access control (RBAC), and segregation of duties (SoD).
- Familiarity with access certification processes, IAM audits, and compliance requirements.
- Working knowledge of cybersecurity frameworks such as NIST CSF and industry best practices.
- Experience with PowerShell scripting or automation tools considered an asset.
- Understanding of IAM security controls and regulatory compliance requirements, including SOX.
Professional Skills
- Strong analytical, troubleshooting, and problem-solving capabilities.
- Ability to influence stakeholders and provide guidance through technical expertise and effective negotiation.
- Demonstrated ability to manage multiple priorities in a dynamic environment.
- Excellent written and verbal communication skills.
- Ability to assess access risks, recommend corrective actions, and clearly communicate outcomes to stakeholders.
- Detail-oriented with a strong governance and control mindset.
- Experience managing third-party vendors and service providers.
- Advanced knowledge of policy and security frameworks, including NIST, ISO, ISF, and related standards.
- Strong client relationship management skills with the ability to collaborate effectively with business partners and technical teams.
Education and Experience
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field required.
- Minimum 7 years of professional IT experience, including at least 5 years working directly in Identity and Access Management.
- Experience supporting enterprise-scale IAM projects, cybersecurity initiatives, or access governance programs preferred.
Apply here or send your resume to dilly.ohuegbe@nesfircroft.com