About this role
About the Role Join Information Security’s Identity Access Management Team as an IAM Architect. The ideal candidate has strong leadership skills and in-depth knowledge of the IAM security domain, with a strong focus on authentication technologies, industry standards, and emerging protocols. This role will deliver Scotiabank’s next-generation CIAM platform, aligned with the long-term product roadmap as part of a large-scale transformation. What You'll Do
- Be responsible for the architecture and design of new features/capabilities the bank is introducing into the IAM platform (ForgeRock / Ping / PingOne Advanced Identity Cloud).
- Provide subject matter expertise on security controls (MFA, device binding, session control) within ForgeRock/Ping platforms.
- Work with application domain architects to design solutions and migration patterns for moving business applications to modern CIAM capabilities (on-prem or SaaS).
- Review business requirements (the “what”) and provide the overall architectural design (the “how”) to the IAM Engineering team.
- Produce design artifacts that clearly outline the solution, components, key decisions, and estimated time and cost.
- Collaborate closely with IAM Engineering partners to ensure alignment and synergy of the proposed solution.
- Evaluate new authentication capabilities in the IAM landscape and determine applicability for short-term and long-term designs.
- Partner with cross-functional architect teams (IAM, security, business channel, fraud) to solidify the design approach. What We're Looking For
- Strong leadership skills and deep knowledge of the IAM security domain, with a focus on authentication technologies, industry standards, and emerging protocols.
- Experience designing and delivering CIAM platforms (ForgeRock / Ping / PingOne) and migrating applications to modern CIAM capabilities.
- Ability to translate business requirements into architecture and to produce design artifacts for stakeholders.
- Experience collaborating with cross-functional teams including IAM Engineering, security, and business channels (and fraud).
- Familiarity with evaluating new authentication capabilities and determining applicability for short-term and long-term roadmap.
- Knowledge of on-prem vs SaaS migrations and patterns.