Role: Full Stack .NET/Privileged Access Platform Engineer
Location: Montreal or Alpharetta, 3 days/week onsite
Overview: Hands-on senior developer joining the Privileged Access Management team to build a secure privileged-access orchestration and integration platform connecting ITSM/CMDB systems, privileged access management tooling, Microsoft identity and endpoint services, and enterprise audit platforms. This role does not require prior domain expertise in privileged access management tools (e.g., CyberArk) — training/context will be provided. Strong full stack .NET development skills are the priority.
Responsibilities
• Develop production-grade services using C#/.NET and ASP.NET Core, including REST APIs, background workers, policy/orchestration services, event-driven workflows, and reconciliation processes.
• Build front-end administrative interfaces using Angular, supporting privileged-access request, approval, and monitoring workflows.
• Build orchestration and integration workflows across privileged access management platforms (session management, endpoint privilege management, and automation components), Microsoft Entra PIM, Intune, Windows LAPS, Microsoft Graph, Windows 365, ITSM/CMDB systems, and endpoint-management/automation platforms.
• Implement policy-driven authorization workflows that evaluate user identity, device identity, role eligibility, business approval, requested operation, target scope, risk level, device posture, and permitted duration before privileged actions are executed.
• Develop orchestration logic that determines the correct execution mechanism (privileged session brokering, endpoint elevation, PIM activation, endpoint-management actions, credential recovery, or other approved mechanisms) while preventing overlapping or conflicting control-plane behavior.
• Design Azure-hosted solutions using services such as Azure App Service, Container Apps or AKS, API Management, Service BEvent Grid, Azure SQL, Key Vault/Managed HSM, Managed Identities, Application Insights, and private networking.
• Implement secure multi-tenant and multi-region application patterns: tenant isolation, scoped workload identities, per-environment secrets/keys, authorization boundaries, replay protection, idempotency, and resilient failover.
• Engineer reliable orchestration workflows with comprehensive instrumentation, including activation, extension, expiry, revocation, credential rotation, reconciliation, stale-access cleanup, dependency-failure handling, retries, and verification that privileged access was actually removed across downstream systems.
• Build scalable asynchronous and bulk-operation capabilities: queues, bounded concurrency, target manifests, canary execution, per-target result tracking, cancellation, retries, and partial-failure handling.
• Implement comprehensive security and audit telemetry capturing requester, approver, operator, target, requested action, policy decision, timestamps, downstream transaction/session identifiers, expiration/revocation, and execution outcome.
• Apply secure software engineering practices: OAuth 2.0/OIDC, workload identity federation, Managed Identities, certificate-based authentication, RBAC, least privilege, OWASP controls, threat modeling, secrets management, secure SDLC, and automated security testing.
• Build automated testing covering unit, integration, contract, authorization-boundary, cross-tenant, concurrency, failover, revocation, reconciliation, and security scenarios, supported by CI/CD and Infrastructure-as-Code (using Ansible for automation) with enterprise-standard tooling.
Requirements
• Strong hands-on experience with C#/.NET, ASP.NET Core, and Angular in a full stack capacity.
• Experience building and operating large-scale