We are seeking a highly motivated and experienced automation engineer with IAM/Workload Identity experience to design and implement automation pipelines that enable secure, scalable, and auditable self-service infrastructure provisioning across our cloud environments (Azure, GCP, and on-prem). This engineer will play a critical role in transforming how developers and service teams consume cloud resources, by codifying access patterns, integrating with Vault, and enforcing least-privilege IAM models using GitHub Actions and Terraform.
This role is part of our broader initiative to modernize secrets management, access control, and compliance automation through infrastructure-as-code.
Depth & Scope:
Education & Experience:
Preferred Qualifications:
β’ Build and maintain GitHub Actions workflows for self-service provisioning of infrastructure, secrets, and IAM roles using Terraform.
β’ Develop reusable Terraform modules that encapsulate compliant patterns for deploying GCP, Azure, and on-prem infrastructure (VMs, networks, K8s clusters, etc.).
β’ Integrate with HashiCorp Vault to securely inject secrets into pipelines and support runtime retrieval for VMs and services.
β’ Support the GitHub repository onboarding process by automating bindings between repositories, identity pools, and service accounts.
β’ Enable secure OIDC-based pipeline authorization (e.g., GCP Workload Identity Federation, Azure Federated Credentials).
β’ Drive automation for certificate-based authentication for on-prem VMs accessing Vault and other internal services.
β’ Collaborate with platform, IAM, and security teams to implement compliant patterns for secrets, identity, and access governance.
β’ Design self-service onboarding workflows for developers and application teams across environments (EDP-GT, EDP-XL, TD Universe).
β’ Contribute to internal documentation and Confluence living strategies to ensure transparency and onboarding clarity.
β’ Experienced with Terraform (including module design, state management, and CI integration) β’ Proficiency with GitHub Actions for CI/CD pipelines and automation workflows β’ Deep knowledge of cloud IAM models (especially GCP Workload Identity Federation and Azure Entra ID) β’ Understanding of cert-based authentication, secure software supply chain, and compliance automation β’ Familiarity with Kubernetes, container-based deployments, and cloud-native network/security controls β’ Comfortable working in multi-cloud environments (Azure, GCP) and hybrid setups (VMC2, on-prem) β’ Strong scripting skills (e.g., Bash, Python, or Go)
Physical Requirements:
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties, and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.
Who We Are: TD is one of the worldβs leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States, and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities, and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing β and so will you.
Our Total Rewards Package: Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including vacation PTO, flex PTO, and holiday PTO), banking benefits and discounts, career development, and reward and recognition.
Additional Information: We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home. Colleague Development: If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD β and we're committed to helping you identify opportunities that support your goals. Training & Onboarding: We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role. Interview Process: We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation: TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law. If you are an applicant with a disability and need accommodations to complete the application process,