About the Role
- We are seeking an experienced Identity & Access Management (IAM) Security Engineer to lead the design, implementation and ongoing enhancement of identity security controls across our Microsoft ecosystem and integrated business platforms.
- This role is responsible for securing digital identities, enforcing Zero Trust access principles, governing privileged access, and ensuring strong authentication controls across the organisation. The successful candidate will act as the technical authority for identity security, partnering with infrastructure, application, cloud and cybersecurity teams to reduce identity-related risk while supporting business agility.
- The position plays a critical role in maintaining regulatory compliance, supporting audit requirements, and ensuring identity and access controls align with organisational and Group cybersecurity standards.
Key Responsibilities
Identity Security Engineering
- Design, implement and manage identity security controls across Microsoft Entra ID and integrated platforms.
- Develop and maintain secure identity architectures that support Zero Trust security principles.
- Configure and optimise identity security controls to minimise the risk of unauthorised access and credential compromise.
- Ensure identity services are aligned with organisational security standards, regulatory requirements and industry best practices.
Conditional Access & Authentication Security
Design, implement and manage Conditional Access policies that balance security, risk mitigation and user experience.
Configure and enforce Multi-Factor Authentication (MFA) controls across the organisation.
Implement phishing-resistant authentication methods where appropriate, including:
FIDO2 Security Keys
Passwordless Authentication
Microsoft Authenticator
Identify and eliminate reliance on legacy authentication protocols.
Manage Self-Service Password Reset (SSPR) and authentication security controls.
Identity Protection & Threat Monitoring
- Configure and maintain Microsoft Entra Identity Protection policies.
- Monitor and respond to identity-related threats and suspicious activity, including:
- Risky users
- Risky sign-ins
- Impossible travel detections
- Unusual MFA activity
- Credential compromise indicators
- Privileged account anomalies
- Investigate and support remediation of high-risk identity events.
- Collaborate with Security Operations and incident response teams during investigations involving identity compromise.
Privileged Access Management
- Administer and optimise Microsoft Privileged Identity Management (PIM).
- Implement least-privilege access models across administrative functions and critical business systems.
- Define privileged access governance standards and approval workflows.
- Reduce standing administrative privileges through Just-In-Time (JIT) access controls.
- Monitor privileged access usage and investigate anomalous administrative activities.
Access Governance & Compliance
- Lead periodic user access reviews and privileged access attestations.
- Coordinate remediation of:
- Dormant accounts
- Orphaned accounts
- Excessive privileges
- Segregation of duties conflicts
- Ensure identity governance processes produce audit-ready evidence.
- Support internal and external audits relating to identity and access controls.
- Maintain policies, standards and operational procedures related to IAM security.
Identity Lifecycle Security
- Support Joiner, Mover and Leaver (JML) processes by designing secure identity governance controls and automation standards.
- Collaborate with HR, IT Operations and Application Owners to strengthen identity lifecycle security controls.
- Validate that access provisioning and deprovisioning processes operate effectively and within established service levels.
- Identify opportunities for identity process automation and risk reduction.
Federation, SSO & External Identity Security
- Support the secure implementation of:
- Single Sign-On (SSO)
- Federation services
- Business partner integrations
- Vendor and external identity access
- Review identity integrations for security risks and compliance requirements.
- Configure and secure authentication protocols including:
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- Ensure third-party access models align with organisational security standards.
Reporting & Governance
- Define, monitor and report key IAM security metrics, including:
- MFA adoption and coverage
- Privileged access coverage
- Time-to-deprovision
- Legacy authentication exposure
- Orphaned account volumes
- Access review completion rates
- Provide regular reporting to security leadership, audit and governance stakeholders.
- Support compliance and risk management initiatives through effective security reporting and evidence management.
Collaboration & Stakeholder Engagement
- Partner with the Intune, EUC & BYOD Security Engineer to align identity controls with endpoint trust and device compliance requirements.
- Collaborate with the Senior Microsoft Cloud & Platform Security Lead to support broader Microsoft security strategies.
- Work closely with infrastructure, cloud, application and governance teams to ensure identity security requirements are embedded within projects and operational processes.
- Act as a trusted advisor on identity security best practices across the organisation.
- Decision-Making Authority
The successful candidate will:
- Implement and manage Conditional Access policies, MFA controls and PIM configurations within delegated authority.
- Recommend identity security improvements, governance processes and access control enhancements.
- Escalate material identity risks, governance failures and non-compliant access practices to cybersecurity leadership.
- Validate that IAM controls meet regulatory, audit and organisational evidence requirements.
- Influence identity security standards and access governance practices across the business.
Essential Skills & Experience
Technical Experience
- Minimum 5-8 years' experience in Identity & Access Management, Identity Security or Cyber Security Engineering.
- Strong hands-on experience with Microsoft Entra ID (Azure AD) in enterprise environments.
- Extensive experience implementing:
- Conditional Access
- Multi-Factor Authentication (MFA)
- Identity Protection
- Privileged Identity Management (PIM)
- Access Reviews
- Entitlement Management
- Experience designing and supporting Zero Trust identity architectures.
- Strong understanding of authentication, authorisation and identity federation technologies.
- Experience supporting hybrid identity environments incorporating Active Directory and Entra ID.
Security & Governance Knowledge
- Strong understanding of:
- Zero Trust Architecture
- Least Privilege Access
- Segregation of Duties
- Identity Governance & Administration (IGA)
- Privileged Access Management (PAM)
- Access Certification Processes
- Regulatory and Audit Requirements
- Experience supporting internal audits, compliance assessments and control reviews.
Professional Skills
- Strong analytical, troubleshooting and problem-solving skills.
- Excellent communication and stakeholder management capabilities.
- Ability to engage effectively with technical and non-technical audiences.
- Strong attention to detail and governance discipline.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
Preferred Qualifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- CISSP, CISM, CRISC or equivalent security certification
- Certified Identity and Access Manager (CIAM) or equivalent IAM qualification advantageous
Core Technologies
Identity Platform
- Microsoft Entra ID (Azure AD)
- Conditional Access
- Identity Protection
- Entra ID RBAC
Privileged Access Management
- Privileged Identity Management (PIM)
- Administrative Role Governance
- Just-In-Time (JIT) Access
Authentication & Credential Security
- Microsoft Authenticator
- FIDO2 Security Keys
- Passwordless Authentication
- Multi-Factor Authentication (MFA)
- Self-Service Password Reset (SSPR)
- Legacy Authentication Blocking
Access Governance
- Access Reviews
- Entitlement Management
- Role-Based Access Control (RBAC)
- Segregation of Duties Controls
Hybrid Identity
- Active Directory
- Microsoft Entra Connect
- Hybrid Azure AD Join
Federation & Application Access
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- Single Sign-On (SSO)
- External Identity Integrations