4 months ago
London, United KingdomStaff+
Responsibilities
- Own end-to-end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls.
- Design and implement IAM integrations across SaaS, on-premises, AWS, Azure, and GCP environments using federation, MFA, and passwordless capabilities.
- Serve as the escalation point for complex IAM issues, perform root-cause analysis, and drive remediation and platform hardening.
- Define IAM engineering standards, patterns, and reference architectures for IGA, PAM, SSO, and application onboarding.
- Lead IAM modernization, security strategy, cloud security, threat modeling, red teaming, cloud security reviews, and large-scale security projects.
- Develop automated provisioning and deprovisioning workflows, access reviews, RBAC/ABAC models, and custom IAM connectors.
- Contribute technical evidence and compensating controls for audits, risk assessments, regulatory reviews, and IAM control-gap remediation.
- Engineer integrations with agentic AI tools for decisioning, policy enforcement, and identity lifecycle operations.
- Mentor and coach IAM engineers, analysts, and senior security engineers while influencing technical roadmaps and engineering practices.
- Collaborate with security, infrastructure, application, HR/IT, architecture, and executive stakeholders to align IAM initiatives with business goals and risk appetite.
Requirements
- 10+ years of experience in information security or infrastructure engineering, including at least five years of hands-on experience with core IAM platforms.
- Deep expertise with IAM platforms and strong hands-on experience with Microsoft Entra ID and Active Directory.
- Extensive experience with SAML, OIDC, and OAuth2 federation protocols and IAM solutions in hybrid multi-cloud environments.
- Experience implementing provisioning automation, access reviews, RBAC/ABAC models, secrets management, and custom IAM connectors.
- Proficiency in at least one scripting or programming language, such as PowerShell, Python, or Java.
- Experience leading large-scale IAM programs and serving as a technical lead or architect while mentoring teams and influencing roadmaps.
- Experience with CyberArk, Okta, SailPoint, Veza, AWS, GCP, Azure, Terraform, Codex, and Claude.
- Ability to balance security, usability, and operational efficiency while translating complex IAM concepts for technical and non-technical stakeholders.
- Experience with threat modeling, red teaming, cloud security reviews, audits, compliance obligations, and regulatory assessments.
- Strong ownership, communication, incremental delivery, and independent problem-solving skills.
