
Principal Authentication Engineer (IAM) — Vice President
Marks & Spencer Group plc2 hours ago
Responsibilities
- Design, build, integrate, and operate secure authentication solutions for human and non-human identities at global scale.
- Implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI, API authentication, and Unix/Linux authentication.
- Integrate and customize Entra ID, Ping Identity, SailPoint, CyberArk, HashiCorp Vault, HSMs, IDM/LDAP, and RCBI across cloud and hybrid environments.
- Operate large-scale IAM estates with high availability/disaster recovery, performance tuning, infrastructure as code, configuration management, CI/CD, observability, and safe deployment strategies.
- Define and enforce identity lifecycle, authentication, authorization, privileged access management, and secrets management controls.
- Assess existing solutions, identify risks and technical debt, deliver remediation plans, and implement secure-by-default patterns.
- Translate architecture into epics, stories, runbooks, pipelines, ADRs, standards, and audit-ready documentation.
- Collaborate with product and platform leads, participate in on-call, lead root-cause analyses, and drive operational excellence.
- Coach engineers and SREs, conduct reviews, influence roadmaps, and drive adoption of identity controls and best practices.
Requirements
- Hands-on principal-level engineering experience designing, implementing, configuring, integrating, and shipping production authentication solutions.
- Deep enterprise-scale expertise with OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI including CA/RA and mTLS, certificate lifecycle management, JWT/mTLS API authentication, and Unix/Linux authentication.
- Experience with HashiCorp Vault, HSMs, CyberArk, SailPoint, Entra ID, Ping Identity, IDM/LDAP, and RCBI, including policy design, integration, automation, and migrations.
- Experience operating IAM and authentication services in large, globally distributed environments with multi-region high availability/disaster recovery, performance tuning, infrastructure as code, configuration management, CI/CD, and observability.
- Strong Shell and Python or Go skills.
- Knowledge of threat modeling, least privilege, privileged access management, secrets management, policy-as-code, and auditability for human and non-human identities.
- Ability to customize and integrate vendor products and open standards into cohesive, documented solutions and APIs.
- Ability to decompose solutions into epics and stories, author ADRs, runbooks, and standards, conduct reviews, coach engineers and SREs, and communicate clearly with stakeholders.
- Experience navigating large institutional environments, influencing roadmaps, and driving adoption of controls and best practices.
- Typically 10+ years of IAM engineering experience in complex, global settings.
Benefits
- Morgan Stanley provides comprehensive employee benefits and perks for employees and their families.
- Employees have opportunities for career mobility across the business.
- Morgan Stanley supports diversity, inclusion, and equal opportunity.