Marks & Spencer Group plc

Principal Authentication Engineer (IAM) — Vice President

Marks & Spencer Group plc
Apply
2 hours ago

Responsibilities

  • Design, build, integrate, and operate secure authentication solutions for human and non-human identities at global scale.
  • Implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI, API authentication, and Unix/Linux authentication.
  • Integrate and customize Entra ID, Ping Identity, SailPoint, CyberArk, HashiCorp Vault, HSMs, IDM/LDAP, and RCBI across cloud and hybrid environments.
  • Operate large-scale IAM estates with high availability/disaster recovery, performance tuning, infrastructure as code, configuration management, CI/CD, observability, and safe deployment strategies.
  • Define and enforce identity lifecycle, authentication, authorization, privileged access management, and secrets management controls.
  • Assess existing solutions, identify risks and technical debt, deliver remediation plans, and implement secure-by-default patterns.
  • Translate architecture into epics, stories, runbooks, pipelines, ADRs, standards, and audit-ready documentation.
  • Collaborate with product and platform leads, participate in on-call, lead root-cause analyses, and drive operational excellence.
  • Coach engineers and SREs, conduct reviews, influence roadmaps, and drive adoption of identity controls and best practices.

Requirements

  • Hands-on principal-level engineering experience designing, implementing, configuring, integrating, and shipping production authentication solutions.
  • Deep enterprise-scale expertise with OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI including CA/RA and mTLS, certificate lifecycle management, JWT/mTLS API authentication, and Unix/Linux authentication.
  • Experience with HashiCorp Vault, HSMs, CyberArk, SailPoint, Entra ID, Ping Identity, IDM/LDAP, and RCBI, including policy design, integration, automation, and migrations.
  • Experience operating IAM and authentication services in large, globally distributed environments with multi-region high availability/disaster recovery, performance tuning, infrastructure as code, configuration management, CI/CD, and observability.
  • Strong Shell and Python or Go skills.
  • Knowledge of threat modeling, least privilege, privileged access management, secrets management, policy-as-code, and auditability for human and non-human identities.
  • Ability to customize and integrate vendor products and open standards into cohesive, documented solutions and APIs.
  • Ability to decompose solutions into epics and stories, author ADRs, runbooks, and standards, conduct reviews, coach engineers and SREs, and communicate clearly with stakeholders.
  • Experience navigating large institutional environments, influencing roadmaps, and driving adoption of controls and best practices.
  • Typically 10+ years of IAM engineering experience in complex, global settings.

Benefits

  • Morgan Stanley provides comprehensive employee benefits and perks for employees and their families.
  • Employees have opportunities for career mobility across the business.
  • Morgan Stanley supports diversity, inclusion, and equal opportunity.

Tech Stack

AnsibleChefGoLinuxPuppetPythonTerraform

Categories

Marks & Spencer Group plc

About Marks & Spencer Group plc

10,000+ employees
Contact me