IAM Engineer
Europe,
United Kingdom,
London
Permanent
Job ID: 2556
Job Description
[Up to c. £225k Comp Package | Office-Led Working]
Role Overview
We are representing a leading quantitative research and technology firm that is investing heavily in the security foundations supporting its researchers, engineers and critical technology platforms. The organisation is expanding its IAM capability from a predominantly operational function into a more engineering-led platform team. You will design, build and operate identity services spanning governance, authentication, entitlement management, privileged access and human and non-human identities, working closely with security engineers, penetration testers and wider technology teams...
Key Responsibilities
- Engineer and operate enterprise IAM platforms responsible for provisioning, modifying and removing access across human and non-human identities
- Develop and improve SailPoint IdentityIQ workflows, provisioning logic, connectors, policies and integrations with internal applications
- Strengthen joiner, mover, leaver and organisational-change processes across Workday, Active Directory and connected business systems
- Build and maintain an authoritative entitlement catalogue covering ownership, business purpose, risk classification, approval requirements and usage context
- Improve access-request, approval, certification and attestation processes while identifying stale, excessive, orphaned and inappropriate permissions
- Help redesign identity and authorisation models using RBAC, ABAC and policy-driven access controls suited to a complex multi-entity environment
- Engineer improvements across authentication, MFA, credential management, privileged access and delegated-access flows
- Create APIs, scripts, automation and self-service capabilities that reduce manual work and make identity services easier for engineering teams to consume
What You’ll Bring…
- Approximately 5-9 years’ experience across IAM engineering, identity security, IGA or closely related platform-engineering roles
- Strong hands-on experience building and operating SailPoint IdentityIQ, Saviynt or another enterprise identity-governance platform
- Practical knowledge of identity lifecycle management, including joiner, mover, leaver and organisational-change processes
- Experience integrating identity platforms with HR systems, Active Directory, LDAP, enterprise applications and authoritative data sources
- Strong understanding of entitlement governance, access models, approval workflows, access reviews, certifications and attestations
- Coding or scripting capability using Java, BeanShell, Python, PowerShell or a comparable language to develop integrations and automate IAM services
- Knowledge of identity integration and authentication technologies such as REST APIs, SCIM, federation, SSO, MFA and modern token-based standards
- (Preferred) Experience with Workday, FIDO2, Microsoft authentication, CyberArk, Ping, ForgeRock, service identities, workload identities or ephemeral access
...
Apply for this role
All fields marked with * are required.