IAM Engineer

Europe, United Kingdom, London
Permanent
Job ID: 2556

Job Description


[Up to c. £225k Comp Package | Office-Led Working]


Role Overview

We are representing a leading quantitative research and technology firm that is investing heavily in the security foundations supporting its researchers, engineers and critical technology platforms. The organisation is expanding its IAM capability from a predominantly operational function into a more engineering-led platform team. You will design, build and operate identity services spanning governance, authentication, entitlement management, privileged access and human and non-human identities, working closely with security engineers, penetration testers and wider technology teams...


Key Responsibilities

  • Engineer and operate enterprise IAM platforms responsible for provisioning, modifying and removing access across human and non-human identities
  • Develop and improve SailPoint IdentityIQ workflows, provisioning logic, connectors, policies and integrations with internal applications
  • Strengthen joiner, mover, leaver and organisational-change processes across Workday, Active Directory and connected business systems
  • Build and maintain an authoritative entitlement catalogue covering ownership, business purpose, risk classification, approval requirements and usage context
  • Improve access-request, approval, certification and attestation processes while identifying stale, excessive, orphaned and inappropriate permissions
  • Help redesign identity and authorisation models using RBAC, ABAC and policy-driven access controls suited to a complex multi-entity environment
  • Engineer improvements across authentication, MFA, credential management, privileged access and delegated-access flows
  • Create APIs, scripts, automation and self-service capabilities that reduce manual work and make identity services easier for engineering teams to consume


What You’ll Bring…

  • Approximately 5-9 years’ experience across IAM engineering, identity security, IGA or closely related platform-engineering roles
  • Strong hands-on experience building and operating SailPoint IdentityIQ, Saviynt or another enterprise identity-governance platform
  • Practical knowledge of identity lifecycle management, including joiner, mover, leaver and organisational-change processes
  • Experience integrating identity platforms with HR systems, Active Directory, LDAP, enterprise applications and authoritative data sources
  • Strong understanding of entitlement governance, access models, approval workflows, access reviews, certifications and attestations
  • Coding or scripting capability using Java, BeanShell, Python, PowerShell or a comparable language to develop integrations and automate IAM services
  • Knowledge of identity integration and authentication technologies such as REST APIs, SCIM, federation, SSO, MFA and modern token-based standards
  • (Preferred) Experience with Workday, FIDO2, Microsoft authentication, CyberArk, Ping, ForgeRock, service identities, workload identities or ephemeral access


...


Apply for this role

All fields marked with * are required.

I confirm I have a pre-existing right to work in the role’s location *
I require visa sponsorship now or will require it in the future

Back to Job Listings