IAM Engineer with significant Active Directory and Entra ID experience is required to join a prestigious financial services organisation with offices in the heart of the city. Within this role you will manage, secure and optimise identity and access management systems and implement modern authentication protocols for networks, IT assets, applications, cloud, and third-party services.
Key Responsibilities:
- Provides guidance on best practices in directory, authentication, federation, and single sign-on (SSO) requirements and work programs.
- Collaborates closely with IT Security, Infrastructure, and Business Relationship Managers to implement Multi-Factor Authentication (MFA), Federation, and Single Sign-On (SSO) solutions.
- Manages directory and authentication solutions, including Active Directory (AD), Entra ID, Privilege Identity Management (PIM) and Sailpoint.
- Develop and enforce IAM policies, procedures, and standards to ensure the security and integrity of systems.
- Perform regular audits and assessments of IAM systems to identify and mitigate potential security risks.
- Works with Human Resources to manage onboarding and offboarding activities and establish authoritative sources for identities.
- Manages various AD domains and forests, collaborating with other Infrastructure groups within the organization as needed to support the AD environment.
- Diagnose and address issues and incidents related to Identity and Access Management (IAM).
- Maintains technical expertise, relevant industry standards and best practices as assigned in IAM technologies such as:
- Active Directory, Kerberos, LDAP, RADIUS
- Entra ID, Entra ID Sync, PIM, MFA, PAM, Conditional Access Policies
- Federation, SSO, SCIM
- SAML, OAuth, OIDC
- Plan and coordinate maintenance operations (evergreening service changes, patching, upgrades, disaster recovery tests, etc).
- Create and maintain both technical and process documentation across the broad range of Cloud services and disparate third party suppliers.
Key Skills and Experience:
- Microsoft Certified: Identity and Access Administrator, CISSP, CISM or equivalent security certification preferred.
- 5+ years of Active Directory management and security preferred.
- Deep understanding of IAM tools and technologies, such as multi-factor authentication (MFA), single sign-on (SSO), Role-based access control (RBAC) and identity governance
- Experience with Powershell scripting.
- Familiarity with Terraform and Infrastructure as Code tools and concepts.
- Familiarity with Agile/Lean/Scrum project management methodologies.
- Working in a distributed technical team within a regulated environment.
- Excellent problem-solving and troubleshooting skills.
- Strong communication and collaboration skills.
Desirable:
- Experience in Microsoft Azure security and protection technologies.
- Familiarity with management of Windows Server infrastructure and security hardening processes.
- Strong understanding of access control principles and identity management best practices.
- Experience with PKI, TLS, Certificate Management.
- Experience with monitoring, log analytics and SIEM tools such as Splunk, Solarwinds, Elastic, Azure Monitor, Defender or QRadar.
For a full consultation on this pivotal role, send your CV to ARC IT Recruitment.