Identity Security Engineer
We are seeking an Identity Security Engineer to be embedded with our customer, a leading organisation in the aviation industry, where you will serve as a core engineering team member responsible for governance and continuous improvement of their identity security posture, including privileged access management. This hands-on role supports the delivery of identity security standards, secure-by-design architectures, identity lifecycle management and access controls under the direction of a senior engineer, working closely with the customer's technology, cyber and business teams.
Key responsibilities & duties include:
Lead ownership of identity and privileged security policies, standards and architecture patterns across Active Directory, Entra and IGA services, ensuring consistency and alignment with the customer's security objectives
Implement and maintain identity lifecycle workflows and governance processes including joiners, movers and leavers, access requests and access reviews using SailPoint, working with the customer's teams to drive adoption and operational excellence
Support implementation of a privileged access platform and develop privileged access controls as part of the customer's identity services, including governance and lifecycle processes
Engineer continuous improvements to identity security controls, PAM and IAM lifecycle processes, enabling self-service and scalable services through automation and working with the customer's stakeholders
Deliver identity posture monitoring and drive ongoing improvements to identity security controls, while providing specialist support for identity-related security incidents and investigations to enable containment and remediation
Support the building of identity metrics and dashboards for centralised oversight of the customer's identity security controls coverage, effectiveness and risks, and collaborate with application and platform teams to embed secure-by-design identity patterns including authentication, authorisation, RBAC and least privilege
Maintain documentation and blueprints for identity security standards and processes, manage configuration of the customer's identity security platforms, contribute to cross-domain security architecture reviews and partner with the customer's Cyber Defence function to ensure appropriate identity telemetry is monitored
Required Experience:
Minimum of 10+ years' industry experience with at least 5+ years in identity management or identity security engineering roles
Hands-on experience with Active Directory and/or Entra in an enterprise environment
Hands-on experience designing, implementing and governing identity lifecycle and access lifecycle processes using an IGA platform
Experience designing and implementing privileged access management controls and processes
Strong understanding of IAM principles including zero trust, least privilege, RBAC, access reviews and certifications, segregation of duties concepts and lifecycle governance
Ability to define secure identity architecture patterns and translate them into practical standards and blueprints, with proven capability to implement identity standards and controls consistently and document outcomes
Desirable skills:
Relevant certifications such as Microsoft identity or security credentials, CISSP, CISM, CIAM or CRISC
Scripting and automation exposure such as PowerShell to improve identity governance processes
Experience with identity threat detection concepts and integration with SOC monitoring, and familiarity with non-human identity governance patterns and modern authentication protocols
Engineering experience with identity protection and governance platforms including SailPoint, CyberArk, BeyondTrust, Microsoft Defender for Identity, Crowdstrike Identity or SilverFort