Identity and Access Management Engineer
This role is based from our Coventry office and home. You will be required to attend the office approximately once per week.
Essential Criteria
- Practical experience in Identity & Access Management (IAM) principles including authentication, authorisation, Access control models (RBAC / ABAC / PBAC), identity lifecycle management (Joiners / Movers / Leavers) and an awareness of Zero Trust.
- Working knowledge of AI-driven or data-led initiatives within IAM or cybersecurity, with an understanding of how analytics can support identity security and governance.
- Ability to analyse identity telemetry (audit logs, sign-in logs, access data) to support investigations, identify trends, and contribute to operational and security improvements.
- Hands-on experience with Microsoft Entra ID (Azure AD), including:
o User and group management (static and dynamic groups)
o Role assignments, service principals, and application registrations
o Familiarity with tenants, directories, objects, and attribute structures
o Supporting Conditional Access, SSPR, MFA, and passwordless authentication (e.g. Windows Hello for Business, FIDO2)
o Identity governance activities including Access reviews, Entitlement Management and access control models.
o MS and 3rd party Agentic AI agents governance and lifecycle management.
- Engineering experience in Active Directory:
o User and group management, OU structures, Group Policy Objects (GPOs)
o Basic LDAP knowledge
o Understanding of Hybrid identity integration (Azure AD Connect / Cloud Sync)
o Awareness of AD tiering concepts and disaster recovery principles
- Experience working with Identity Governance tooling such as Saviynt / SailPoint or any other similar product.
- Ability to define AI or identity-analytics use cases, particularly in areas such as identity governance, lifecycle management, and access risk reduction.
- Awareness of the identity threat landscape and an understanding of how analytics or AI techniques can help detect and reduce identity‑based risks.
- Ability to work with the Engineering Manager, Product Manager, Stakeholders and senior engineers to deliver technical tasks and milestones aligned to agreed IAM roadmaps.
- Proven ability to work collaboratively with IT teams, product teams, security operations, and service partners to support secure IAM delivery and protect colleague and customer data.
- Exhibit excellent communication and presentation skills, able to convey complex issues and findings clearly and effectively.
- Demonstrates a strong technical and delivery focussed mindset, able to follow designs, apply sound engineering practices, and contribute to secure, scalable IAM solutions.
- Shows a commitment to continuous learning, staying current with identity, security, and AI developments, and applying new knowledge to improve IAM services.
Additional Criteria
- Understanding of AI and machine learning concepts to analyse identity-related data (e.g. sign-in logs, access patterns, usage trends)
- Awareness of AI-assisted automation use cases within IAM:
o Access or sign‑in anomaly detection
o Risk-based access decisions
o Intelligent access reviews or entitlement recommendations
- Experience or familiarity with Microsoft security and analytics tools (e.g. Entra ID logs, Azure Monitor, Log Analytics, Sentinel).
- Awareness of ethical AI and responsible use of AI, especially in security-sensitive and personal-data contexts.
- Exposure to Privileged Access Management (PAM) solutions and role-based privileged access (hands-on experience beneficial but not essential)
- Understanding data governance, data quality, and information security principles, particularly where AI models consume identity data.
- Relevant professional certifications (or actively working towards), such as:
o Microsoft Identity or Security certifications
o AI / data analytics certifications
o CISSP, CISM, or equivalent (desirable)