Skills
Microsoft Entra ID
Active Directory
Azure
Hybrid identity
Azure AD Connect
Microsoft Intune
Endpoint Management
Conditional Access
Identity Governance
PIM
MFA
SSO
LDAP
Kerberos
NTLM
SAML
OAuth 2.0
OIDC
Zero Trust
PowerShell
Azure CLI
Microsoft Graph API
Technical architecture
Windows Autopilot
Terraform
GitHub
Azure DevOps
Summary
Lead the modernization of enterprise identity services from legacy directory infrastructure to a secure cloud-first architecture. You will own the IAM roadmap, design hybrid identity solutions, strengthen authentication and governance controls, automate operational processes, and provide technical leadership across transformation initiatives.
Highlights
Senior ownership role leading a major cloud-first identity transformation, with technical leadership, architecture influence, mentoring, and close collaboration across security and infrastructure teams.
Description
Role: Senior IAM Engineer
Location: London, United Kingdom (Hybrid)
Employment Type: Full-time
Salary: Competitive + Benefits
Are you an experienced Identity & Access Management Engineer with a passion for modernising enterprise identity platforms and delivering cloud-first security solutions? We're looking for a hands-on Senior IAM Engineer to take ownership of our identity strategy and lead the transformation from a traditional Active Directory environment to a modern Microsoft Entra ID-centric architecture.
This is a unique opportunity to play a pivotal role in shaping the future of identity and access management across a growing retail organisation.
You'll work closely with Cyber Security, Infrastructure, Network and Application teams to deliver a secure, scalable and compliant identity platform while acting as the subject matter expert for IAM technologies, governance and modern authentication.
What You'll Do
Own and deliver the organisation's IAM strategy and roadmapLead the transition from traditional Active Directory services towards a cloud-first Entra ID architectureDesign and manage hybrid identity solutions across Active Directory, Entra ID and AzureImplement and enhance SSO, Conditional Access, MFA and passwordless authentication capabilitiesDrive identity governance initiatives including RBAC, PIM, access reviews and entitlement managementLead device modernisation projects using Microsoft Intune and Windows AutopilotReduce dependency on legacy Active Directory services through structured migration and transformation programmesCollaborate with Security teams to strengthen identity security and Zero Trust controlsCreate architecture documentation, technical standards and executive-level presentationsSupport the retirement of legacy authentication methods and infrastructure servicesAutomate IAM and infrastructure processes using PowerShell, Microsoft Graph API and Azure toolingProvide technical leadership across identity-related projects and mentor colleagues where required
Required Experience
5+ years' experience in Identity & Access Management, Infrastructure Engineering or Hybrid Cloud environmentsStrong expertise across Microsoft Entra ID, Active Directory and AzureExperience delivering hybrid-to-cloud identity transformation programmesHands-on experience with Azure AD Connect, identity synchronisation and directory servicesStrong knowledge of Microsoft Intune, Endpoint Management and Group Policy migrationExperience implementing Conditional Access, Identity Governance, PIM, MFA and SSO solutionsDeep understanding of authentication and identity protocols including LDAP, Kerberos, NTLM, SAML, OAuth2 and OIDCExperience adopting Zero Trust principles and improving enterprise identity security postureStrong scripting and automation experience using PowerShell, Azure CLI and Microsoft Graph APIAbility to develop technical documentation, architecture designs and communicate effectively with technical and business stakeholders
Key Technologies
Microsoft Entra IDMicrosoft Active DirectoryAzure AD ConnectMicrosoft IntuneMicrosoft AzureConditional AccessSSO & MFAIdentity GovernancePrivileged Identity Management (PIM)PowerShellMicrosoft Graph APIZero Trust Security
Nice to Have
Microsoft certifications such as SC-300, SC-100, AZ-104 or Enterprise Administrator ExpertExperience with Microsoft Defender for Identity, Sentinel or PurviewKnowledge of CIS, NIST, PCI DSS, ISO 27001 or similar security frameworksExperience retiring legacy identity and infrastructure services including ADCS, RADIUS or LDAP-based applicationsExposure to Terraform, GitHub, Azure DevOps and Infrastructure AutomationFamiliarity with SailPoint, Saviynt or other Identity Governance solutionsExperience working within Agile delivery environments
This role is ideal for someone who has successfully managed both Active Directory and Entra ID environments and understands the practical realities of transitioning from legacy infrastructure to a modern cloud-first identity platform.
We're looking for a self-sufficient engineer who can take ownership of the IAM roadmap, communicate confidently with senior stakeholders, and deliver meaningful transformation while remaining hands-on with technology.
If you're an IAM specialist who thrives on identity transformation, security modernisation and building the future of enterprise access management, we'd love to hear from you.