Description
DevOps Engineer – Identity & Access Management (IAM)
The Opportunity
**Position Type:** Inside IR35 Contract
**Location:** South Yorkshire (Hybrid)
**Duration:** Multi-year transformation program engagement
We're seeking an experienced **DevOps Engineer with GCP expertise** to help design and operate enterprise Identity & Access Management (IAM) capabilities at scale.
This is a key position in a multi-year transformation program modernizing how IAM is delivered across a global financial services organization.
You'll work at the intersection of infrastructure, security, and identity platforms—building CI/CD pipelines, infrastructure-as-code, and cloud-native IAM services that serve thousands of users and systems.
What You'll Do
Platform & Infrastructure
Design, build, and maintain CI/CD pipelines for IAM components, policies, connectors, and microservicesDevelop and maintain Infrastructure-as-Code (Terraform) for deploying IAM infrastructure, identity policies, directories, and supporting platforms on GCPEnsure consistent, repeatable environments aligned with architectural standardsDeploy IAM services on Kubernetes (GKE), cloud-native platforms, and serverless environmentsManage containerization, certificates, secrets, and service mesh integrations for IAM workloads
Automation & Operations
Develop scripts and automation for account lifecycle operations, access provisioning, and system integrationsEnable automated testing, security scanning, and controlled deployments across DEV/TEST/PROD environmentsImplement continuous improvement to streamline IAM release processes and operational efficiencySupport regional deployments, failover strategies, data residency requirements, and compliance across multiple jurisdictionsManage data pipelines for identity events (Kafka, Pub/Sub) and streaming infrastructure monitoring
Graph & Data Architecture
Deploy and manage graph platform infrastructure (Neo4j) for identity relationship mapping and access analyticsImplement graph database backups, recovery, disaster recovery, and observability (GDS/APOC)Integrate graph-based identity models with IAM provisioning and access decision workflows
Security & Governance
Embed security into the build and deployment process (vulnerability scanning, secrets detection, code quality checks)Collaborate with security teams to ensure compliance with Zero Trust principles and IAM security policiesImplement Privileged Access Management (PAM) controls and identity governance at scaleWork with cybersecurity and compliance teams on architecture, integration requirements, and regulatory controlsCreate and maintain documentation for pipelines, IaC, deployment patterns, and operational processes
Collaboration
Partner with IAM architects, security engineers, platform teams, and application owners on design and integrationSupport both cloud and on-premises IAM solutionsCommunicate complex architectural and operational concepts across technical and non-technical audiencesManage workload prioritization and engagement in Agile environments
What We're Looking For
Core Technical Skills (Must-Have)
**GCP Infrastructure & Provisioning:** Hands-on experience with Terraform (core), GCP infrastructure, and policy-as-code.
Ability to manage, maintain, and write infrastructure policies at scale.**Containerization & Kubernetes:** Docker, Kubernetes, Helm/Kustomize, and GKE operations.
Experience deploying and managing containerized IAM services.**CI/CD Engineering:** Pipeline authoring, artifact management, testing automation, and deployment strategies.
Experience with Cloud Build or equivalent.**DevSecOps & Platform Security:** Security scanning, secrets detection, vulnerability scanning, code quality checks, and compliance automation.**Release Engineering & Governance:** Release operations, change management, documentation, and release governance in regulated environments.
Essential Technical Skills
**Data Pipelines & Streaming:** Kafka fundamentals, schema registry, streaming infrastructure, and monitoring.
Experience with Pub/Sub or equivalent event streaming platforms.**Graph Platform Engineering:** Neo4j basics, backups, recovery, disaster recovery, GDS/APOC, and observability.**IAM & Identity Governance:** Understanding of authentication, authorization, elevated access, Privileged Access Management (PAM), and identity lifecycle management.**Network Security & Compliance:** Network security, conditional access, regional deployments, data residency, and compliance requirements across multiple jurisdictions.
Soft Skills
Strong problem-solving and troubleshooting capabilitiesAbility to work collaboratively across security, engineering, and operations teamsExcellent communication and documentation skillsSelf-motivated to learn and adapt to new technologies quicklyExperience working in Agile/Scrum environments (Jira, Jira Service Desk, kanban)Comfortable working across multiple time zones and in culturally diverse, globally distributed teamsAbility to handle the pace and complexity of large-scale enterprise environmentsExperience working at scale in global IT enterprises