IAM ENGINEER

Sanderson

Greater London

Hybrid

GBP 85,000 - 105,000

Full time

26 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sanderson is seeking a Senior IAM Engineer to own the identity strategy and lead a cloud-first transformation from Active Directory to Entra ID across a hybrid environment in London. You will govern identity across AD, Entra ID, and Azure, implementing SSO, MFA, and passwordless authentication while shaping security at scale.

You will collaborate with Cyber Security, Infrastructure, and Application teams, guiding governance, architecture documentation, and executive-level presentations to drive

Qualifications

  • 5+ years' experience in Identity & Access Management, Infrastructure Engineering or Hybrid Cloud environments.
  • Experience across Microsoft Entra ID, Active Directory and Azure.
  • Experience delivering hybrid-to-cloud identity transformation programmes.
  • Hands-on experience with Azure AD Connect, identity synchronisation and directory services.
  • Strong knowledge of Microsoft Intune, Endpoint Management and Group Policy migration.
  • Experience implementing Conditional Access, Identity Governance, PIM, MFA and SSO solutions.
  • Deep understanding of authentication and identity protocols including LDAP, Kerberos, NTLM, SAML, OAuth2 and OIDC.

Responsibilities

  • Own and deliver the organisation's IAM strategy and roadmap.
  • Lead the transition from traditional Active Directory services towards a cloud-first Entra ID architecture.
  • Design and manage hybrid identity solutions across Active Directory, Entra ID and Azure.
  • Implement and enhance SSO, Conditional Access, MFA and passwordless authentication capabilities.
  • Drive identity governance initiatives including RBAC, PIM, access reviews and entitlement management.
  • Lead device modernisation projects using Microsoft Intune and Windows Autopilot.
  • Reduce dependency on legacy Active Directory services through structured migration and transformation programmes.
  • Collaborate with Security teams to strengthen identity security and Zero Trust controls.
  • Create architecture documentation, technical standards and executive-level presentations.
  • Support the retirement of legacy authentication methods and infrastructure services.
  • Automate IAM and infrastructure processes using PowerShell, Microsoft Graph API and Azure tooling.
  • Provide technical leadership across identity-related projects and mentor colleagues where required.

Skills

IAM
Hybrid Cloud
PowerShell
Azure
Entra ID
Azure AD Connect
Scripting
Identity Governance
Zero Trust

Tools

Microsoft Graph API
Intune
Windows Autopilot
Azure CLI

Job description

Location: London, United Kingdom (Hybrid)

Employment Type: Full-time

Are you an experienced Identity & Access Management Engineer with a passion for modernising enterprise identity platforms and delivering cloud-first security solutions? We're looking for a hands-on Senior IAM Engineer to take ownership of our identity strategy and lead the transformation from a traditional Active Directory environment to a modern Microsoft Entra ID-centric architecture.

This is a unique opportunity to play a pivotal role in shaping the future of identity and access management across a growing retail organisation. You'll work closely with Cyber Security, Infrastructure, Network and Application teams to deliver a secure, scalable and compliant identity platform while acting as the subject matter expert for IAM technologies, governance and modern authentication.

What You'll Do
  • Own and deliver the organisation's IAM strategy and roadmap
  • Lead the transition from traditional Active Directory services towards a cloud-first Entra ID architecture
  • Design and manage hybrid identity solutions across Active Directory, Entra ID and Azure
  • Implement and enhance SSO, Conditional Access, MFA and passwordless authentication capabilities
  • Drive identity governance initiatives including RBAC, PIM, access reviews and entitlement management
  • Lead device modernisation projects using Microsoft Intune and Windows Autopilot
  • Reduce dependency on legacy Active Directory services through structured migration and transformation programmes
  • Collaborate with Security teams to strengthen identity security and Zero Trust controls
  • Create architecture documentation, technical standards and executive-level presentations
  • Support the retirement of legacy authentication methods and infrastructure services
  • Automate IAM and infrastructure processes using PowerShell, Microsoft Graph API and Azure tooling
  • Provide technical leadership across identity-related projects and mentor colleagues where required
Required Experience
  • 5+ years' experience in Identity & Access Management, Infrastructure Engineering or Hybrid Cloud environments
  • Strong expertise across Microsoft Entra ID, Active Directory and Azure
  • Experience delivering hybrid-to-cloud identity transformation programmes
  • Hands-on experience with Azure AD Connect, identity synchronisation and directory services
  • Strong knowledge of Microsoft Intune, Endpoint Management and Group Policy migration
  • Experience implementing Conditional Access, Identity Governance, PIM, MFA and SSO solutions
  • Deep understanding of authentication and identity protocols including LDAP, Kerberos, NTLM, SAML, OAuth2 and OIDC
  • Experience adopting Zero Trust principles and improving enterprise identity security posture
  • Strong scripting and automation experience using PowerShell, Azure CLI and Microsoft Graph API
  • Ability to develop technical documentation, architecture designs and communicate effectively with technical and business stakeholders
Key Technologies
  • Microsoft Active Directory
  • Conditional Access
  • SSO & MFA
  • Identity Governance
  • Privileged Identity Management (PIM)
  • PowerShell
  • Microsoft Graph API
  • Zero Trust Security
Nice to Have
  • Microsoft certifications such as SC-300, SC-100, AZ-104 or Enterprise Administrator Expert
  • Experience with Microsoft Defender for Identity, Sentinel or Purview
  • Knowledge of CIS, NIST, PCI DSS, ISO 27001 or similar security frameworks
  • Experience retiring legacy identity and infrastructure services including ADCS, RADIUS or LDAP-based applications
  • Exposure to Terraform, GitHub, Azure DevOps and Infrastructure Automation
  • Familiarity with SailPoint, Saviynt or other Identity Governance solutions
  • Experience working within Agile delivery environments

This role is ideal for someone who has successfully managed both Active Directory and Entra ID environments and understands the practical realities of transitioning from legacy infrastructure to a modern cloud-first identity platform. We're looking for a self-sufficient engineer who can take ownership of the IAM roadmap, communicate confidently with senior stakeholders, and deliver meaningful transformation while remaining hands-on with technology.

If you're an IAM specialist who thrives on identity transformation, security modernisation and building the future of enterprise access management, we'd love to hear from you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity & Access Management Architect
Identity & Access Management Architect

Edison Smart® • Basingstoke

Hybrid
GBP 80,000 - 110,000
Microsoft IAM Consultant / Associate Manager
Microsoft IAM Consultant / Associate Manager

3004 Avanade UK Limited Company • City Of London

On-site
GBP 55,000 - 75,000
Identity & Privileged Access Management Engineering Director / Leader - London/ Financial Services
Identity & Privileged Access Management Engineering Director / Leader - London/ Financial Services

Entasis Partners • Greater London

On-site
GBP 140,000 - 180,000
Performance bonus
Comprehensive benefits
Identity Management Consultant
Identity Management Consultant

TechNET IT Recruitment Ltd • Cheltenham

On-site
GBP 70,000 - 100,000
Identity Access Management Architect Engineer Cyber Consulting
Identity Access Management Architect Engineer Cyber Consulting

Oliver James Associates Ltd. • Greater London

Hybrid
GBP 80,000 - 120,000
Flexible benefits packages
Car allowances
Bonuses
+1
Identity & Access Management Engineer (IAM Engineer)
Identity & Access Management Engineer (IAM Engineer)

Edison Smart® • Basingstoke

Hybrid
GBP 42,000 - 70,000
Hybrid work (3 days on-site)
IAM Engineer
IAM Engineer

SR2 | Socially Responsible Recruitment | Certified B Corporation™ • Greater London

On-site
GBP 65,000 - 90,000
IAM Engineer
IAM Engineer

Insight Global • Dacorum

On-site
GBP 60,000 - 80,000
IAM Engineer
IAM Engineer

Edison Smart • Basingstoke

Hybrid
GBP 63,000 - 77,000
IAM Security Architect
IAM Security Architect

undisclosed • Greater London, Brighton, Staines-upon-Thames

Hybrid
GBP 69,000 - 115,000