Location: London, United Kingdom (Hybrid)
Employment Type: Full-time
Are you an experienced Identity & Access Management Engineer with a passion for modernising enterprise identity platforms and delivering cloud-first security solutions? We're looking for a hands-on Senior IAM Engineer to take ownership of our identity strategy and lead the transformation from a traditional Active Directory environment to a modern Microsoft Entra ID-centric architecture.
This is a unique opportunity to play a pivotal role in shaping the future of identity and access management across a growing retail organisation. You'll work closely with Cyber Security, Infrastructure, Network and Application teams to deliver a secure, scalable and compliant identity platform while acting as the subject matter expert for IAM technologies, governance and modern authentication.
What You'll Do
- Own and deliver the organisation's IAM strategy and roadmap
- Lead the transition from traditional Active Directory services towards a cloud-first Entra ID architecture
- Design and manage hybrid identity solutions across Active Directory, Entra ID and Azure
- Implement and enhance SSO, Conditional Access, MFA and passwordless authentication capabilities
- Drive identity governance initiatives including RBAC, PIM, access reviews and entitlement management
- Lead device modernisation projects using Microsoft Intune and Windows Autopilot
- Reduce dependency on legacy Active Directory services through structured migration and transformation programmes
- Collaborate with Security teams to strengthen identity security and Zero Trust controls
- Create architecture documentation, technical standards and executive-level presentations
- Support the retirement of legacy authentication methods and infrastructure services
- Automate IAM and infrastructure processes using PowerShell, Microsoft Graph API and Azure tooling
- Provide technical leadership across identity-related projects and mentor colleagues where required
Required Experience
- 5+ years' experience in Identity & Access Management, Infrastructure Engineering or Hybrid Cloud environments
- Strong expertise across Microsoft Entra ID, Active Directory and Azure
- Experience delivering hybrid-to-cloud identity transformation programmes
- Hands-on experience with Azure AD Connect, identity synchronisation and directory services
- Strong knowledge of Microsoft Intune, Endpoint Management and Group Policy migration
- Experience implementing Conditional Access, Identity Governance, PIM, MFA and SSO solutions
- Deep understanding of authentication and identity protocols including LDAP, Kerberos, NTLM, SAML, OAuth2 and OIDC
- Experience adopting Zero Trust principles and improving enterprise identity security posture
- Strong scripting and automation experience using PowerShell, Azure CLI and Microsoft Graph API
- Ability to develop technical documentation, architecture designs and communicate effectively with technical and business stakeholders
Key Technologies
- Microsoft Active Directory
- Conditional Access
- SSO & MFA
- Identity Governance
- Privileged Identity Management (PIM)
- PowerShell
- Microsoft Graph API
- Zero Trust Security
Nice to Have
- Microsoft certifications such as SC-300, SC-100, AZ-104 or Enterprise Administrator Expert
- Experience with Microsoft Defender for Identity, Sentinel or Purview
- Knowledge of CIS, NIST, PCI DSS, ISO 27001 or similar security frameworks
- Experience retiring legacy identity and infrastructure services including ADCS, RADIUS or LDAP-based applications
- Exposure to Terraform, GitHub, Azure DevOps and Infrastructure Automation
- Familiarity with SailPoint, Saviynt or other Identity Governance solutions
- Experience working within Agile delivery environments
This role is ideal for someone who has successfully managed both Active Directory and Entra ID environments and understands the practical realities of transitioning from legacy infrastructure to a modern cloud-first identity platform. We're looking for a self-sufficient engineer who can take ownership of the IAM roadmap, communicate confidently with senior stakeholders, and deliver meaningful transformation while remaining hands-on with technology.
If you're an IAM specialist who thrives on identity transformation, security modernisation and building the future of enterprise access management, we'd love to hear from you.