Identity & Infrastructure Engineer (Security-Aware)

Space NK Limited

Greater London

On-site

GBP 70,000 - 95,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Space NK Limited is seeking an Identity & Infrastructure Engineer in London. You will support, maintain, and modernise identity and infrastructure services in a hybrid Microsoft environment.

You will administer Entra ID, Active Directory, Windows infrastructure, Intune and Azure services, strengthening identity security and enabling a cloud‑native operating model.

Qualifications

  • Hands-on Admin of Active Directory and domain services.
  • Experience with MFA, SSO, Conditional Access and identity controls.
  • Strong foundation in Microsoft identity and infrastructure technologies.

Responsibilities

  • Administer Entra ID, AD DS in a hybrid environment.
  • Implement and troubleshoot SSO, MFA, Conditional Access, passwordless auth.
  • Support RBAC, PIM, least-privilege access controls.
  • Manage Entra Connect, Azure AD Connect and Cloud Sync.
  • Onboard applications to Entra ID using SAML/OAuth/OpenID Connect.
  • Collaborate with Security and Cloud teams on identity security.

Skills

Microsoft Entra ID
Active Directory
PowerShell
Azure
Intune
Security & Zero Trust
Identity governance

Education

Bachelor's degree in CS/IT or related

Tools

Microsoft Graph API
Azure Monitor

Job description

If you love beauty, you’re in the right place.

As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go‑to destination for worldwide beauty discovery.

Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands.

Identity & Infrastructure Engineer | Space NK, London
  • Job title: Identity & Infrastructure Engineer
  • Reporting to: Platform Engineering Principal
  • Location: London/hybrid
  • Department: Technology
Role Overview

The Identity & Infrastructure Engineer will support, maintain and modernise Space NK’s identity and infrastructure services across a hybrid Microsoft environment.

This hands‑on engineering role is responsible for the administration and continuous improvement of Microsoft Entra ID, Active Directory, Windows infrastructure, Intune and Azure services. The role will help strengthen identity security, improve operational reliability and support Space NK’s transition towards a cloud-native, Entra ID-centric operating model.

Working closely with Security, Cloud, Infrastructure and Application teams, the engineer will implement secure identity controls, resolve technical issues and deliver defined areas of project and transformation work. The role will apply automation, robust governance and secure‑by‑default principles across identity, infrastructure and endpoint management.

The successful candidate will have strong foundations in Microsoft identity and infrastructure technologies, together with the capability and ambition to develop deeper expertise in cloud identity, security, automation and modern endpoint management.

Key Responsibilities
Identity and Access Management
  • Administer and support Microsoft Entra ID and Active Directory Domain Services within the hybrid identity environment.
  • Implement, maintain and troubleshoot SSO, MFA, Conditional Access and passwordless authentication.
  • Support RBAC, Privileged Identity Management and least‑privilege access controls.
  • Support identity lifecycle activities, including joiner, mover and leaver processes and access reviews.
  • Administer and troubleshoot Entra Connect, Azure AD Connect and Cloud Sync.
  • Support application onboarding to Entra ID using SAML, OAuth 2.0 and OpenID Connect.
  • Investigate authentication, authorisation and account‑related issues across cloud and on‑premises environments.
Active Directory and Infrastructure
  • Administer and support Active Directory, including users, groups, computers, organisational units, Group Policy and domain services.
  • Monitor and troubleshoot domain controllers, replication, DNS, DHCP, authentication and Windows Server infrastructure.
  • Support Active Directory Certificate Services and certificate lifecycle activities where required.
  • Maintain and troubleshoot Group Policy while supporting the migration of appropriate configurations to modern cloud management.
  • Support the secure management of service accounts and non‑human identities.
  • Maintain technical documentation, configuration records and operational procedures.
Entra ID, Intune and Modern Device Management
  • Support Windows device management through Microsoft Intune.
  • Assist with the migration from domain and hybrid joined devices to Microsoft Entra Join.
  • Support Windows Autopilot, device provisioning and lifecycle management.
  • Implement and maintain Intune configuration profiles, compliance policies and security baselines under agreed standards.
  • Assist with the migration of appropriate legacy Group Policy settings to Intune.
  • Troubleshoot device enrolment, compliance, authentication and registration issues.
Security, Governance and Compliance
  • Apply Zero Trust, least‑privilege and secure‑by‑default principles to identity and infrastructure engineering.
  • Work with Cyber Security to implement agreed identity security controls and investigate identity‑related alerts.
  • Support access reviews, privileged access reviews and entitlement governance.
  • Assist with audit evidence and remediation activities relating to SOX, PCI DSS, GDPR and other applicable requirements.
  • Support incident response by providing identity information, access logs and technical assistance with containment activities.
  • Contribute to reducing legacy authentication and unnecessary privileged access.
Monitoring, Automation and Continuous Improvement
  • Monitor identity and infrastructure services using Azure Monitor, Log Analytics, Entra logs and Microsoft Defender.
  • Troubleshoot authentication, synchronisation and infrastructure issues, escalating complex problems where appropriate.
  • Automate repeatable administration activities using PowerShell, Microsoft Graph API, Azure CLI and related services.
  • Identify opportunities to improve reliability, security and operational efficiency through automation and process improvement.
  • Contribute to projects supporting Space NK’s wider identity and infrastructure modernisation programme.
Qualifications, Knowledge and Experience
Experience
  • Hands‑on experience administering Microsoft Active Directory and supporting Active Directory Domain Services.
  • Practical experience with Microsoft Entra ID, including users, groups, roles and enterprise applications.
  • Experience supporting MFA, Conditional Access, SSO and identity access controls.
  • Experience with Windows Server, Group Policy and core Microsoft infrastructure services.
  • Experience with Microsoft Intune or another modern endpoint management platform.
  • Practical experience using PowerShell to support administration and automation.
  • Good troubleshooting and problem‑solving skills across hybrid Microsoft environments.
  • A sound understanding of information security, change control and operational support practices.

Candidates are not expected to be experts in every technology listed. Strong technical foundations, sound judgement and a clear commitment to developing expertise in modern Microsoft identity and cloud technologies are essential.

Technical Skills

Experience in the following areas would be advantageous:

  • Entra PIM and Entra ID Governance, including Access Reviews.
  • Windows Autopilot, Entra Join and Hybrid Entra Join.
  • Entra Connect, Azure AD Connect or Cloud Sync.
  • Active Directory Certificate Services and PKI.
  • Microsoft Defender for Identity or Microsoft Sentinel.
  • Azure Monitor and Log Analytics.
  • Microsoft Graph API or Azure automation.
  • Passwordless authentication, FIDO2 and passkeys.
  • Application SSO integration.
  • SOX, PCI DSS, GDPR or ISO 27001 environments.
  • General Microsoft Azure administration.
Qualifications and Certifications

A degree in Computer Science, Cyber Security, Infrastructure Engineering or a related discipline is advantageous, although equivalent practical experience will also be considered.

Relevant professional experience in identity, infrastructure, Microsoft 365, Azure or a related engineering role is expected; technical capability, delivery experience and potential are more important than a specific number of years.

Relevant certifications are desirable but not mandatory, including:

  • Microsoft Identity and Access Administrator Associate (SC‑300).
  • Microsoft Endpoint Administrator Associate (MD‑102).
  • Microsoft Azure Administrator Associate (AZ‑104).
  • Microsoft Security, Compliance and Identity Fundamentals (SC‑900).
  • Microsoft Azure Fundamentals (AZ‑900).
  • CompTIA Security+ or equivalent.

Candidates actively working towards relevant certifications are also encouraged to apply.

Skills and Attributes
  • Strong interest in identity, Microsoft cloud technologies and security.
  • Ability to take ownership of assigned technical work while recognising when escalation or guidance is required.
  • Logical and methodical approach to troubleshooting.
  • Clear written and verbal communication skills.
  • Ability to collaborate effectively across Platform Engineering, Cyber Security, Cloud, Infrastructure and Application teams.
  • Commitment to continuous learning and sharing technical knowledge.
  • Good understanding of change control, documentation and production support.
  • Ability to balance operational support with project and transformation activities.
  • Proactive approach to automation and continuous improvement.
Development and Progression

This role provides the opportunity to develop deeper capability across Entra ID, Identity Governance, PIM, Conditional Access, Intune, modern authentication, automation and Zero Trust.

As technical capability and experience grow, the engineer will take increasing responsibility for complex changes, technical solutions and project delivery, providing a natural development path towards a Senior Identity & Infrastructure Engineer role.

Please note that only successful candidates will be contacted.

All applicants must have the right to live and work in the UK.

If you want to find out more about us, what it is like to work for us, all about our benefits, and our pledges on Diversity, Inclusion and Belonging, please visit our website.

Space NK are an equal opportunities employer.

How We Will Use Your Information

We will use the information you provide to us with your job application to help us process your application for the specific job you have applied for. If you apply speculatively, we will process your application for the job/relevant business area that you detail within your email.

Please note that our current system does not use an automated filtering system.

All applications made via the website, through a third‑party website or in‑store will be kept on file for a period of 12 months.

This information will be retained and used to assess your suitability to similar positions that may arise in the future, or if the initial vacancy becomes live again during the 12‑month period. If you would prefer us to not hold your information on file/ you wish to be ‘forgotten’ if you are not offered a position with Space NK, please email your ‘right to be forgotten’ to our recruitment email address with RIGHT TO BE FORGOTTEN as the title of the email. We will always inform you when we have deleted your application details, otherwise we will treat your application as consent to us holding this information.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Infrastructure Engineer
Identity & Infrastructure Engineer

Space NK Limited • Greater London

Hybrid
GBP 70,000 - 90,000
Security Engineer – Cloud & On-Prem (Hybrid Security)
Security Engineer – Cloud & On-Prem (Hybrid Security)

Space NK Limited • Greater London

On-site
GBP 65,000 - 90,000
Beauty Advisor Leeds (8 hours)
Beauty Advisor Leeds (8 hours)

Space NK • Leeds

On-site
GBP 21,000 - 26,000
Competitive salary
25 days annual leave
Employee discount 50%
+2
Security Engineer
Security Engineer

Space NK Limited • City of Westminster

Hybrid
GBP 60,000 - 95,000
Beauty Advisor (12 hours)
Beauty Advisor (12 hours)

Space NK • Liverpool

On-site
GBP 19,000 - 23,000
Competitive salary
Generous time off up to 25 days
Employee discount up to 50%
+4
Beauty Advisor (22.5 Hours)
Beauty Advisor (22.5 Hours)

SPACE NK • Greenhithe

On-site
GBP 18,000 - 24,000
Competitive salary
25 days annual leave
Employee discount up to 50%
+4
Beauty Advisor FTC (15 hours)
Beauty Advisor FTC (15 hours)

Space NK Limited • Milton Keynes

On-site
GBP 22,000 - 26,000
Competitive salary
Generous annual leave
Staff discount up to 50%
+4
Beauty Advisor (15 hours)
Beauty Advisor (15 hours)

Space NK Limited • Greater London

On-site
GBP 21,000 - 28,000
Competitive salary
25 days annual leave
Employee discount 50%
+2
Warehouse Operations Manager (FTC)
Warehouse Operations Manager (FTC)

Space NK Limited • Greater London

Remote
GBP 40,000 - 60,000
Beauty Advisor (7.5 Hours)
Beauty Advisor (7.5 Hours)

SPACE NK • Greenhithe

On-site
GBP 19,000 - 23,000
Competitive salary
25 days annual leave
Employee discount up to 50%
+4