Principal Engineer, Workforce, Customer & Agentic Identity

Jobtailor

Belfast City District

On-site

GBP 120,000 - 150,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Allstate is seeking a Senior IAM Architect to define and drive enterprise identity strategy across customer and workforce identities, authentication, federation, and governance. You will collaborate with engineering, architecture, product, and security teams to design secure, scalable identity solutions and mentor engineering staff.

The role focuses on leading Zero Trust initiatives, MFA, risk-based authentication, and least-privilege access controls, while shaping governance for machine

Qualifications

  • 5+ years designing and implementing enterprise Identity and Access Management (IAM) solutions.
  • 5+ years of experience managing engineering teams.
  • Working knowledge of IAM platforms, including Ping Identity or SailPoint.
  • Strong knowledge of customer and workforce identity, federation, SSO, MFA, identity governance, and access certification.

Responsibilities

  • Define and drive technical strategy and architecture for IAM platforms across the enterprise.
  • Improve authentication experiences while maintaining security, governance, and compliance.
  • Partner with engineering, architecture, product, and security teams to design, implement, and modernize identity solutions.
  • Provide technical leadership for authentication, authorization, federation, governance, lifecycle management, privileged access, and access certification.
  • Drive Zero Trust initiatives through MFA, risk-based authentication, fine-grained authorization, and least-privilege controls.
  • Collaborate with digital product teams to create secure, scalable customer identity experiences.
  • Mentor engineering teams and establish engineering standards, architectures, and best practices.

Skills

IAM Architecture
Zero Trust
Leadership
Stakeholder Management
Influence Senior Leaders
Cloud Identity
Security Governance

Education

Bachelor's degree in CS/Cybersecurity/IT/Engineering
CISSP
CCSP

Tools

Ping Identity
SailPoint

Job description

  • Define and drive technical strategy and architecture for workforce, customer, machine, and agentic identity platforms across the enterprise
  • Improve customer authentication experiences while maintaining security, governance, and compliance standards
  • Partner with engineering, architecture, product, and security teams to design, implement, and modernize identity solutions
  • Provide technical leadership for authentication, authorization, federation, identity governance, lifecycle management, privileged access management, and access certification
  • Evaluate, design, and adopt identity platforms and technologies including Ping Identity and SailPoint
  • Drive Zero Trust initiatives through MFA, risk-based authentication, fine-grained authorization, identity governance, and least-privilege controls
  • Define governance models and lifecycle processes for machine identities, service accounts, workload identities, and AI agents
  • Establish controls for autonomous and agentic systems, including delegated authority, ownership, governance, and privileged access management
  • Drive enterprise adoption of identity modernization initiatives and communicate business value, customer impact, and security outcomes
  • Collaborate with digital product teams to create secure, scalable customer identity experiences
  • Participate in architecture, troubleshooting, integration design, and implementation while mentoring engineering teams
  • Establish engineering standards, reference architectures, and best practices for Allstate's identity roadmap and Zero Trust strategy
Requirements
  • Legal right to work in the UK; Allstate is not providing sponsorship
  • 5+ years of experience designing and implementing enterprise Identity and Access Management (IAM) solutions
  • 5+ years of experience managing engineering teams
  • Working knowledge of Ping Identity, SailPoint, or similar IAM platforms
  • Strong knowledge of customer and workforce identity, federation, SSO, MFA, privileged access management, identity governance, and access certification
  • Experience designing and implementing Zero Trust identity architectures, including conditional access, risk-based authentication, fine-grained authorization, and least-privilege access controls
  • Experience supporting machine identities, workload identities, service accounts, certificates, secrets management, and cloud-native identity models
  • Familiarity with emerging AI and agentic identity concepts, governance models, and authorization frameworks
  • Ability to influence senior leaders, drive enterprise adoption, and communicate complex technical strategies across diverse stakeholder groups
  • Ability to influence enterprise strategy and drive adoption of identity modernization initiatives
  • Strong change leadership and stakeholder management skills
  • Technical leadership experience guiding architectures, engineering standards, and best practices
  • Customer-centric mindset balancing security, usability, and business outcomes
  • Ability to lead through influence, navigate ambiguity, and drive enterprise-wide change without direct authority
  • Experience influencing vendor roadmaps and product strategies
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related technical field is desirable
  • Relevant IAM or security certifications such as CISSP, CCSP, SailPoint, Ping Identity, Microsoft Security, or equivalent are desirable
  • Supervisory duties are included
Core Competencies

Demonstrates expertise in designing and implementing enterprise Identity and Access Management (IAM) solutions, with a strong focus on Zero Trust architectures and customer-centric identity experiences. Proven ability to lead engineering teams, influence enterprise strategy, and drive adoption of identity modernization initiatives while ensuring compliance and security.

Highest-signal resume keywords
  • Identity And Access Management (IAM)
  • Zero Trust Architecture
  • Ping Identity
  • SailPoint
  • Privileged Access Management
ATS Optimization Keywords
Hard Skills
  • Identity Governance
  • Federation
  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • Risk-Based Authentication
  • Fine-Grained Authorization
  • Lifecycle Management
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer, Workforce, Customer & Agentic Identity -Hybrid
Principal Engineer, Workforce, Customer & Agentic Identity -Hybrid

Allstate Insurance Company • Belfast City District

On-site
GBP 90,000 - 120,000
Corporate bonus scheme
Pension scheme
Hybrid working
+2
Security Architect - IAM
Security Architect - IAM

Integrity360 • Greater London

On-site
GBP 90,000 - 140,000
Senior IAM Architect: Zero-Trust Identity Strategy Lead
Senior IAM Architect: Zero-Trust Identity Strategy Lead

Integrity360 • Greater London

On-site
GBP 90,000 - 140,000
Lead IAM Technical Architect
Lead IAM Technical Architect

eTeam Workforce Limited • Swindon

Remote
GBP 85,000 - 120,000
Identity and Access Senior Manager
Identity and Access Senior Manager

A&O Shearman • Belfast City District

On-site
GBP 70,000 - 110,000
Corporate IT Engineer
Corporate IT Engineer

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Technical Lead NextGen
Technical Lead NextGen

TESTQ Technologies LTD. • Sheffield

On-site
GBP 85,000 - 120,000
Senior IAM Engineer
Senior IAM Engineer

Selby Jennings • City Of London

On-site
GBP 80,000 - 120,000
Identity Access Management Architect Engineer Cyber Consulting
Identity Access Management Architect Engineer Cyber Consulting

Oliver James Associates Ltd. • Greater London

Hybrid
GBP 80,000 - 120,000
Flexible benefits packages
Car allowances
Bonuses
+1
Lead IAM Technical Architect
Lead IAM Technical Architect

Gold Group • Swindon

Remote
GBP 90,000 - 130,000