Senior Microsoft Identity Security Specialist

Willis Towers Watson

Greater London

On-site

GBP 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Private healthcare
Pension scheme
Volunteer day
Share scheme

Job summary

Willis Towers Watson is seeking a Senior Microsoft Identity Security Specialist to strengthen our identity security posture in a hybrid London-based role. You will design, implement and optimise Microsoft Entra ID across enterprise environments, focusing on Conditional Access, Identity Protection, PIM and passwordless authentication.

The role blends hands-on engineering with design, automation and AI-assisted analysis to improve identity operations and security monitoring.

Qualifications

  • Hands-on experience in IAM, including Microsoft Entra ID administration and security in complex enterprises.
  • Experience implementing Conditional Access, Identity Protection, PIM and Identity Governance.
  • Experience deploying passwordless and phishing-resistant authentication.
  • Strong grasp of OAuth 2.0, OpenID Connect and SAML modern auth protocols.
  • Proficiency in scripting and automation; familiarity with CI/CD pipelines such as Azure DevOps or GitHub.

Responsibilities

  • Design, implement and optimise Microsoft Entra ID as the strategic identity platform.
  • Configure and enhance Conditional Access, Identity Protection, PIM, and Just‑in‑Time access controls.
  • Support identity governance including access reviews and role-based access models.
  • Implement phishing-resistant authentication and Zero Trust controls across SaaS, cloud and on‑prem apps.
  • Develop reusable pipelines and automation for identity operations; enable self‑service patterns.

Skills

Identity & Access Management
Microsoft Entra ID administration
Conditional Access
Identity Governance
Phishing-resistant authentication
Zero Trust
Scripting & automation
Azure DevOps or GitHub

Tools

Azure DevOps
GitHub
PowerShell
Microsoft Defender
Microsoft Sentinel
Log Analytics

Job description

The Senior Microsoft Identity Security Specialist will play a key role within the Global Information and Cyber Defence and Identity function, supporting the organisation's Microsoft-first identity security strategy through the design, implementation and optimisation of Microsoft Entra ID and related platforms.

The role will strengthen the organisation's identity security posture through Conditional Access, Identity Protection, Privileged Identity Management, password less authentication and Zero Trust-aligned controls.The role combines hands-on engineering with technical design, automation and continuous improvement, including the appropriate use of AI-assisted analysis to improve identity operations and security monitoring. This position follows a hybrid working model and is based in the London office. The successful candidate will be expected to attend the office when required to meet business and team requirements.

The Role:


Identity Platform Engineering

  • Contribute to the design, implementation, and optimisation of Microsoft Entra ID as the organisation's strategic identity platform.
  • Configure and enhance Conditional Access, Identity Protection, PIM and Just-in-Time access controls.
  • Support identity governance capabilities, including access reviews, entitlement management, Joiner-Mover-Leaver processes and role-based access control models.
  • Support workforce identities, external identities, application identities, managed identities and service principals.
  • Troubleshoot complex authentication, authorisation, federation and provisioning issues.

Authentication and Access Security

  • Support the adoption of phishing-resistant authentication, including FIDO2/passkeys, Windows Hello for Business, certificate-based authentication and hardware-backed credentials.
  • Implement and support Zero Trust identity controls across SaaS, cloud and enterprise applications.
  • Support secure application integration using OAuth 2.0, OpenID Connect and SAML.

Automation and Platform Enablement

  • Develop reusable pipelines, scripts and workflow automation for repeatable identity operations.
  • Create approved self-service patterns for activities such as application registration and enterprise application onboarding, using validation, approvals and audit logging to reduce direct administrative access.
  • Integrate identity standards and secure defaults into application-modernisation, CI/CD and infrastructure-as-code processes.
  • Automate routine activities such as configuration validation, certificate and secret-expiry monitoring, evidence collection and operational reporting.

AI-Assisted Operations and Security Monitoring

  • Identify and support practical uses of approved AI capabilities to improve the efficiency and quality of identity engineering and operations.
  • Use AI-assisted analysis and automation to help identify Conditional Access gaps, configuration drift, anomalous sign-ins, risky privilege activity, stale identities and excessive permissions.
  • Support identity-focused monitoring and signal correlation using Entra ID, Microsoft Defender, Log Analytics and Microsoft Sentinel.
  • Help define and apply approved identity controls to AI agents and agent identities, including ownership, least privilege, credential management, monitoring and lifecycle governance.
  • Ensure high-impact access, policy and remediation decisions retain appropriate human review and approval.

Threat Detection and Continuous Improvement

  • Support detection and remediation of identity threats including credential compromise, privilege escalation, token theft and suspicious authentication activity.
  • Collaborate with security operations teams to improve identity threat visibility, triage and response.
  • Contribute to technical designs, standards, documentation, operational procedures and control-effectiveness reporting.
  • Provide technical guidance and subject matter expertise relating to Microsoft identity technologies.
Qualifications

What you'll bring:

Required Skills and Experience:

  • Demonstrable recent, hands-on experience in Identity and Access Management, including substantial expertise in Microsoft Entra ID administration and security within complex enterprise environments.
  • Experience implementing and supporting Conditional Access, Identity Protection, PIM and Identity Governance.
  • Experience deploying and supporting passwordless and phishing-resistant authentication.
  • Strong understanding of OAuth 2.0, OpenID Connect, SAML and modern authentication protocols.
  • Experience with scripting and automation and familiarity with source control and deployment pipelines such as Azure DevOps or GitHub.
  • Understanding of Zero Trust, least privilege and identity-centric security controls.
  • Experience troubleshooting authentication and access issues in enterprise environments.
  • Ability to translate architecture and security standards into practical engineering solutions.
  • Strong communication, documentation and stakeholder-engagement skills.

Desirable Experience:

  • Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security.
  • Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced workflow automation.
  • Experience using AI/ML or Agentic AI within security or identity operations.
  • Application registration, managed identity, service principal, workload identity, and secrets or certificate lifecycle governance.
  • Active Directory security, Entra Connect or Cloud Sync, and hybrid identity monitoring.
  • SailPoint identity governance or CyberArk privileged access and credential management.
  • AWS, Google Cloud Platform or Oracle Cloud Infrastructure identity and access management.
  • Relevant Microsoft Security, cloud or industry certifications such as CISSP or CCSP.

What We Offer

  • Enjoy a benefits package designed to help you thrive, both professionally and personally.
  • You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge.
  • Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind.
  • Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.
  • We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community.
  • On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more.
  • Start making the most of your career and wellbeing with a range of benefits tailored for you.

Equal Opportunity Employer

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Microsoft Identity Security Specialist
Senior Microsoft Identity Security Specialist

WTW • Greater London

Hybrid
GBP 90,000 - 130,000
Private healthcare
Pension scheme
Hybrid work options
+3
Senior Microsoft Security Engineer (XDR, IRM, Deception Engineering)
Senior Microsoft Security Engineer (XDR, IRM, Deception Engineering)

Willis Towers Watson • Greater London

Hybrid
GBP 120,000 - 180,000
Hybrid work
Private healthcare
Life insurance
+3
Principal Microsoft Defender XDR, IRM & Deception Engineer in London
Principal Microsoft Defender XDR, IRM & Deception Engineer in London

Energy Jobline ZR • Greater London

Hybrid
GBP 140,000 - 180,000
25 days annual leave
Private health care
Pension scheme
Senior Identity Security Engineer: Entra ID & Zero Trust
Senior Identity Security Engineer: Entra ID & Zero Trust

WTW • Greater London

Hybrid
GBP 90,000 - 130,000
Private healthcare
Pension scheme
Hybrid work options
+3
Digital Identity Senior Manager
Digital Identity Senior Manager

PwC UK • West of England

Hybrid
GBP 110,000 - 180,000
Digital Identity Senior Manager
Digital Identity Senior Manager

PwC UK • Greater London

Hybrid
GBP 140,000 - 180,000
Flexible working
Private medical cover
Volunteer/CSR days
Senior Microsoft Cloud Platform Engineer
Senior Microsoft Cloud Platform Engineer

Wellington Management • Greater London

Hybrid
GBP 120,000 - 170,000
Hybrid work model
Office in London
Associate Manager - Cyber Security Incident Response
Associate Manager - Cyber Security Incident Response

WTW • Greater London

Hybrid
GBP 70,000 - 100,000
Hybrid working
Private healthcare
Life insurance
+4
Senior Associate – Information Security
Senior Associate – Information Security

Willis Towers Watson • Ipswich

Hybrid
GBP 55,000 - 75,000
25 days annual leave
Private healthcare
Life insurance
+3
Senior Cloud Security Architect
Senior Cloud Security Architect

ITC Secure • Greater London

Hybrid
GBP 120,000 - 180,000
25 days annual leave
Pension scheme
Private health insurance
+2