Identity Security Engineer

Aer Lingus

Dublin

On-site

EUR 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Aer Lingus is seeking an Identity Security Engineer to govern and continuously improve our identity security posture, including privileged access. This hands-on role covers secure‑by‑design identity architectures, lifecycle management, access controls and processes within a large enterprise environment.

You will work with Cyber, technology and applications teams to implement identity controls, automate lifecycle workflows, and monitor identity health across platforms.

Qualifications

  • 10+ years in security engineering or identity domains.
  • Hands‑on with AD and/or Entra in large enterprises.
  • Experience designing identity lifecycle and access workflows on an IGA platform.
  • Experience implementing privileged access controls and governance.
  • Experience with access governance and least privilege controls.
  • Relevant certifications (Microsoft identity/security, CISSP/CISM/CIAM/CRISC).
  • Strong IAM concepts: zero trust, RBAC, access reviews, lifecycle governance.
  • Ability to translate secure identity architectures into standards and blueprints.
  • Ability to document outcomes and implement identity standards consistently.
  • Strong analytical and troubleshooting skills for identity and access issues.
  • Excellent communication across tech, cyber and business teams.

Responsibilities

  • Own identity and privileged security policies, standards and patterns across AD/Entra/IGA.
  • Design and govern identity lifecycle workflows and access reviews using an IGA platform.
  • Support implementation of a privileged access platform and controls.
  • Automate identity governance processes and lifecycle workflows via scripts.
  • Deliver identity posture monitoring and continuous improvements of controls.
  • Provide SME support for identity-related security incidents and investigations.
  • Build identity metrics and dashboards for centralized oversight.
  • Collaborate with application/platform teams to embed secure-by-design identity patterns.
  • Maintain documentation and blueprints for identity security platforms.
  • Contribute to cross-domain security architecture reviews and compliance alignment.
  • Coordinate with Cyber Defence to monitor identity telemetry and security events.
  • Oversee third-party providers supporting identity services.

Skills

Active Directory
Entra
Identity lifecycle
Privileged access
Access governance
Least privilege
IAM concepts
Zero trust
RBAC
SailPoint
CyberArk
BeyondTrust
MS Defender for Identity
CrowdStrike Identity
PowerShell
Identity threat detection
Non-human identity governance

Tools

SailPoint
CyberArk
BeyondTrust
MS Defender for Identity
CrowdStrike Identity
SilverFort

Job description

Your role

Reporting to the Senior Manager of Cyber Engineering & Architecture, the Identity Security Engineer will be a core member of the engineering team, responsible for the governance and continuous improvement of the Aer Lingus’ identity security posture (which includes privileged access). This hands‑on role supports delivery of identity security standards, secure‑by‑design architectures, identity lifecycle management, access controls and processes.

Your role

Reporting to the Senior Manager of Cyber Engineering & Architecture, the Identity Security Engineer will be a core member of the engineering team, responsible for the governance and continuous improvement of the Aer Lingus’ identity security posture (which includes privileged access). This hands‑on role supports delivery of identity security standards, secure‑by‑design architectures, identity lifecycle management, access controls and processes.

Responsibilities

The role will work closely with cross‑functional teams in Cyber, technology and applications, to implement identity controls and process governance, automation for identity lifecycle processes, management and oversight of our identity security posture and the health of underlying identity platforms. Responsibilities to include:

  • Support ownership of identity & privileged security policies, standards and architecture patterns across AD, Entra and IGA services.
  • Implement and maintain identity lifecycle workflows and governance processes (joiners/movers/leavers, access requests, access reviews) leveraging SailPoint.
  • Support implementation of a privileged access platform, and the development of privileged access controls as part of identity services, including governance and lifecycle processes.
  • Engineer continuous improvements of identity security controls, PAM and IAM lifecycle processes, enabling self‑service and scalable services through automation
  • Deliver identity posture monitoring, and ongoing improvements of identity security controls.
  • Provide SME support for identity‑related security incidents and investigations, contributing to containment and remediation activities.
  • Support the building of identity metrics and dashboards, for centralised oversight of identity security controls coverage, effectiveness and risks.
  • Collaborate with application and platform teams to embed secure‑by‑design identity patterns (authentication, authorisation, RBAC, least privilege).
  • Maintain documentation and blueprints for identity security standards and processes, including configuration management of the identity security platforms.
  • Contribute to cross‑domain security architecture reviews.
  • Partner with Cyber Defence ensuring appropriate identity telemetry is being monitored.
  • Support cyber alignment with compliance requirements & regulations.
  • Provide direction and oversight to third party providers that are supporting and operating identity services and platforms.
Your Qualifications And Key Criteria
  • Minimum of 10 years’ industry experience with at least 5 years in identity management or identity security engineering roles.
  • Hands‑on experience with Active Directory and/or Entra in an enterprise environment.
  • Hands‑on experience designing, implementing and governing identity lifecycle and access lifecycle processes using an IGA platform
  • Experience designing & implementing privileged access management controls and processes
  • Experience working with stakeholders to implement access governance and least privilege controls.
  • Relevant certifications e.g., Microsoft identity/security, CISSP/CISM/CIAM/CRISC
  • Strong understanding of IAM principles including zero trust, least privilege, RBAC, access reviews/certifications, segregation of duties concepts and lifecycle governance.
  • Ability to define secure identity architecture patterns and translate them into practical standards and blueprints.
  • Ability to implement identity standards and controls consistently and document outcomes.
  • Strong analytical and troubleshooting skills for identity and access issues.
  • Good communication and collaboration skills across technology, cyber and business teams.
  • Engineering experience with Identity Protection, IAM, and governance e.g. SailPoint, CyberArk, BeyondTrust, MS Defender for Identity, Crowdstrike Identity, SilverFort
  • Scripting/automation exposure (e.g., PowerShell) to improve identity governance processes.
  • Experience with identity threat detection concepts and integration with SOC monitoring.
  • Experience with non‑human identity governance patterns and modern authentication protocols.
Division / Department

Digital & Information - IT Other

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity Security Engineer: Privileged Access & IAM Leader
Identity Security Engineer: Privileged Access & IAM Leader

Aer Lingus • Dublin

On-site
EUR 120,000 - 160,000
Identity Security Engineer
Identity Security Engineer

Realtime Recruitment • Dublin

Hybrid
EUR 70,000 - 100,000
Identity Security Engineer — IAM & PAM Lead (Dublin)
Identity Security Engineer — IAM & PAM Lead (Dublin)

Aer Lingus Group • Dublin

On-site
EUR 110,000 - 140,000
Staff travel benefits (with Aer Lingus
Competitive salary
Career advancement opportunities
Identity Security Engineer: IAM, PAM & SailPoint Lead
Identity Security Engineer: IAM, PAM & SailPoint Lead

Realtime Recruitment • Dublin

Hybrid
EUR 70,000 - 100,000
IAM Engineer (One Identity Manager)
IAM Engineer (One Identity Manager)

Methodius IT Recruitment • Ireland

Hybrid
EUR 75,000 - 120,000
Contributory Pension Scheme
Private Medical Insurance
Life Assurance
+6
Principal Security Engineer
Principal Security Engineer

Jobgether • Ireland

On-site
EUR 120,000 - 180,000
Cyber Security Platform Engineer
Cyber Security Platform Engineer

Methodius Ltd • Dublin

Hybrid
EUR 60,000 - 80,000
Annual Bonus Scheme
Contributory Pension
Private Medical Insurance
+6
Lead Cyber Security Engineer
Lead Cyber Security Engineer

Mater Private Network • Dublin

Hybrid
EUR 90,000 - 140,000
IAM Engineer (One Identity Manager)
IAM Engineer (One Identity Manager)

Methodius Ltd • Letterkenny

Hybrid
EUR 60,000 - 80,000
Annual Bonus Scheme
Contributory Pension Scheme
Private Medical Insurance
+8
IT Security Automation Engineer
IT Security Automation Engineer

Cpl • Dublin

Hybrid
EUR 75,000 - 81,000
Hybrid and flexible working
Discretionary bonus
Private medical cover
+5