Identity Engineer

Randstad

Auckland

On-site

NZD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Randstad New Zealand is seeking an Identity Engineer (WIAM & Cloud Migration) for a 12-month contract. You will direct technical delivery for a major cloud transition and manage identity architecture within a hybrid enterprise environment.

This senior role requires IAM specialization, strong Microsoft Entra ID and Azure AD expertise, and the ability to lead cross-functional teams to implement SSO, MFA, RBAC/ABAC, and SailPoint governance across on-prem and cloud workloads.

Qualifications

  • IAM Specialisation: Extensive engineering experience in Identity and Access Management, with a proven history of delivering technical solutions in hybrid environments rather than advisory-only capacities.
  • Microsoft Stack Expertise: Advanced technical knowledge of Microsoft identity platforms, including Entra ID (Azure AD), Active Directory, Conditional Access policies, and Azure RBAC.
  • Security Control Application: Practical experience implementing privileged access controls, resolving toxic access combinations, and managing directory services during active cloud migrations.
  • Federation Protocols: Solid understanding of modern identity protocols, directory structures, and system integration methods.
  • Strategic Communication: Exceptional communication skills with a demonstrated capability to direct technical specialists, risk teams, and architecture business partners effectively.

Responsibilities

  • Identity Platform Modernisation: Define technical specifications to connect information systems to the identity platform as cloud migration progresses, ensuring reliable and secure operations across the hybrid estate.
  • Access Control Enforcement: Design and implement privileged access controls, manage Separation of Duties (SoD) to address toxic entitlement combinations, and deploy RBAC/ABAC models aligned with a least-privilege methodology.
  • Cloud Integration: Direct Identity and Solution Architects to identify and resolve identity control gaps that emerge as workloads shift between on-premises and cloud environments.
  • Authentication Standards: Implement Single Sign-On (SSO), multi-factor authentication (MFA) protocols, and federation models between enterprise applications and primary identity providers.
  • Governance Frameworks: Drive the implementation of SailPoint to govern access across the estate, while ensuring clear operational documentation is maintained.

Skills

IAM
Identity Platform
Workforce Identity
WIAM
Cloud Migration
Enterprise Architecture
Entra ID
Azure AD
Active Directory
Azure RBAC
Conditional Access
Identity Governance
IGA
SailPoint
PAM

Education

Bachelor Degree
Post Graduate Diploma ICT

Job description

Jora New Zealand will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

Identity Engineer (WIAM & Cloud Migration)
The Opportunity - 12 Month Contract

This critical technical role within the Workforce Identity (WIAM) team directs technical delivery for a major cloud transition. You will manage identity architecture and enforce security governance within a complex enterprise environment.

You will direct application and security teams to modernise access controls and governance across hybrid infrastructure. While initially managing the large workforce estate, the role offers pathways to lead customer identity (CIAM) systems.

Key Responsibilities
  • Identity Platform Modernisation: Define technical specifications to connect information systems to the identity platform as cloud migration progresses, ensuring reliable and secure operations across the hybrid estate.
  • Access Control Enforcement: Design and implement privileged access controls, manage Separation of Duties (SoD) to address toxic entitlement combinations, and deploy RBAC/ABAC models aligned with a least-privilege methodology.
  • Cloud Integration: Direct Identity and Solution Architects to identify and resolve identity control gaps that emerge as workloads shift between on-premises and cloud environments.
  • Authentication Standards: Implement Single Sign-On (SSO), multi-factor authentication (MFA) protocols, and federation models between enterprise applications and primary identity providers.
  • Governance Frameworks: Drive the implementation of SailPoint to govern access across the estate, while ensuring clear operational documentation is maintained.
Skills and Experience Required
  • IAM Specialisation: Extensive engineering experience in Identity and Access Management, with a proven history of delivering technical solutions in hybrid environments rather than advisory-only capacities.
  • Microsoft Stack Expertise: Advanced technical knowledge of Microsoft identity platforms, including Entra ID (Azure AD), Active Directory, Conditional Access policies, and Azure RBAC.
  • Security Control Application: Practical experience implementing privileged access controls, resolving toxic access combinations, and managing directory services during active cloud migrations.
  • Federation Protocols: Solid understanding of modern identity protocols, directory structures, and system integration methods.
  • Strategic Communication: Exceptional communication skills with a demonstrated capability to direct technical specialists, risk teams, and architecture business partners effectively.
Desirable Criteria
  • Familiarity with Customer Identity (CIAM) platforms such as Optimal, Okta, or Azure AD B2C.
  • Exposure to Privileged Access Management (PAM) or Identity Governance and Administration (IGA) solutions like SailPoint.

At Randstad, we are passionate about providing equal employment opportunities and embracing diversity to the benefit of all. We actively encourage applications from any background.

Experience

7 years

Skills

Identity Engineering, IAM, Workforce Identity, WIAM, Cloud Migration, Enterprise Architecture, Microsoft Identity Stack, Entra ID, Azure AD, Active Directory, Azure RBAC, Conditional Access, Identity Governance, IGA, SailPoint, PAM

Qualifications
  • Bachelor Degree

education

Post Graduate Diploma&ICT

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

identity engineer
identity engineer

Randstad Digital New Zealand • Auckland

On-site
NZD 110,000 - 130,000
Identity Platform Lead: Cloud Migration & Access Governance
Identity Platform Lead: Cloud Migration & Access Governance

Randstad • Auckland

On-site
NZD 120,000 - 180,000
Cloud Identity Architect for IAM & Governance
Cloud Identity Architect for IAM & Governance

Randstad Digital New Zealand • Auckland

On-site
NZD 110,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

Alexander James • Auckland

Hybrid
NZD 110,000 - 150,000
Senior Security Engineer - Cloud Platform
Senior Security Engineer - Cloud Platform

Xero • Wellington

On-site
NZD 120,000 - 160,000
Senior Security Engineer - Cloud Platform
Senior Security Engineer - Cloud Platform

JobSpace • Auckland

Hybrid
NZD 120,000 - 180,000
Hybrid work model
Modern office spaces
Work from home flexibility
Security Engineer (Contract)
Security Engineer (Contract)

Consult Recruitment • Auckland

On-site
NZD 120,000 - 180,000
Security Architect
Security Architect

Consult Recruitment • Wellington

Hybrid
NZD 120,000 - 170,000
Hybrid work flexibility
Challenging project for a financial-PI
Collaborative team environment
Infrastructure Cloud Engineer
Infrastructure Cloud Engineer

AA Insurance • Auckland

On-site
NZD 95,000 - 125,000
Wellbeing allowance
Insurance discounts
Fareshare programme access
Specialist Identity and Access Management
Specialist Identity and Access Management

Cyber Security and Identity • New Zealand

Hybrid
NZD 99,000 - 108,000
Five weeks annual leave
6.75% superannuation scheme
Real work-life balance