Identity & Access Management Engineer (IAM Platform Engineer)
Summary
The IAM Platform Engineer will design, implement, and maintain identity and access management solutions, including federation technologies and automation scripts. The role involves managing platforms like Microsoft Entra ID and Active Directory while applying DevSecOps principles to ensure secure and compliant identity operations.
Role overview:
We are looking for a Platform Operations Engineer to design, implement, operate and continuously improve Identity and Access Management (IAM) capabilities.
Responsibilities
- Design, implement, configure and maintain IAM solutions across the organisation.
- Configure and manage identity brokering and federation technologies, including Active Directory, AD FS, PKI and Microsoft Entra ID.
- Implement and manage authentication and authorisation protocols including Kerberos, SAML, OAuth and OpenID Connect.
- Use Microsoft Graph API to support identity administration, integration and automation.
- Develop and maintain scripts, tools and automation using PowerShell, Python or similar technologies to reduce manual effort and operational workload.
- Build and maintain platform and deployment automation using scripting, configuration management and CI/CD practices.
- Apply DevSecOps principles to platform, identity and security automation.
- Support day-to-day platform operations, troubleshoot incidents and resolve IAM and platform-related issues.
- Ensure identity platforms are secure, resilient, governed and compliant.
- Contribute to monitoring, documentation, testing, change management and operational readiness activities.
- Work closely with internal teams, vendors and technology partners to deliver identity and automation initiatives and resolve technical issues.
- Communicate technical matters clearly to both technical and non-technical stakeholders.
- Share knowledge and contribute to a collaborative team environment.
- Participate in on-call, incident response and operational support when required.
Requirements
- 4 or more years of experience in IAM, platform engineering, automation or a related field.
- Hands-on experience with Active Directory, LDAP, AD FS and Microsoft Entra ID.
- Strong understanding of SAML, OAuth and OpenID Connect; knowledge of Kerberos is an advantage.
- Experience using Microsoft Graph API for identity management, integration or automation.
- Proficiency in PowerShell, Python or similar scripting languages.
- Knowledge of identity governance, access management and compliance.
- Strong troubleshooting, analytical and problem-solving skills.
- Certifications such as the Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure Security Engineer Associate or any relevant AWS or DevOps certifications will be a plus.
- Degree in Computer Science, Computer Engineering, Information Technology, Engineering or a related discipline, or equivalent relevant experience.