Senior Security Identity Engineer

Summary

The Senior Security Identity Engineer will conduct security assessments and remediate vulnerabilities within Microsoft Active Directory and Microsoft Entra ID environments. The role involves using tools like Purple Knight and PingCastle to strengthen identity security, automate reporting, and manage privileged access in a regulated industry setting.

Salary: £68,000 - 108,000 per year

Requirements:
  • Strong hands-on experience securing Microsoft Active Directory.
  • Strong hands-on experience securing Microsoft Entra ID.
  • Demonstrable experience delivering identity vulnerability-remediation programmes.
  • Practical experience using Purple Knight, PingCastle, Forest Druid and Microsoft Defender for Identity.
  • Ability to interpret and remediate findings from assessment tools rather than simply producing reports.
  • Deep understanding of AD domains, forests, trusts and replication.
  • Deep understanding of Group Policy, Kerberos and NTLM.
  • Deep understanding of LDAP, privileged access management, service accounts and managed service accounts.
  • Deep understanding of delegation and access control lists.
  • Deep understanding of Microsoft Entra roles and permissions.
  • Deep understanding of Conditional Access and multi-factor authentication.
  • Deep understanding of application registrations and service principals.
  • Deep understanding of Microsoft Graph permissions and hybrid identity and directory synchronisation.
  • Strong PowerShell capability.
  • Experience with Microsoft Graph or equivalent identity APIs.
  • Experience implementing secure changes in production environments.
  • Understanding of change management, risk management and security assurance.
  • Strong documentation and stakeholder-management skills.
  • Experience in financial services or another regulated industry.
  • Experience with Microsoft Entra Connect or Microsoft Cloud Sync.
  • Experience with privileged-access workstations and administrative tiering.
  • Experience with identity governance, access reviews and entitlement management.
  • Familiarity with zero-trust principles.
  • Experience integrating identity-security findings with SIEM, SOAR, vulnerability-management or service-management platforms.
  • Knowledge of Microsoft Defender XDR and related security recommendations.
  • Experience with infrastructure-as-code or configuration-management tools.
  • Relevant Microsoft, identity or cyber-security certifications.
Responsibilities:
  • Conduct regular security assessments of Active Directory and Microsoft Entra ID.
  • Run, interpret and report on findings from Purple Knight, PingCastle, Forest Druid, Microsoft Defender for Identity recommendations, Microsoft Entra recommendations, Secure Score, vulnerability scanners and other approved tools.
  • Validate assessment findings and remove false positives.
  • Correlate findings across tools to identify common root causes and attack paths.
  • Assess the security posture of AD domains, forests and trusts, domain controllers and member servers, privileged and administrative accounts, service accounts, Group Policy, delegated permissions, Microsoft Entra roles, applications, service principals, and hybrid identity synchronisation components.
  • Produce a prioritised identity-vulnerability and remediation register.
  • Map findings to agreed security standards, control objectives and risk categories.
  • Provide clear reporting to technical teams, project governance and risk owners.
  • Remediate security weaknesses identified through assessment tooling.
  • Review and improve privileged-group membership, administrative access, delegation, Group Policy configuration, service accounts, Kerberos settings, LDAP signing and channel binding, NTLM usage, delegation, credential-exposure risks, stale accounts, domain-controller security configuration, replication and trust relationships, and administrative tiering.
  • Investigate and remediate identity attack paths identified through assessment tooling.
  • Support hardening of domain controllers and associated infrastructure.
  • Validate that changes have removed or reduced relevant security findings.
  • Record exceptions where remediation cannot be completed and ensure they are risk-assessed.
  • Review and remediate Microsoft Entra ID security recommendations and configuration weaknesses.
  • Improve controls relating to privileged roles, Privileged Identity Management, Conditional Access, multi-factor authentication, risk-based sign-in and user-risk policies, legacy authentication, guest and external-user access, application registrations and consent, enterprise applications and service principals, managed identities, authentication methods, emergency-access accounts, access reviews and entitlement governance, and secure administrative access.
  • Review and reduce excessive permissions granted to applications and service principals.
  • Identify and remediate stale certificates, secrets and credentials.
  • Review Microsoft Graph permissions and administrative consent.
  • Implement or improve monitoring for suspicious authentication and privilege activity.
  • Validate remediation against Microsoft Entra recommendations, Secure Score and agreed security standards.
  • Install, configure or execute Purple Knight assessments in accordance with approved security and access requirements.
  • Run PingCastle health checks and security assessments across relevant AD environments.
  • Use Forest Druid to assess forest configuration, trust relationships, attack paths and identity-security risks.
  • Review and action Microsoft Defender for Identity recommendations, exposure findings, identity alerts and Secure Score improvements.
  • Maintain controlled and repeatable assessment procedures.
  • Protect assessment outputs, compare results over time, and ensure tools are used in accordance with licensing, security, privacy and change-management requirements.
  • Document tool versions, assessment dates, scope, assumptions and limitations.
  • Avoid treating automated tool output as evidence without appropriate technical validation.
  • Prioritise remediation according to severity, exploitability, exposure, business criticality and programme objectives.
  • Develop technical remediation plans, implementation procedures and rollback plans.
  • Coordinate testing with infrastructure, application, endpoint, cloud and service owners.
  • Implement changes through approved change-management processes.
  • Validate remediation through repeat assessments and technical testing.
  • Maintain evidence of the original finding, agreed remediation, testing and approvals, implemented change, and post-remediation validation.
  • Track residual risks, accepted exceptions and dependencies.
  • Escalate risks that cannot be remediated within agreed timescales.
  • Develop PowerShell scripts and automation to support identity assessment, remediation and reporting.
  • Use Microsoft Graph and approved APIs to assess and manage Entra ID configuration.
  • Automate checks for privileged access, stale accounts, risky configurations and policy compliance where appropriate.
  • Create repeatable reporting from Purple Knight, PingCastle, Forest Druid and Defender for Identity outputs.
  • Ensure scripts and automation are tested, documented, access-controlled and reviewed before production use.
  • Produce technical documentation, configuration records and operational runbooks.
  • Provide knowledge transfer to internal identity and infrastructure teams.
  • Define repeatable assessment schedules and ownership for ongoing reviews.
  • Establish processes for reviewing assessment results.
  • Support transition of remediation controls into business-as-usual operations.
  • Contribute to post-remediation reporting, lessons learned and continuous improvement.
Technologies:
  • Active Directory
  • Cloud
  • Support
  • LDAP
  • PowerShell
  • Security

More:

We are seeking an experienced Security Identity Engineer to support a fixed-term contract or consultancy engagement within our Hosting and Identity team in the United Kingdom on a hybrid basis. Our work focuses on identifying, prioritising and remediating security vulnerabilities and control weaknesses across Microsoft Active Directory and Microsoft Entra ID, using recognised identity-security assessment tools and Microsoft Defender for Identity recommendations. The role is centred on reducing identity-related risk, strengthening security controls and providing clear evidence of remediation or formally recorded and accepted residual risk. The successful candidate will report to the Identity Engineering Lead / Cyber Security Programme Lead and contribute to technical reporting, remediation delivery, automation, documentation and operational transition.

last updated 34 week of 2026

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available