This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Senior Identity Security Engineer to design, implement and enhance large‑scale identity environments across Microsoft Active Directory, Entra ID, PKI/ADCS and modern hybrid platforms. This role combines hands‑on engineering with leadership in security design, implementation and assessment, requiring someone who can resolve complex identity challenges end‑to‑end and deliver robust, high‑impact solutions. You will work closely with engineering, architecture and operational teams, across a range of sectors, to deliver secure, resilient identity and certificate services across on‑premises, hybrid and cloud environments.
Job Responsibility:
Design and architect modern Microsoft identity platforms, including new Active Directory and Entra ID environments, design patterns, standards and long‑term roadmaps for secure, scalable foundations
Integrate third‑party identity services, including platforms such as Okta, Ping, Duo, Auth0 and Yubico
Assess and improve existing identity environments by identifying risks, technical debt, reliability issues and leading the engineering work to implement practical, measurable improvements
Engineer PKI and certificate lifecycle services at scale, including PKI/ADCS design and operation, certificate automation, cloud integrations and modern machine‑identity use cases
Plan and lead safe migrations and legacy exits, including decommissioning legacy AD forests, MIM, ADFS and outdated identity components
Drive adoption of passwordless and modern authentication, implementing solutions such as Windows Hello, passkeys, FIDO2 and supporting clients through change and adoption
Evolve organisations toward cloud‑first identity models, implementing hybrid identity strategies, modern authentication, attribute mastering and secure workload/device identity patterns
Automate identity and certificate operations using automation, DevSecOps practices and infrastructure‑as‑code to deliver secure, consistent and maintainable identity services
Advising clients on IAM best practices, standards and regulatory requirements, including GDPR, ISO 27001, NIST Frameworks
Requirements:
Strong engineering background with deep expertise across Active Directory, Entra ID and PKI/ADCS in large, complex environments
Pragmatic, methodical problem‑solver able to diagnose and resolve identity issues end‑to‑end in hybrid platforms
Effective communicator and collaborator, working across architecture, engineering and operations teams
Trusted by clients and colleagues
delivers practical, secure solutions that reduce real‑world risk
Broad experience across Active Directory, PKI, hybrid identity and modern authentication, including tiering, automation and identity hygiene
Skilled in identity migrations and legacy exits, covering AD consolidation, ADFS/MIM retirement and modernisation
Strong automation capability with PowerShell, CI/CD, monitoring and IaC to improve reliability and consistency
Nice to have:
Microsoft identity & security certifications (SC-300, SC-100, AZ-500 or equivalent AD/Entra/PKI qualifications)
Security or architecture credentials like CISSP, ISSAP, CRISC, TOGAF or SABSA
Cloud platform certifications across Azure, AWS, GCP or Terraform
What we offer:
A collaborative and supportive environment in which you can grow and develop your career
The tools and opportunity to do work you can be proud of
A chance to work alongside some of the best people in the industry, who always seek to share their knowledge and experience
Hybrid working – we empower you to make smart choices about when and where to work to achieve great results
Industry leading coaching and mentoring
Competitive salary and an excellent benefits package