Identity & Access Management (IAM) Security Engineer
Role Purpose
Engineer and operate identity and access security controls across Entra ID and
integrated platforms, ensuring Zero Trust access, strong MFA enforcement, least
privilege, privileged access governance and audit-grade identity evidence in line
with the Client’s regulatory and Group requirements.
Responsibilities
• Configure and manage Entra ID security controls: Conditional Access, MFA (including phishing-resistant options where applicable), Identity Protection policies and Privileged Identity Management (PIM).
• Design and implement role and group-based access models that enforce least privilege, separation of duties and Zero Trust access patterns across critical applications and infrastructure.
• Support IAM lifecycle processes (joiner/mover/leaver) by providing secure technical patterns, automation hooks and periodic control checks; coordinate with HR, IT operations and application owners.
• Monitor and respond to identity-related risks: risky sign-ins, legacy authentication usage, unusual MFA activity, impossible travel alerts and privileged access anomalies.
• Lead periodic access reviews and privileged access attestations; coordinate cleanup of orphaned and dormant accounts; provide audit-ready evidence for compliance assessments.
• Define and report IAM security metrics: MFA coverage, time-to-deprovision, orphaned account count, privileged access coverage and legacy authentication exposure.
• Partner with the Intune/EUC Security Engineer and Senior M365/Azure Lead to align identity controls with endpoint, BYOD and application access requirements.
• Support SSO, federation and external identity (partner/vendor) integrations from a security design and control perspective.
Scope Boundaries
• IAM lifecycle administration (provisioning and deprovisioning) is owned by IT/HR operations processes; this role focuses on the security controls that govern identity.
• Strategic PAM tooling investment decisions and policy approvals remain with cyber leadership.
• Application-level access rights management remains with application owners; this role provides identity security patterns and oversight.
Decision Rights
• Recommend and implement Conditional Access rules, MFA policies and PIM configurations within delegated authority.
• Escalate identity control failures, access governance breaches, overdue access reviews or high-risk identity events to cyber leadership.
• Validate that identity security controls meet audit and regulatory evidence requirements.
Tools and Platforms
Identity Platform Microsoft Entra ID (Azure AD), Conditional Access, Identity Protection
Privileged Access Privileged Identity Management (PIM), admin role governance
Authentication MFA (Microsoft Authenticator, FIDO2), legacy auth blocking, SSPR
Access Governance Access reviews, entitlement management, Entra ID RBAC
Hybrid Identity On-premises Active Directory, Entra Connect, hybrid join Federation & SSO SAML, OAuth 2.0/OIDC, application integrations