IAM Platform Engineer - Authentication, Credentials & PAM

G-Research
London, UK
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Active Directory User Authentication C Sharp (Programming Language) Continuous Integration Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth Openid Connect Azure Active Directory Security Assertion Markup Language (SAML)
+7 more
Software Engineering Data Logging Okta Pingfederate Kubernetes Infrastructure Automation Frameworks Api Design

Job description

We’re looking for an experienced Identity and Access Management (IAM) Platform Engineer to own and evolve our authentication, identity federation, credential management and privileged access platforms.

You will help modernise our identity infrastructure, replacing bespoke authentication patterns with scalable, standards-based IAM services that are secure, automated and easy for engineering teams to consume.

You’ll help shape the future of authentication and privileged access within one of the world’s leading quantitative research firms, working on large-scale engineering problems rather than traditional operational IAM., * Designing, implementing and supporting enterprise authentication and identity federation services

  • Developing standard onboarding patterns for applications using SAML, OAuth2 and OpenID Connect
  • Improving and rationalising our identity provider estate, including PingFederate, PingAM and cloud identity platforms
  • Engineering secure privileged access solutions using Teleport and Just-in-Time access principles
  • Defining standards for service accounts, certificates, secrets and machine identities
  • Building APIs and automation to simplify identity platform operations
  • Partnering with engineering teams to deliver reusable, secure authentication services
  • Improving operational maturity through monitoring, alerting, logging, documentation and automation
  • Supporting migration away from bespoke authentication implementations towards enterprise IAM standards

Requirements

The ideal candidate will have the following skills and experience:

  • Experience engineering and operating enterprise IAM platforms
  • Experience with enterprise identity providers such as PingFederate, PingAM, Microsoft Entra ID or Okta
  • Strong understanding of authentication, authorisation, Active Directory, LDAP and privileged access management
  • Experience applying modern platform engineering practices, including infrastructure as code, CI/CD, automation and observability
  • Software engineering experience in languages such as C#, Java, Python or Go
  • Experience building APIs and automating identity platform services
  • Experience supporting hybrid on-premises and cloud identity platforms, including Kubernetes

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension
  • Company events, * Highly competitive compensation plus annual discretionary bonus.
  • Lunch provided via Just Eat for Business and dedicated barista bar.
  • 35 days’ annual leave.
  • 9% company pension contributions.
  • Informal dress code and excellent work-life balance.
  • Comprehensive healthcare and life assurance.
  • Cycle-to-work scheme.
  • Monthly company events.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:10 min

Understanding the core concepts of API design

Alen Pokos · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:26 min

Prioritizing backward compatibility in API design

Justin Kitagawa · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all