IAM Security Engineer

Iam
Bradford, UK
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Kubernetes Security User Authentication Cloud Computing Security Cyber Security Identity and Access Management Key Management Public Key Infrastructure Zero Trust Network Access Policy as Code SSL Certificate Management Software Security Kubernetes
+2 more
CIS Benchmarks Devsecops

Job description

The client is undergoing a transformation of its Identity and Access Management practices including the delivery of a set of net new tools to overhaul how IAM is carried out in the industry. We are seeking experienced and dynamic Security Engineer who have an excellent understanding of Identity Management, with a successful track record of working in complex global organisations at fast pace.

In this role, you will:

  • Design and implement security controls across the IDAM 2.0 platform.

  • Embed Secure by Design principles throughout solution delivery.

  • Implement and maintain Zero Trust security controls.

  • Configure and maintain authentication and authorisation security mechanisms.

  • Implement secure service-to-service communication using mutual TLS (mTLS).

  • Implement and maintain Policy-as-Code solutions using OPA and related technologies.

  • Integrate secrets management, PKI and certificate lifecycle services.

  • Support cryptographic key management and certificate rotation processes.

  • Perform security reviews of solution designs, infrastructure and application code.

  • Conduct threat modelling and security risk assessments.

  • Develop and maintain security baselines, standards and hardening guides.

  • Implement cloud security controls for GCP resources and Kubernetes platforms.

  • Support identity governance, privileged access and least privilege implementation.

  • Collaborate with Security Operations and Incident Response teams during security events.

  • Support security assurance for third-party integrations and supplier solutions.

Requirements

  • Information Security Engineering

  • Identity and Access Management (IAM)

  • Zero Trust Architecture

  • Authentication and Authorisation

  • Workload Identity

  • Agent Identity

  • PKI and Certificate Management

  • Cryptography

  • Cloud Security (GCP)

  • Kubernetes Security

  • API Security

  • Policy-as-Code (OPA)

  • DevSecOps

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · World Congress 2025

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all