Senior IAM Engineer

Morningstar, Inc.
London, UK
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
£59,400.0 - £82,867.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Authentication Protocols Microsoft Azure Software as a Service Multi-Factor Authentication Identity and Access Management OAuth OpenID Windows PowerShell Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On
+6 more
Systems Integration Enterprise Software Applications Okta Information Technology Splunk Servicenow

Job description

We’re looking for a Senior IAM Engineer to own and evolve our enterprise identity platform across Okta and Microsoft Entra ID. This highly visible role partners closely with teams across the organization, requiring a proactive, innovative mindset and a willingness to think beyond conventional approaches. Operating within an Agile environment, the team moves at pace to adapt to evolving business needs. Our technologists bring a diverse range of expertise and share a commitment to treating technology as a craft, with a strong focus on delivering high-quality, customer-centric outcomes. The team underpins critical business services, enabling key functions across the organization to deliver seamless and exceptional user experiences.

Responsibilities

  • Design, build, and maintain enterprise Identity and Access Management solutions using Okta and Microsoft Entra ID.

  • Engineer and automate Joiner, Mover, Leaver (JML) lifecycle processes using Okta Workflows.

  • Design and implement Single Sign-On (SSO), Multi-Factor Authentication (MFA), and identity governance solutions across enterprise applications.

  • Integrate cloud and on-premises applications using SAML, OAuth, OIDC, SCIM, and other modern authentication protocols.

  • Develop PowerShell automation to streamline identity provisioning, administration, and operational processes.

  • Engineer and maintain hybrid identity services across Active Directory and Microsoft Entra ID.

  • Administer and optimize Active Directory, including Group Policy management and enterprise domain services.

  • Support Azure Application Proxy and secure remote application access.

  • Participate in the design, planning, and delivery of identity-related projects and platform enhancements.

  • Produce and maintain technical documentation for identity architecture, integrations, and automation.

  • Provide third-line technical support for complex IAM issues and contribute to incident response and root cause analysis.

  • Stay current with emerging identity technologies and recommend improvements to the platform.

Requirements

  • Bachelor’s degree in Computer Science or a related discipline (or equivalent practical experience).

  • Strong hands-on experience engineering enterprise IAM solutions.

  • 2+ years’ experience with Okta Single Sign-On (SSO) and Lifecycle Management.

  • 2+ years’ experience with Okta Identity Governance (OIG).

  • 2+ years’ experience developing solutions using Okta Workflows.

  • 5+ years’ experience working with Active Directory in complex enterprise environments.

  • Strong knowledge of Active Directory Group Policies (GPO).

  • Experience with Microsoft Entra ID (Azure Active Directory).

  • Experience with Azure Application Proxy or similar application proxy technologies.

  • Strong PowerShell scripting skills with a focus on automation.

  • Experience with Microsoft Certificate Services.

  • Excellent troubleshooting and problem-solving skills.

  • Ability to work independently and thrive in a fast-paced, evolving environment.

Desirable:

  • ServiceNow

  • Splunk

  • Experience with System for Cross-domain Identity Management (SCIM)

  • Experience integrating SaaS applications with enterprise identity platforms

  • Familiarity with Infrastructure as Code or automation tooling

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

Videos

See all

Related articles

See all