IAM Engineer - Identity & Access Management Engineer

Finning International Inc.
Cannock, UK
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) User Authentication Configuration Management Identity and Access Management OpenID Windows PowerShell Security Assertion Markup Language (SAML) Okta Microsoft Power Automate

Job description

The IAM Engineer will co-own and advance our authentication capabilities end-to-end. In this role, you will work with leading technologies such as Entra ID, OKTA, ClearPass/NPS, and on-prem Active Directory, ensuring secure, modern, and highly available authentication services worldwide., Authentication & Identity Management Manage Entra ID configurations for SSO, MFA, and Conditional Access baselines. Oversee app registrations, enterprise app approvals, and environment hygiene. Govern admin consent for Graph/API scopes. Support a multi-domain Active Directory environment and ensure optimised global authentication. Maintain overall GPO health and configuration management. Lead transitions between On-Prem AD and Entra ID. Enhance authentication using FIDO2 and phish-resistant methods. Monitor authentication service health and publish regular performance and risk reports. Projects & Strategic Initiatives: Implement OIDC/SAML federation patterns and SCIM integrations. Advance Customer IAM journeys and strengthen posture integrations with ClearPass. Drive identity transition projects and collaborate closely with the broader Global IAM team.

Requirements

Relevant IAM experience, with strong expertise in Active Directory and Entra ID. Hands-on experience managing and supporting OKTA, ClearPass, and NPS (asset). Direct experience with AD * Entra ID transitions. Proficiency in automation/scripting, including PowerShell and Power Automate. Proven ownership of GPO design, health, and lifecycle management. Deep understanding of modern authentication technologies and industry standards. Microsoft SC-300 or equivalent IAM/security certification desirable

Benefits & conditions

In addition to a competitive salary, bonus, 25 days holiday, life insurance and up to 7% pension, you will benefit from: Comprehensive benefits package A supportive and collaborative work environment Opportunities for professional growth and development At Finning, we prioritize creating a diverse and inclusive environment. We are proud to be an equal opportunity employer, and we actively encourage all individuals to express themselves and achieve their full potential. As a company, we continuously strive to enhance our outreach to individuals of all backgrounds and identities. We do not discriminate against applicants based on gender identity, race, national and ethnic origin, religion, age, sexual orientation, marital and family status, and/or mental or physical disabilities. Furthermore, Finning is committed to collaborating with and providing reasonable accommodations /adjustments to individuals with disabilities. If you require an adjustment/accommodation at any point during the recruitment process, please inform your recruiter. Finning is a forces-friendly employer having signed the Armed Forces Covenant, and pledges to treat those who serve or have served in the armed forces, and their families fairly.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · WWC 2023

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all