Identity Infrastructure Engineer

Hays plc
London, UK
1 day ago
Apply on www.jobs.service.gov.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£116,220.0
Working hours
Regular working hours

Tech stack

Active Directory Domain Controllers User Authentication Cloud Computing Disaster Recovery Integrated Windows Authentication Domain Name System (DNS) Monitoring of Systems Identity and Access Management Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Windows Servers
+8 more
Public Key Infrastructure Windows PowerShell Role-Based Access Control Azure Active Directory Runbook Okta System Availability Enterprise Integration

Job description

You will be joining an organisation operating within a secure and highly regulated environment, supporting critical Identity and Access Management (IDAM) services. Working closely with security, engineering and IDAM teams, you will help maintain the resilience, availability and security of core identity infrastructure platforms.

Your new role

As a Senior Identity Infrastructure Engineer, you will be responsible for the administration, support, security and continuous improvement of the organisation’s identity infrastructure estate. This role focuses on Active Directory, PKI, DNS, Group Policy and authentication services, while also providing L2/L3 operational support across wider identity platforms.

Key responsibilities

Active Directory Infrastructure

  • Administer and maintain enterprise Active Directory forests, domains and domain controllers.
  • Manage Active Directory Sites and Services, replication topology, trusts and directory infrastructure.
  • Maintain AD-integrated DNS and authentication services.
  • Design, implement and support Group Policy architecture.
  • Support Active Directory backup, recovery, disaster recovery and business continuity processes.
  • Monitor platform health, security, performance and replication.
  • Participate in Active Directory upgrades, migrations and infrastructure improvement programmes.
  • Implement security hardening standards and privileged access controls.

Public Key Infrastructure (PKI)

  • Administer Microsoft Active Directory Certificate Services (AD CS).
  • Manage Certificate Authorities, templates, enrolment processes and certificate lifecycle management.
  • Support Offline Root CA and Issuing CA environments.
  • Maintain CRL, AIA and certificate distribution services.
  • Monitor renewals, revocations, compliance and certificate expiry.
  • Maintain PKI documentation, recovery procedures and security standards.
  • Troubleshoot cryptographic and certificate-related issues.

Identity Infrastructure & Authentication Services

  • Support Microsoft Entra Connect and hybrid identity services.
  • Maintain LDAP, LDAPS, Kerberos and NTLM authentication platforms.
  • Support integrations across Active Directory, MIM, Entra ID, Okta and BeyondTrust.
  • Resolve authentication, directory and infrastructure incidents.
  • Contribute to service improvements and platform optimisation initiatives.

Automation & Continuous Improvement

  • Develop and maintain PowerShell automation for infrastructure administration.
  • Drive operational efficiency and service improvements.
  • Support security remediation and infrastructure modernisation initiatives.
  • Produce and maintain technical documentation, support procedures and runbooks.

Requirements

  • Extensive experience administering enterprise Active Directory environments.
  • Strong knowledge of:

  • Active Directory Domain Services (AD DS)
  • Active Directory Sites and Services
  • Forest and domain administration
  • DNS
  • Group Policy
  • LDAP / LDAPS
  • Kerberos authentication
  • Trusts and replication
  • Active Directory backup and recovery

Experience troubleshooting complex authentication and directory service issues.

PKI

  • Strong experience with Microsoft Active Directory Certificate Services (AD CS).
  • Experience managing:

  • Certificate Authorities
  • Certificate Templates
  • CRL and AIA infrastructure
  • Certificate lifecycle management
  • Certificate enrolment services
  • Key recovery and archival

Experience supporting enterprise PKI environments.

Infrastructure Platforms

  • Windows Server 2016, 2019 and 2022 administration.
  • PowerShell scripting and automation.
  • Security hardening and privileged administration.
  • High availability and disaster recovery planning.
  • Infrastructure monitoring and operational support.

Identity Technologies

  • Working knowledge of:

  • Microsoft Entra ID
  • Microsoft Entra Connect / Cloud Sync
  • Microsoft Identity Manager (MIM)
  • Okta
  • BeyondTrust
  • Strong understanding of:
  • Identity and Access Management (IAM)
  • Identity lifecycle management
  • Authentication and authorisation
  • Access governance
  • Role-Based Access Control (RBAC)
  • Joiner, Mover, Leaver processes

Desirable skills and experience

  • Experience supporting Microsoft Identity Manager (MIM).
  • Experience supporting hybrid identity architectures.
  • Experience with Okta administration and integration.
  • Knowledge of BeyondTrust PAM or Endpoint Privilege Management.
  • Experience with Tier 0 administration and privileged access models.
  • Familiarity with CrowdStrike, Zscaler and security platform integrations.
  • Experience working within highly regulated or secure environments.
  • Knowledge of ITIL-based operational support models.
  • Experience supporting large-scale enterprise identity programmes.

What you’ll get in return

  • Opportunity to work on critical enterprise identity and authentication platforms.
  • Exposure to complex Active Directory, PKI and hybrid identity environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobs.service.gov.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all