Quick Overview
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Scotland, United Kingdom
MFASAMLActive DirectoryAzureOnboarding
Job Description
Client: MASTEK
Role: Permanent
Salary: 80K GBP Per Annum (incl 10% variable)
Location: Scotland (once or twice a month)
Key expectations
- Lead MFA and SailPoint discovery and design.
- Create one joined-up IAM architecture across Microsoft Entra, MFA, Microsoft Authenticator, FIDO2 tokens, Active Directory, F5/Legacy access routes, SailPoint ISC and Application A.
- Define the MFA target design, including policy, authentication methods, exceptions, privileged users, recovery and operational controls.
- Define the SailPoint target design for Application onboarding, including AD groups, RBAC, Access Profiles, roles, workflows and approvals.
- Ensure the MFA and SailPoint designs work together and do not create conflicting AD-group, access-governance or privileged-access models.
- Model and implement risk based authentication policies in Azure Entra.
- Lead technical workshops and document architecture decisions.
- Produce technical design documentation and maintain the design-decision log.
- Support Design Authority approval.
- Provide targeted technical assurance during implementation, resolving complex decisions and reviewing significant deviations from design.
- Support RFC, CAB, security assurance, implementation planning, rollback planning and technical handover where required.
- Be hands on in implementing MFA entra, policies, application onboarding and others.
Minimum experience
- 10+ years in IAM, identity architecture, cyber security or enterprise security architecture.
- 5+ years designing and delivering Microsoft Entra ID/Azure AD identity, MFA and Conditional Access solutions in enterprise or public-sector-scale environments.
- Proven experience of Microsoft Authenticator, FIDO2 security keys/passkeys, authentication-method policy, privileged access and emergency-access design.
- 3+ years of hands-on SailPoint Identity Security Cloud architecture or implementation experience, including access profiles, roles, workflows, life cycle controls and access governance.
- Demonstrable Active Directory and hybrid identity experience, including AD groups, group-based authorisation, provisioning and Legacy/on-premise integration.
- Experience of Legacy/hybrid application patterns, including Kerberos, SAML/OIDC, F5/reverse Proxy or application Proxy, Windows-integrated applications and on-premise estates.
- Experience preparing and defending technical designs through formal Design Authority, cyber-security assurance or CAB governance.
Similar jobs
- EU
SOC Reporter
NewEurofins
Warrington🇬🇧On-site6 hours agoContinuous ImprovementData Entry - AD
GRC Analyst
NewAdecco
Preston, Lancashire🇬🇧£42k - £47k/yrHybrid1 hour agoTechnology - LB
Cyber Security Engineer Graduate Scheme
NewLloyds Banking Group
Manchester, Lancashire🇬🇧£48.5k/yrHybrid1 hour agoDockerNode.jsAzure+8Technology - LB
Cyber Security Engineer Graduate Scheme
NewLloyds Banking Group
Edinburgh, Midlothian🇬🇧£48.5k/yrHybrid1 hour agoDockerNode.jsAzure+8Technology - LB
Cyber Security Engineer Graduate Scheme
NewLloyds Banking Group
Leeds, Yorkshire🇬🇧£48.5k/yrHybrid1 hour agoDockerNode.jsAzure+8Technology - TR
SailPoint IAM Engineer
NewTria Recruitment
London🇬🇧Hybrid3 hours agoStakeholder ManagementTechnology