Back to search
Sygnum Bank Linkedin · Posted 2d ago

Senior Identity Engineer

Switzerland

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About Sygnum

Sygnum is a global digital asset banking group, founded on Swiss and Singapore heritage. We empower professional and institutional investors, banks, corporates and DLT foundations to invest in digital assets with complete trust. Our team enables this through our institutional-grade security, expert personal service and portfolio of regulated digital asset banking, asset management, tokenization and B2B services.


In Switzerland, Sygnum holds a banking licence and has CMS and Major Payment Institution Licences in Singapore. The group is also regulated in the established global financial hubs of Abu Dhabi and Luxembourg.


We believe that the future has heritage. Our crypto-native team of banking, investment and digital asset technology professionals are building a trusted gateway between the traditional and digital asset economies that we call Future Finance. To learn more about how Sygnum’s mission and values are shaping this digital asset ecosystem, please visit sygnum.com and follow us on LinkedIn and X.


About the role

This is an engineering role, and we mean it. We are looking for a Senior Identity Engineer to build identity at a regulated digital asset bank and keep it ahead of a business that is not slowing down. Automation matters here, but not as an end in itself. Routine work is what stops engineers doing the work that counts, and the work that counts keeps arriving: non-human identity, AI agents as first-class principals, a directory estate to modernise. Every joiner flow and review campaign you take off a person buys the room to get to it.

In this role keeps your focus is where the programme is, and the programme is real, not a maintenance queue: user provisioning in Microsoft Entra designed and implemented from the authoritative source through to access, Joiner-Mover-Leaver for internal staff that is event-driven and end to end, Conditional Access rolled out and then kept honest, and the retirement of the remaining on-premise Active Directory estate, which is the kind of finite, visible piece of work an identity engineer can point at for the rest of their career.

We hold a line on how identity gets engineered, and we want someone who holds it with us. Declarative state belongs in Terraform: Conditional Access, PIM configuration, entitlement packages, anything where the question is what should be true. Operational events belong in automation: joiners, movers, leavers, access requests, review campaigns, anything where the question is what happens next. The portal is for diagnosis, not for change.

Getting that judgement right is most of the job, because both failure modes are expensive. Put operations into Terraform and every request becomes a pull request and you become the queue. Put state into scripts and you get drift you cannot evidence. Click it into a portal and you have no control at all. We would rather hire someone with strong opinions about where that line sits than someone who is fluent in one tool.

It is a genuinely rare combination: the autonomy and pace of a start-up, with the engineering standards and consequences of a bank. What you build protects real client assets. We also expect you to use AI as a serious engineering tool. AI-assisted development and agentic automation are already part of how this team works, not a side experiment, and they are where this role ends up.


Working With the Lead

The Identity & Access Lead owns the strategy, the roadmap, the governance and the regulatory accountability. You own how it gets built.

That split only works if it runs both ways. The Lead sets the target state and holds the bar. You tell them what is feasible, what it costs and what it will break, and that assessment shapes what actually gets committed. When the Lead sets a guardrail for AI use or a standard for non-human identity, you build within it and tell them where it does not survive contact with production. You are the engineering half of a function that has to be right, not a pair of hands on someone else's plan.


What You Will Do

Build the Platform

  • Design and implement user provisioning in Microsoft Entra, from the authoritative source through to provisioned access
  • Design and implement Joiner-Mover-Leaver for internal staff: event-driven, end to end, with movers and leavers handled inside SLA and without a ticket
  • Roll out Conditional Access policy and keep it maintained as code, reviewed and reproducible
  • Deliver the move to cloud-native identity and retire the remaining on-premise Active Directory estate, including the legacy authentication dependencies that come with it
  • Build and support privileged access workflows across PIM, just-in-time access and MFA


Automate the Operations

  • Build self-service and automated access request, approval and fulfilment, so routine access never reaches an engineer
  • Automate access review campaigns end to end: generation, targeting, chasing, revocation and evidence
  • Automate the exceptions rather than routing them to a person, and design the escalation path for the cases that genuinely need judgement
  • Act as third level escalation for identity, and treat every recurring escalation as an automation backlog item rather than a permanent duty
  • Apply agentic automation to routine identity operations, including triage and evidence collection, within the guardrails set by the Lead
  • Attack toil deliberately: find the identity work that still needs a human, and remove the need for one


Integrate and Prove It

  • Build the integrations that make automation possible: Microsoft Graph, our ITSM platform, HR systems, SIEM and event-driven services
  • Automate the collection and presentation of control evidence, so audit readiness is continuous rather than a periodic exercise
  • Instrument the platform: provisioning SLAs, access review coverage, policy violations and drift, surfaced as data the Lead can act on and report
  • Integrate identity signals into SIEM and SOC detection workflows in partnership with Security Operations
  • Measure the automation itself: what share of identity operations now run with no human touch, and what is stopping the rest


Work Across Teams

  • Act as the hands-on identity specialist for Platform, Security, HR and Risk & Compliance colleagues designing secure application and infrastructure access
  • Advise our engineering teams on authentication and authorisation models (SAML, OAuth2, OIDC) for the applications they build, including client-facing ones, as the identity specialist rather than the implementer
  • Advise on Microsoft tenant security, Azure RBAC and endpoint policy alignment
  • Work with the Platform team on secure service identities and permissions across CI/CD and Azure environments


What Success Looks Like

  • Provisioning and Joiner-Mover-Leaver live, event-driven and evidenced
  • Conditional Access rolled out, maintained as code, and defensible in an audit
  • The on-premise Active Directory estate materially closer to retirement
  • A measurable fall in the share of identity operations that need a human in the loop
  • The person the rest of IT comes to when identity does something unexpected


Our ideal candidate

You are an automation engineer who works in identity. You have strong Microsoft identity foundations and you can hold your own in a Terraform codebase, but you are less interested in how a control is configured than in whether a person still has to touch it. You have opinions about what belongs in code, what belongs in a workflow and what belongs nowhere near a portal, and you can defend them. You have enough judgement to know when a control is genuinely protective and when it is theatre, and you like the idea of your work being audited, because it holds up.


Essential

  • 5+ years in IT, including 3+ years focused on IAM
  • Demonstrable track record designing, implementing and automating identity provisioning and Joiner-Mover-Leaver end to end, not only operating them
  • Strong hands-on experience with Microsoft Entra ID, Conditional Access, PIM and related tooling
  • Strong scripting and API integration skills: Microsoft Graph, PowerShell, Python or equivalent
  • Experience building event-driven or workflow automation, for example Logic Apps, Azure Functions, Power Automate or equivalent orchestration
  • Working experience with Terraform and CI/CD delivery, and a clear view of what does and does not belong in it
  • Hybrid identity experience: Active Directory, Entra Connect or Cloud Sync, and the migration or decommissioning of on-premise directory services
  • Experience integrating identity with ITSM, HR or SIEM platforms
  • Solid grasp of core IAM concepts: RBAC, least privilege, zero trust and identity lifecycle management
  • Working knowledge of regulatory expectations (for example FINMA, ISO 27001) and what good audit evidence looks like
  • Strong communication skills in English; German an advantage


Desirable

  • Experience using AI-assisted development or agentic tooling in a production engineering context
  • Experience with Azure B2B guest identity, federated login or identity brokering
  • Exposure to non-human or workload identity: service accounts, managed identities and secrets management
  • Experience retiring legacy authentication protocols and the applications that depend on them
  • Familiarity with AWS IAM and CloudTrail logging for access insight
  • Exposure to Intune, endpoint compliance and device policy alignment
  • Certifications such as Microsoft Identity and Access Administrator, Azure Security Engineer, CISSP or CISM
  • Financial services, digital assets or crypto experience


If you are passionate about the potential of blockchain to shape Future Finance and your profile is a good fit for this position, please send us your CV today!

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search