Identity Security Engineer
Indexed description
About the Role
Working as an Identity Security Engineer within the Cyber Engineering & Architecture function, you will be a core member of the engineering team, responsible for the governance and continuous improvement of my clients identity security posture (which includes privileged access). This hands‑on role supports delivery of identity security standards, secure‑by‑design architectures, identity lifecycle management, access controls and processes under the direction of the Senior Identity Security Engineer.
Key Responsibilities
- Improve the execution quality and timeliness of identity lifecycle processes, including joiner/mover/leaver provisioning, access changes, and third-party identity governance.
- Own and support identity and privileged access security policies, standards, and architecture patterns across Active Directory (AD), Microsoft Entra, and Identity Governance and Administration (IGA) platforms.
- Design, implement, and maintain identity lifecycle workflows and access governance processes using SailPoint.
- Support the implementation and ongoing development of Privileged Access Management (PAM) controls, platforms, and lifecycle governance processes.
- Engineer continuous improvements to IAM and PAM controls, enabling scalable, automated, and self-service identity management capabilities.
- Deliver identity security posture monitoring and drive remediation of identity-related control gaps in collaboration with technology owners.
- Provide subject matter expertise in identity-related security incidents, supporting investigation, containment, and remediation activities.
- Develop and maintain identity security metrics, dashboards, and reporting to provide visibility of control effectiveness, coverage, and risk.
- Collaborate with application and platform teams to embed secure-by-design identity patterns, including authentication, authorisation, RBAC, and least privilege principles.
- Maintain identity architecture documentation, blueprints, and configuration standards for identity security platforms.
- Contribute to cross-domain security architecture reviews and ensure alignment with enterprise security principles.
- Partner with cyber defence teams to ensure appropriate identity telemetry is monitored and integrated into detection capabilities.
- Support compliance and regulatory alignment for identity security controls and governance.
- Provide oversight and direction to third-party providers delivering identity services and platforms.
Requirements
- Minimum 10 years of IT industry experience, with at least 5 years focused on identity management or identity security engineering.
- Hands-on experience with Active Directory and/or Microsoft Entra in an enterprise environment.
- Strong experience designing and implementing identity lifecycle and access governance processes using an IGA platform such as SailPoint.
- Proven experience designing and implementing Privileged Access Management (PAM) solutions and controls.
- Strong understanding of IAM principles including zero trust, least privilege, RBAC, segregation of duties, and access certification processes.
- Experience working with stakeholders to implement access governance and enforce least privilege across enterprise environments.
- Ability to define identity security architecture patterns and translate them into practical standards, controls, and documentation.
- Strong analytical and troubleshooting skills related to identity and access management issues.
- Experience working across technical, cyber security, and business stakeholders with strong communication and collaboration skills.
- Familiarity with identity security and protection tools such as CyberArk, BeyondTrust, Microsoft Defender for Identity, CrowdStrike Identity, or similar platforms.
- Experience supporting identity-related security incident investigation and coordination with SOC or cyber defence teams.
- Exposure to scripting or automation (e.g., PowerShell) for identity process improvement is desirable.
- Understanding of identity telemetry, threat detection concepts, and integration with security monitoring systems is desirable.
- Experience with non-human identity governance and modern authentication protocols is desirable.
- Relevant certifications such as Microsoft security/identity certifications, CISSP, CISM, CIAM, or CRISC are advantageous.
Apply now or email your CV to [email protected]
The role is open to candidates based in Dublin or with a 3 day onsite expectation
Must be in Ireland holding Stamp 4, EU, Irish Passport with full working rights – No Sponsorship supported
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search