IAM Specialist
Senior Identity & Access Management Specialist
Location: Warwickshire Salary: Circa £90,000 + benefits, including £4,800 car allowance Working Pattern: Hybrid – 3 days remote per week
The Role
We’re looking for an experienced Identity & Access Management (IAM) Specialist to join a growing Cyber Security function and help develop a more mature, secure and scalable approach to identity and access management.
This is a hands-on opportunity to assess an existing identity environment, identify areas for improvement and help shape the future IAM strategy across a complex global organisation.
You’ll work closely with Cyber Security, Engineering, Architecture, Infrastructure and business teams, ensuring identity controls are secure, practical and aligned with operational requirements.
The initial focus will be approximately 50% IAM design, 30% governance and 20% operational IAM, with this balance expected to evolve as the capability develops.
The environment supports up to around 15,000 users, with approximately 3,500–4,000 active users at any one time.
Key Responsibilities
- Design, develop and improve IAM capabilities, controls, standards and operating processes.
- Assess the existing identity estate, identifying security gaps, risks and opportunities for improvement.
- Develop effective Joiner, Mover and Leaver (JML) processes across employee, contractor, privileged, service and system identities.
- Define and implement authentication, authorisation, RBAC, least privilege and segregation of duties controls.
- Support the transition from traditional Microsoft identity services towards Microsoft Entra ID.
- Establish and enhance IAM governance, including access reviews, recertification, role modelling, audit evidence and control assurance.
- Develop privileged access controls, elevated-access workflows and privileged account lifecycle management.
- Work with Engineering, Architecture, Infrastructure and Application teams to embed secure identity principles into technology and solution designs.
- Define scalable identity patterns for enterprise applications, SaaS platforms, APIs and cloud services.
- Investigate identity-related incidents, access exceptions and control failures, escalating risks where appropriate.
- Identify opportunities to automate access requests, approvals, lifecycle processes, reporting and other IAM activities.
- Produce clear technical documentation, standards, procedures and guidance.
- Work with internal teams, external suppliers and managed service partners to deliver IAM improvements.
- Provide technical guidance to both technical and non-technical stakeholders, translating identity risks into practical solutions.
What We're Looking For
The core requirement is strong technical experience in either IAM or Privileged Access Management (PAM), alongside the desire to broaden your expertise across the wider identity security landscape.
You may come from a strong IAM background with an interest in developing your PAM knowledge, or from a PAM-focused position with broader experience across IAM design, governance and lifecycle management.
You’re likely to have:
- Strong hands-on experience designing, implementing or improving IAM or PAM within an enterprise environment.
- Experience transforming an existing identity capability or developing IAM services towards a defined target state.
- Strong knowledge of identity lifecycle management and JML processes.
- Experience managing user, privileged and service identities across cloud and on-premise environments.
- Practical experience with cloud identity services – cloud experience is essential.
- Experience with Active Directory, Microsoft Entra ID/Azure AD or similar enterprise identity platforms.
- Strong understanding of authentication, authorisation, RBAC, least privilege, access governance and segregation of duties.
- Experience translating security, risk and compliance requirements into practical technical controls.
- Experience working with Architecture and Engineering teams to influence secure technology design.
- Exposure to access reviews, recertification, privileged access controls, audit and identity governance.
- Strong analytical and problem-solving skills when dealing with complex identity and access issues.
- Confident communication and stakeholder-management skills, with the ability to challenge existing processes constructively.
- A proactive approach and a genuine focus on continuous improvement.