IAM Consultant/Developer (Microsoft Entra ID) - UK, fully remote

Posted 14 Days Ago
Be an Early Applicant
Hiring Remotely in UK
Remote
Senior level
Cloud • Information Technology
The Role
Hands-on IAM consultant responsible for auditing existing identity estates, designing Microsoft Entra ID target architectures, executing phased migrations, configuring hybrid sync, implementing MFA/Conditional Access/passwordless, migrating SSO integrations, enabling identity governance (PIM, access packages, reviews), monitoring/sign-in logs during cutover, and documenting runbooks for operations handover.
Summary Generated by Built In
About Us

Colibri Digital is a specialist consultancy delivering advanced Data, AI and Cloud solutions for clients across financial services, healthcare, government and enterprise technology sectors.
We help organisations build intelligent, scalable and production-grade data platforms that drive measurable business outcomes. We work closely with our clients to move beyond experimentation and into real-world AI and data transformation delivery. Our Consultants operate as trusted advisors and technical leaders within client environments, combining deep technical expertise with strong stakeholder engagement and delivery capability.
The Role
We're looking for a hands-on IAM Consultant/Developer to join Colibri Digital on client engagement, supporting a major Microsoft Entra ID implementation. 
This is a hands-on delivery role requiring someone who can combine IAM architecture and design with practical implementation experience. You’ll play a key role in delivering the migration to Microsoft Entra ID, working across discovery, target state design, migration execution, security and handover. 
This is not a steady-state IAM administration role. We're looking for someone who has previously delivered complex identity migration/implementation projects and is comfortable operating within a fast-paced client consulting environment.

What You'll Be Doing
  • Discovery & design — audit the existing identity estate (on-prem AD, and/or third-party IdP such as Okta or Ping) and design the target-state architecture in Microsoft Entra ID.
  • Migration execution — plan and run the cutover, including phased/staged migration approaches to minimise disruption to live services.
  • Hybrid identity — configure and manage synchronization between on-prem and cloud using Microsoft Entra Connect or Entra Cloud Sync during the transition period.
  • Authentication & security — implement MFA, Conditional Access policies, and passwordless sign-in aligned to Zero Trust principles.
  • Application integration — migrate or re-establish SSO for enterprise applications using SAML, OAuth 2.0, and OIDC.
  • Identity governance — stand up Privileged Identity Management (PIM), Entitlement Management (access packages), and Access Reviews as part of the target state.
  • Cutover support & troubleshooting — monitor sign-in/audit logs and identity protection signals during and after migration to catch issues early.
  • Documentation & handover — leave the operations team with clear runbooks and a clean handover once migration is complete.

What We're Looking For

Essential:
  • Proven experience delivering a migration onto Microsoft Entra ID (formerly Azure AD) — from on-prem AD DS or from a third-party IdP (Okta, Ping, ForgeRock, etc.).
  •  Demonstrable Experience owning migrations of large user bases (500k+) 
  • Strong working knowledge of Conditional Access, Zero Trust security models, and modern authentication protocols (SAML 2.0, OAuth 2.0, OIDC).
  •  Experience with DNS, TLS certificates and Load Balancers. 
  • Confident PowerShell scripting for identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK.
  • Comfortable working independently and communicating migration risk/status to non-technical stakeholders.
Desirable:
  • KQL for log analysis in Microsoft Sentinel or Azure Monitor.
  • Experience with Entra ID B2B/B2C.
  • Background with an alternative IAM platform (ForgeRock, Ping, Okta) — genuinely useful for migration work, since you understand what you're migrating from, not just what you're migrating to.
  •  Experience with API Gateway, API Management platforms 
Certifications (nice to have, not mandatory):
  • SC-300 (Identity and Access Administrator Associate) 
  • SC-100 (Cybersecurity Architect Expert) 
  • SC-500 (Cloud and AI Security Engineer Associate) 
  • CISSP 

About
We are passionate about helping businesses navigate the rapidly changing and complex world of emerging technologies. We create well-structured, secure, scalable solutions at speed to provide the foundation for groundbreaking change.

Skills Required

  • Proven experience delivering migrations onto Microsoft Entra ID from on-prem AD DS or third-party IdP (Okta, Ping, ForgeRock)
  • Strong working knowledge of Conditional Access, Zero Trust security models, and modern authentication protocols (SAML 2.0, OAuth 2.0, OIDC)
  • PowerShell scripting for identity lifecycle automation, ideally using the Microsoft Graph PowerShell SDK
  • Experience configuring and managing hybrid identity synchronization (Microsoft Entra Connect or Entra Cloud Sync)
  • Experience implementing MFA, Conditional Access policies, and passwordless sign-in aligned to Zero Trust
  • Experience migrating or re-establishing SSO for enterprise applications using SAML, OAuth 2.0, and OIDC
  • Experience with identity governance: Privileged Identity Management, Entitlement Management (access packages), and Access Reviews
  • Ability to monitor sign-in/audit logs and identity protection signals and support cutover troubleshooting
  • Comfortable working independently and communicating migration risks/status to non-technical stakeholders
  • KQL for log analysis in Microsoft Sentinel or Azure Monitor
  • Experience with Entra ID B2B/B2C
  • Background with alternative IAM platforms (ForgeRock, Ping, Okta) for migration experience
  • Certifications such as SC-300, SC-100, SC-500, or CISSP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lincoln
923 Employees
Year Founded: 1998

What We Do

At Nasstar, we specialise in transformative technology. Our integrated suite of managed services delivers everything from cloud optimisation and application modernisation to networking, security and self-serve tools. With a consultative approach at our core, we modernise and manage technology to help our clients succeed in today's competitive business world. Through strategic consultation, to implementation and management, we provide the vision and the mechanics needed to create transformational change for our clients.

Similar Jobs

Remote or Hybrid
2 Locations
289097 Employees

Affirm Logo Affirm

Senior Manager MLRO, Compliance

Big Data • Fintech • Mobile • Payments • Financial Services
Easy Apply
Remote
UK
2200 Employees
120K-168K Annually

GitLab Logo GitLab

Back-end Engineer

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
2 Locations
2500 Employees
132K-282K Annually

SOPHiA GENETICS Logo SOPHiA GENETICS

IVD & CDx Validation Lead (Relocation to Switzerland)

Artificial Intelligence • Big Data • Healthtech • Software • Biotech
Remote or Hybrid
3 Locations
450 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account