Senior Identity Engineer

Posted 2 Days Ago
Be an Early Applicant
Colombo, LKA
In-Office
Senior level
Information Technology • Software • Consulting
The Role
Senior Identity Engineer to design, administer and improve IAM across cloud and on-premises environments. Responsibilities include provisioning, SSO integrations, service-account and service-principal management, incident and request handling, identity governance, automation, documentation, audit support, and mentoring. Role operates in a regulated financial-services environment emphasizing security, compliance and operational resilience.
Summary Generated by Built In
About the Role

We are seeking a Senior Identity Engineer to design, administer, support and continuously improve enterprise Identity and Access Management (IAM) services across cloud and on-premises environments.

This is a hands-on senior technical role within a complex, regulated environment where security, compliance, operational resilience and effective access governance are critical. You will manage identity requests and incidents, implement application integrations, administer privileged and non-human identities, and ensure access is provisioned in line with approved security policies and controls.

You will work closely with security, infrastructure, application, risk, audit and business teams, while also contributing to broader security, cloud and infrastructure initiatives as organisational priorities evolve.

About the Client

You will be working with a large, established financial-services organisation operating in a highly regulated environment. The organisation places strong emphasis on security, risk management, regulatory compliance, operational resilience and the ongoing maturity of its technology and identity capabilities.

Ideal ProfileEssential Experience & Qualifications
  • Significant professional experience in Identity and Access Management, identity engineering or a closely related discipline.
  • Experience supporting identity services within a large and complex enterprise environment.
  • Previous experience in banking, insurance, superannuation, wealth management, payments or another regulated financial-services environment.
  • Strong understanding of least privilege, segregation of duties, role-based access and enterprise access-control principles.
  • Hands-on experience administering identities across cloud and on-premises environments.
  • Experience managing service accounts, service principals, application identities and associated credentials.
  • Proven experience implementing and supporting Single Sign-On integrations.
  • Strong troubleshooting capabilities across authentication, authorisation, federation and directory services.
  • Experience working within formal incident, problem, request and change-management frameworks.
  • Understanding of security, risk, audit and compliance requirements within regulated organisations.
  • Ability to produce clear technical documentation, implementation plans, support procedures and audit evidence.
  • Strong written and verbal communication skills.
  • Ability to manage competing priorities and collaborate effectively with technical and non-technical stakeholders.
  • Relevant tertiary qualifications, industry certifications or equivalent practical experience.
Technical Expertise

Strong experience across several of the following:

  • Microsoft Entra ID, Microsoft Active Directory and Group Policy.
  • Hybrid identity and directory synchronisation.
  • Enterprise application and service-principal administration.
  • Managed and workload identities.
  • Role-Based Access Control (RBAC).
  • Privileged Identity Management (PIM) and Privileged Access Management (PAM).
  • Conditional Access and Multi-Factor Authentication (MFA).
  • SAML 2.0, OAuth 2.0 and OpenID Connect.
  • Single Sign-On and federated authentication.
  • Microsoft Azure and Microsoft 365 identity and access controls.
  • PowerShell, Microsoft Graph API or comparable automation technologies.
  • Certificate, secret and credential lifecycle management.
  • Identity governance, access reviews and entitlement management.
  • IT service management and formal change-management practices.
Desirable
  • Experience with IAM platforms such as Okta, Ping Identity, SailPoint, CyberArk or similar.
  • Experience with Identity Governance and Administration and PAM solutions.
  • Knowledge of financial-services regulatory and security-control frameworks.
  • Experience supporting identity-related audit, risk and compliance activities.
  • Exposure to cloud-security posture management and identity-threat detection.
  • Familiarity with DevOps, infrastructure-as-code and automated identity deployment.
  • Experience with Azure DevOps, GitHub or similar source-control and delivery platforms.
  • Knowledge of Microsoft Graph, REST APIs and workflow automation.
  • Experience designing or improving enterprise identity operating models.
  • Relevant Microsoft, security, cloud or IAM certifications.
Personal Attributes
  • Strong security and risk awareness with exceptional attention to detail.
  • Comfortable operating in a controlled and highly regulated environment.
  • Able to balance security, compliance, operational and user-experience requirements.
  • Proactive, accountable and committed to resolving issues through to completion.
  • Adaptable and comfortable contributing beyond a narrowly defined IAM remit.
  • Able to communicate complex identity concepts clearly to different audiences.
  • Calm and methodical when managing high-priority incidents.
  • Collaborative, dependable and committed to continuous improvement.
  • Confident in challenging requests or proposed solutions where security or control concerns exist.
ResponsibilitiesIdentity & Access Administration
  • Provision, modify and remove access across cloud and on-premises applications, platforms, infrastructure and data resources.
  • Administer user identities, security groups, roles, entitlements and related access controls.
  • Manage joiner, mover and leaver processes in line with approved policies.
  • Apply least-privilege, need-to-know and segregation-of-duties principles.
  • Review access requests for appropriate approvals and policy alignment.
  • Investigate and remediate excessive, conflicting, inappropriate or orphaned access.
  • Support access reviews, recertification and entitlement audits.
Service Account Management
  • Create, maintain and decommission service accounts across cloud and on-premises environments.
  • Ensure service accounts have documented ownership, purpose, dependencies and approved access.
  • Implement appropriate credential, password and authentication controls.
  • Identify and remediate inactive, unmanaged, shared or overprivileged service accounts.
  • Work with application and infrastructure teams to adopt managed identities and other secure alternatives where appropriate.
  • Maintain accurate service-account ownership and lifecycle records.
Service Principals & Application Identities
  • Manage service principals, enterprise applications, managed identities and other non-human identities.
  • Configure application permissions, API access and delegated permissions.
  • Assess security and operational risks associated with application-permission requests.
  • Manage certificates, secrets and credentials throughout their lifecycle.
  • Identify and remediate expired, unused, duplicated or overprivileged application credentials.
  • Support application teams with secure authentication and authorisation implementations.
  • Maintain clear records of application access, technical ownership, business ownership and dependencies.
Single Sign-On & Application Integration
  • Design, configure and support Single Sign-On integrations for enterprise applications.
  • Implement and troubleshoot SAML, OAuth 2.0, OpenID Connect, Kerberos and related authentication technologies.
  • Partner with application teams and vendors to gather requirements and deliver integrations.
  • Configure claims, attributes, group mappings, certificates, conditional-access requirements and user-assignment models.
  • Test authentication flows and coordinate implementations across development, test and production environments.
  • Develop implementation, testing, rollback and support documentation.
  • Troubleshoot complex federation, authentication and authorisation issues.
Incident & Service Request Management
  • Resolve IAM incidents and service requests within agreed service levels.
  • Investigate authentication failures, access issues, account lockouts, permission problems and identity-synchronisation errors.
  • Conduct root-cause analysis for recurring or high-impact incidents.
  • Coordinate critical identity incidents across security, infrastructure, application and vendor teams.
  • Maintain clear stakeholder communication throughout investigation and resolution.
  • Identify opportunities to automate repetitive requests and reduce recurring incidents.
  • Maintain accurate records within IT service-management platforms.
Identity Security & Governance
  • Apply IAM policies, standards and procedures consistently across the environment.
  • Support access-control requirements associated with financial-services regulation, internal risk frameworks and external audits.
  • Assist with privileged-access reviews, segregation-of-duties controls and access certifications.
  • Produce evidence and reporting for audit, risk, compliance and security teams.
  • Identify control weaknesses and recommend practical remediation actions.
  • Support investigations involving unauthorised access, compromised credentials or suspicious identity activity.
  • Ensure identity-related changes follow formal change-management and approval processes.
  • Contribute to identity standards, procedures and technical controls.
Platform Administration & Improvement
  • Administer and support enterprise identity platforms across cloud and on-premises environments.
  • Monitor identity synchronisation, authentication services, federation components and provisioning workflows.
  • Maintain the security, availability, performance and resilience of IAM services.
  • Develop scripting and automation to improve provisioning, reporting and administration.
  • Maintain technical documentation, support procedures, configuration records and knowledge articles.
  • Participate in identity-platform upgrades, migrations, enhancements and remediation programs.
  • Contribute to the organisation's IAM roadmap and identify opportunities to improve security, user experience, efficiency and control maturity.
Senior Technical Contribution
  • Provide technical guidance and mentoring to engineers and service-delivery teams.
  • Review technical designs, access models and proposed identity integrations.
  • Act as an escalation point for complex IAM issues.
  • Translate business, security and regulatory requirements into practical technical solutions.
  • Work independently on complex initiatives while collaborating across multidisciplinary teams.
  • Contribute to cloud adoption, application modernisation, security uplift and infrastructure-transformation projects.
  • Support adjacent security, cloud, infrastructure and operational responsibilities where required.
  • Adapt to emerging priorities and contribute beyond the immediate IAM function.
Measures of Success
  • Accurate and timely completion of access requests.
  • Reduction in recurring identity-related incidents.
  • Reliable and secure authentication services.
  • Effective management of service accounts, service principals and application identities.
  • Successful delivery of SSO and application integrations.
  • Increased automation and reduced manual administration.
  • Strong audit outcomes and timely remediation of access-control findings.
  • Accurate identity documentation and ownership records.
  • Positive collaboration with security, risk, application, infrastructure and business stakeholders.
  • Meaningful improvement in the organisation's identity-security maturity.
How we take care of our team

💰 Get paid in Australian Dollars
🏥 Medical insurance from day one for you + spouse (or parents if unmarried)
🩺 Generous OPD coverage from doctor visits to all your medical needs
🏡 Home office setup allowance to build your ideal workspace
🌐 Internet allowance to keep you connected
💪 Gym & wellness allowance to stay fit and balanced
🎉 Work hard, play hard – regular team events & engagement activities
🧠 Diji Assist – Mental health & counseling support when you need it
📚 We invest in you – reimbursement for industry certifications
🗣️ Open-door culture – your ideas and feedback always matter
🌍 Flexible work – home or office, wherever you do your best work
🏆 Rewards & recognition that actually recognize you
🥳 Great christmas & financial year-end parties to unwind with your loved ones


By applying for this role, your contact details will be securely stored in our candidate database. If you're not selected for this role, our Talent Acquisition Team may contact you regarding future opportunities that match your profile.Additionally, your email address will be automatically subscribed to our monthly newsletter, as well as special announcements such as upcoming webinars and events that we host. You may unsubscribe from these communications at any time by clicking the Unsubscribe link at the bottom of any of our emails.

Skills Required

  • Significant professional experience in Identity and Access Management or identity engineering
  • Experience supporting identity services within large, complex enterprise environments
  • Experience in banking, insurance, wealth management, payments or other regulated financial-services environments
  • Strong understanding of least privilege, segregation of duties and role-based access control
  • Hands-on administration of identities across cloud and on-premises environments
  • Experience managing service accounts, service principals, managed identities and non-human identities
  • Proven experience implementing and supporting Single Sign-On integrations
  • Troubleshooting authentication, authorization, federation and directory services
  • Experience working within formal incident, problem, request and change-management frameworks
  • Understanding of security, risk, audit and compliance requirements in regulated organisations
  • Ability to produce clear technical documentation, implementation plans, support procedures and audit evidence
  • Strong written and verbal communication and stakeholder collaboration skills
  • Relevant tertiary qualifications, industry certifications or equivalent practical experience
  • Experience with Microsoft Entra ID, Microsoft Active Directory and Group Policy
  • Experience with Conditional Access, MFA, RBAC, Privileged Identity Management and Privileged Access Management
  • Experience with SAML 2.0, OAuth 2.0, OpenID Connect, Kerberos and federated authentication
  • Experience with Microsoft Azure and Microsoft 365 identity and access controls
  • Experience with PowerShell, Microsoft Graph API or comparable automation technologies
  • Experience managing certificate, secret and credential lifecycle
  • Experience with identity governance, access reviews and entitlement management
  • Familiarity with IT service management and formal change-management practices
  • Experience with IAM platforms such as Okta, Ping Identity, SailPoint, CyberArk or similar
  • Experience with Identity Governance and Administration and PAM solutions
  • Knowledge of financial-services regulatory and security-control frameworks and audit support
  • Exposure to cloud-security posture management and identity-threat detection
  • Familiarity with DevOps, infrastructure-as-code and automated identity deployment
  • Experience with Azure DevOps, GitHub or similar source-control and delivery platforms
  • Knowledge of Microsoft Graph, REST APIs and workflow automation
  • Experience designing or improving enterprise identity operating models
  • Relevant Microsoft, security, cloud or IAM certifications (reimbursement available)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
302 Employees
Year Founded: 2023

What We Do

Dijital Team is an Australian IT services and consulting company that partners with MSPs and other IT businesses to reduce costs, scale capabilities, and improve operational maturity. It builds dedicated offshore teams in Sri Lanka and provides managed services such as software development, helpdesk support, data analytics, and IT operations. The company acts as an extension of clients’ businesses, supporting growth and profitability.

Similar Jobs

IFS Logo IFS

Senior Systems Engineer

Information Technology • Software
In-Office
Colombo, LKA
6788 Employees

Mastercard Logo Mastercard

Consultant

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Colombo, LKA
38800 Employees

Cin7 Logo Cin7

Customer Success Manager

Cloud • eCommerce • Logistics • Software
Easy Apply
Hybrid
Colombo, LKA
276 Employees

Cin7 Logo Cin7

Customer Success Specialist

Cloud • eCommerce • Logistics • Software
Easy Apply
Hybrid
Colombo, LKA
276 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account