National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Senior Security Engineer - IAM Focus | Strategic Financial Risk Solutions Firm

ZipRecruiter
London
1 week ago
Create job alert

Job Description

[Up to c. £225k Comp Package | Hybrid Working - 3 Days in Office]

We’re partnering with a market-defining pensions investment firm undertaking a major multi-year transformation of its technology and security stack. Backed by full executive sponsorship, they’re modernising cloud- architecture, overhauling their platforms, and embedding security engineering into every layer of infrastructure delivery. With responsibility for safeguarding over £65 billion in assets and millions of pension holders, this is a high-impact opportunity to shape the fabric of a business where your work will be operational, not theoretical - influencing every application, platform and access point across the estate...

Key Responsibilities

  • Lead design and hands-on delivery of secure & Access Management (IAM) capabilities across cloud- and SaaS platforms (AWS, Azure, internal systems)
  • Build scalable lifecycle workflows, including access provisioning, deprovisioning, RBAC/ABAC models, just-in-time access, and directory integrations
  • Automate governance processes via policy-as-code frameworks, IaC pipelines and audit/attestation tooling
  • Integrate IAM controls into CI/CD pipelines, infrastructure delivery, and developer workflows, ensuring consistent security guardrails from build to production
  • Partner with security architects, developers, and DevOps engineers to embed controls into broader security architecture design
  • Support secure federation and SSO integrations across SAML, OIDC, SCIM and modern authentication protocols
  • Translate regulatory and compliance needs into technical controls that balance security, usability and engineering agility
  • Continuously refine IAM capabilities in response to emerging threats, platform evolution, and business growth
  • Collaborate closely with leadership to provide governance oversight, reporting and risk visibility for -related access controls

What You’ll Bring...

  • 4-10 years’ experience in Security Engineering or Software Engineering roles, with 2+ years directly focused on IAM
  • Proven delivery of IAM capabilities within cloud- environments (AWS or Azure), including lifecycle and access governance
  • Practical knowledge of authentication and authorisation protocols including SAML, OIDC, OAuth2, SCIM, LDAP, and federated models
  • Hands-on experience with cloud- IAM tools such as AWS IAM, Azure AD, Okta, Saviynt or equivalent directory services
  • Strong automation skills across policy-as-code frameworks (OPA), infrastructure-as-code (Terraform), and CI/CD integration
  • Familiarity with Zero Trust architecture principles and evolving access control models
  • Solid understanding of security control frameworks such as NIST, ISO27001 or CIS Benchmarks, as they apply to access management
  • () Prior experience in financial services, risk management, pensions, or insurance industries
  • () Certifications such as CISSP, CCSP, or IAM/cloud-focused security qualifications

...


#J-18808-Ljbffr

Related Jobs

View all jobs

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.

How to Get a Better Cyber Security Job After a Lay-Off or Redundancy

Redundancy is never easy—especially in a fast-moving field like cyber security, where your skills and experience are constantly evolving. But if you’ve recently been made redundant from a cyber security role, know this: the UK cyber workforce remains in high demand, and your expertise is more valuable than ever. Whether you’re a SOC analyst, penetration tester, incident responder, security architect or GRC specialist, there are still thousands of opportunities across sectors including finance, defence, government, retail, and critical infrastructure. This guide will help you turn redundancy into a career relaunch, with a clear action plan tailored to the UK cyber security job market.