Senior Identity Engineer
Job description
About the role
The Senior Identity Engineer is responsible for architecting and maintaining the foundational identity infrastructure that secures access across Sophos global operations. This role owns the strategic design and execution of identity architectures that underpin authentication, authorization, and compliance for all corporate platforms. You will define how digital identity appears and behaves across Sophos systems, ensuring alignment with security standards and frameworks. Working in concert with X-Ops experts, you will translate business requirements into robust identity workflows and governance models. A core part of this position involves analyzing complex identity challenges and devising scalable solutions that balance security with operational efficiency. You will act as a steward of identity integrity, implementing controls that safeguard privileged access and sensitive resources. This role demands a proactive mindset focused on continuous improvement and the reliable execution of identity lifecycle processes. By leveraging deep technical expertise, you will ensure that identity remains a resilient and verifiable control point within Sophos cybersecurity ecosystem.
Key facts
What you'll do
- Architect and implement scalable identity structures that support the global workforce using contemporary identity platforms and tools.
- Orchestrate the full joiner lifecycle across multiple directories, ensuring that access provisioning and deprovisioning adhere to strict security and compliance protocols.
- Document detailed workflows and operational procedures for identity management activities to provide clear guidance for internal stakeholders and support teams.
- Partner with external vendors and internal teams to harmonize third-party access management practices with Sophos internal guidelines and security policies.
- Establish and maintain support procedures for resolving authentication-related issues, minimizing user downtime and maintaining productivity.
- Conduct in-depth analysis of identity logs and security alerts to detect anomalous account behaviors and potential indicators of compromise.
- Propose actionable enhancements to identity controls and governance models based on insights gathered from operational monitoring and incident response.
- Validate identity configurations and access policies by rigorously testing new setups in isolated staging environments prior to production rollout.
- Collaborate with X-Ops and security teams to ensure identity solutions integrate seamlessly with broader security tooling and monitoring strategies.
- Drive standardization efforts across identity platforms, promoting best practices for identity lifecycle management and access governance.
- Evaluate emerging identity technologies and recommend integrations that improve security posture and streamline identity operations.
- Serve as a technical authority on identity matters, providing guidance and mentorship to cross-functional teams on identity-related initiatives.
- Monitor industry trends and regulatory requirements to ensure identity practices remain aligned with compliance obligations and security frameworks.
- Facilitate knowledge transfer and documentation to ensure continuity and clarity in identity processes for current and future team members.
Requirements
- Possess hands-on experience with passkeys and modern authentication mechanisms, demonstrating proficiency in implementing and managing these technologies.
- Have a background in identity governance administration processes, including the ability to manage access reviews and certification workflows.
- Show understanding of directory services, including architecture, administration, and integration with other systems.
- Demonstrate knowledge of certificate infrastructure, including issuance, renewal, and revocation processes within enterprise environments.
- Bring experience with identity threat detection and response concepts, applying frameworks such as IDRA to identify and mitigate risks.
- Exhibit familiarity with security operations monitoring specifically for identity issues, leveraging SIEM and other monitoring platforms.
- Understand access control models, including RBAC and ABAC, and have a history of implementing least privilege strategies effectively.
- Commit to adhering to established security policies and procedures, ensuring all identity activities comply with organizational standards.
Nice to have
- Hold preferred experience with modern identity platforms such as Azure AD, Okta, or similar solutions and their associated integrations.
- Have a track record of working with hybrid identity models that integrate on-premises and cloud environments.
- Demonstrate familiarity with SCIM protocols for automated user provisioning and lifecycle management.
- Possess knowledge of adaptive access and conditional access policies used to enforce risk-based authentication.
- Show exposure to identity federation and SSO implementations within complex enterprise ecosystems.
Practical notes
- Location is restricted to the United Kingdom.
- Engagement is a permanent position.
- Compensation is specified as an annual range of £70,000 to £90,000.