Senior Identity Management Engineer in Andover, Hampshire

Senior Identity Management Engineer in Andover, Hampshire

Andover +1 Full-Time No working from home possible
CloudPay

About this job opportunityOur VisionTo be the world's most trusted global payroll partner, simplifying pay for all employees.Our MissionEmpowering global workforces with seamless, compliant, and innovative payroll and payment solutions, enabling businesses to thrive in a connected world.Our PeopleOur fundamental beliefs at CloudPay are built on core values of professionalism, passion, empowerment, innovation, and teamwork. We value our employees and strive to create a great workplace where everyone is valued, heard, inspired, and encouraged to bring their authentic selves to work. We're committed to providing an excellent employee experience through fulfilling projects, empowerment to make a difference, and an environment that inspires innovation.What makes this role excitingThis role balances high-level architectural vision with deep, hands-on technical execution. It is a critical role responsible for end-to-end delivery of our identity modernisation roadmap. The role is expected to define strategy and personally execute configuration, integration, and deployment of our identity fabric. You will lead our Zero Trust transition by building and scaling identity infrastructure on ForgeRock Identity and Access Management (PingOne Advanced Identity Cloud), with future-state integration of IGA, PAM, and PIM capabilities as part of the roadmap. This role is for a technical leader who delivers results through direct engineering contribution, platform ownership, and technical mentorship. Main responsibilities:Lead configuration, optimisation, and operational maintenance of ForgeRock Identity and Access Management (PingOne Advanced Identity Cloud). Define and deliver ForgeRock deployment and platform strategy, including environment architecture, high availability and resilience design, and controlled release governance. Design, configure, and optimise user journeys across authentication, registration, recovery, and federation use cases. Build and evolve IAM CI/CD pipelines and promotion strategy for secure, repeatable rollout of configuration, code, and policy across environments. Establish and enhance monitoring and operational insights across authentication journeys, platform reliability, security event detection, and connector performance. Own configuration and customisation standards, including scripted nodes, journeys, policies, and reusable engineering patterns. Establish reusable integration patterns for SAML, OIDC, and OAuth2 across cloud and hybrid applications. Own end-to-end connector strategy and lifecycle for enterprise provisioning, reconciliation, and entitlement integration. Design, configure, and operate OpenICF connectors, including schema alignment, version governance, secure credential handling, and connector host integration. Build and maintain advanced mapping logic with correlation queries, transformation scripts, and policy-driven lifecycle actions. Operate scheduled reconciliation and LiveSync with environment-aware controls, clustered reconciliation support, and operational safeguards. Define technical standards through high-quality code, robust architecture patterns, and rigorous documentation. Act as an escalation point for complex IAM failures and protocol troubleshooting across SAML, OIDC, and OAuth2. Mentor junior and mid-level engineers through peer reviews, pairing, and structured technical coaching. Partner with security, platform, product, and engineering teams to deliver cross-functional IAM outcomes. Roadmap delivery focus Deliver centralized IGA-driven joiner and leaver automation for internal users managed by Corporate IT. Define and govern authoritative identity rules and enterprise RBAC policies to enable immediate day-one access and precise, policy-aligned deprovisioning at exit. Replace fragmented, application-specific access controls with a single enterprise RBAC model across the CloudPay platform. Harmonise inconsistent access models across Payroll and Payments into a standardised, job-responsibility-based permission framework. Decouple access management from individual applications and integrate with IGA capabilities for automated provisioning and deprovisioning across CloudPay and connected third-party applications. Drive a phased rollout across third-party applications to reduce delivery risk while increasing automation coverage. Modernise foundational setup processes for company details, payrolls, and pay periods by removing monolithic and duplicated organisation setup across systems. Deliver a reimagined self-service UI and streamlined process flows for client administrators to manage access, payroll, and payment assignments directly. Reduce Tier 1 operational burden by replacing manual identity and role administration with policy-driven automation. Enforce least-privilege posture, improve access auditability, reduce orphaned account risk, and strengthen regulatory compliance. Experience needed for this role:Experience: Solid hands-on engineering experience in IAMPingIdentity Mastery: Extensive hands-on experience deploying and managing PingFederate (SAML/OAuth/OIDC configurations), PingDirectory, and PingAccess (WAM/API security).Identity Modernisation: A proven track record of executing the migration of legacy identity systems to modern, claims-based architectures.Tooling & Governance: Direct experience configuring and integrating IGA tools (e.g. SailPoint, Saviynt) and PAM/PIM solutions to enforce the principle of least privilege.Protocol Expertise: Expert-level capability in debugging and configuring SAML, OIDC, OAuth2, and SCIM workflows.Core IAM Concepts: Strong understanding of RBAC, ABAC, Zero Trust architecture, and Directory Services (LDAP, Active Directory, Azure AD/Entra ID).PAM/PIM Knowledge: Proven experience implementing or managing PAM solutions (e.g., vaulting, session recording, password rotation) and PIM principles (role elevation, time-bound access).DevOps & Automation: Proficiency in scripting (Python, PowerShell, Bash) and Infrastructure as Code (Terraform, Ansible) to automate IAM deployments.Troubleshooting: Ability to analyze headers, trace logs (Fiddler, Wireshark), and identity telemetry to resolve complex authentication flow issuesCore CompetenciesBuilder Mindset: A strong preference for hands-on creation and a drive to see technical projects through to completion.Strategic Execution: The ability to understand the broader business objective and translate it into a functional, secure technical reality.Technical Rigour: A disciplined engineering approach that prioritises correct facts and industry standards over temporary workarounds.Preferred Qualifications:Certifications: Ping Identity Certified Professional (PingFederate/PingAccess), CISSP, CISM, or vendor-specific PAM certifications (e.g., CyberArk Defender).Cloud Identity: Extensive experience with cloud identity providers (Azure AD/Entra ID) and securing workloads in AWS, Azure, or GCP.Containerization: Experience deploying IAM solutions in Docker/Kubernetes environments.Languages: Excellent written and oral communication skills in English. About you and Our core valuesTaking ownership, working with integrity and respectBeing a team player is key to our cultureSolution and customer focusedGreat initiative with the goal for excellence in achieving resultsDedicated to developing and always looking for continuous improvementsBe creative, be committed, be engaged and enjoy what you doUnited Kingdom Package and benefitsCompetitive SalaryCompetitive vacation allowanceCalm appWFH AllowanceLife AssurancePrivate Medical InsuranceCycle to Work SchemeEAPEye Tests & Glasses ContributionSimplyhealth Enhanced Health PlanPension SchemeGive-As-You-Earn (GAYE)Employee Referral ProgramCloudPay NOWPaid Volunteering daysMarriage LeaveBereavement LeaveVacation Purchase PlanCloudPay is committed to being an equal opportunities employer. #LI-AC1 #LI-HIBRID #LI-REMOTEThe CloudPay culture is built upon on five core values, from which we develop our service, our technology and our business strategies. Our fundamental beliefs are a promise to our employees, customers and partners, built on the core values of professionalism, passion, empowerment, innovation, and teamwork.GlassdoorSummaryLocation: Andover, United Kingdom; Remote, UKType: Full time

Locations

AndoverHampshire

Senior Identity Management Engineer in Andover, Hampshire employer: CloudPay

CloudPay is an exceptional employer, offering a dynamic work environment in Spain or the UK where innovation meets collaboration. With a strong focus on employee growth and development, we provide competitive packages and benefits that reflect our commitment to fostering talent. Our inclusive culture encourages open communication and teamwork, ensuring that every team member plays a vital role in driving impactful technology initiatives that deliver real value to our customers.

CloudPay

Contact Details:

CloudPay Recruitment Team