Principal Engineer - Identity Access Management in Reading

Principal Engineer - Identity Access Management in Reading

Reading Full-Time 70000 - 90000 £ / year (est.) No working from home possible
Elanco

At a Glance

  • Tasks: Lead technical delivery of identity transformation projects and mentor engineering teams.
  • Company: Join Elanco, a leader in innovative identity solutions with a collaborative culture.
  • Benefits: Enjoy a hybrid work environment, competitive salary, and opportunities for professional growth.
  • Other info: Diverse and inclusive workplace; apply even if you don't meet every requirement!
  • Why this job: Make a real impact on enterprise identity solutions while working with cutting-edge technology.
  • Qualifications: 10+ years in Identity & Access Management with expertise in Microsoft Entra ID and Active Directory.

The predicted salary is between 70000 - 90000 £ per year.

Principal Engineer - Identity Access Management

Elanco is seeking a highly skilled and experienced IAM Principal Engineer to provide technical leadership and architectural support for our enterprise hybrid identity architecture, authentication platforms, and workforce identity lifecycle management.

In this pivotal role, you will drive the technical execution of our Active Directory (AD), Microsoft Entra ID and Joiner‑Mover‑Leaver (JML) platforms through transformation projects, ensuring solutions are robust, secure, and aligned with the overarching architectural vision set by the client‑side Lead architect.

The role does not include direct people management; however, the Principal Engineer will be expected to provide technical leadership, mentoring and support for other Workplace engineers in the team.

Responsibilities

  • Lead the end‑to‑end technical delivery of the directory transformation program, converting target‑state architecture into detailed engineering designs, implementation patterns, and deployment runbooks.
  • Drive collaborative requirements gathering and joint design workshops with cross‑functional stakeholders to ensure identity solutions meet business, security, compliance, and operational needs.
  • Serve as the technical authority throughout the project lifecycle, assessing business and security requirements, guiding technology selection, mentoring engineering teams, and incorporating feedback from security operations and platform teams.
  • Define and validate technical requirements for Microsoft Entra ID and on‑premises directory integrations, partnering closely with information security, risk, infrastructure, architecture, and business units to ensure seamless interoperability.
  • Execute complex platform changes, including directory consolidation, domain modernization, tenant optimization, divestitures, and merger‑related identity platform integrations.
  • Contribute to enterprise technology strategies, architectural standards, and design principles, ensuring identity and directory services consistently support Elanco’s business and security objectives.
  • Design and support the deployment of Identity and Access Management (IAM) integrations, ensuring alignment with architectural standards, technical feasibility, and secure‑by‑design patterns.
  • Engage in the community (internally and externally) across multiple channels, looking to share, educate and inspire.
  • Establish strong partnerships across the architecture community and Information Security, helping to identify opportunities and mitigate risks.
  • Work with Information Security on the implementation of the Elanco security roadmap.
  • Serve on various forums to analyse projects and programs to ensure they are technically sound, will do no harm, and will deliver the expected outcomes.

Qualifications

  • 10+ years of progressive experience in Identity & Access Management, with at least 5 years focused on enterprise directory services and hybrid identity architectures across large, global organizations.
  • Expert‑level proficiency in Microsoft Entra ID and Active Directory, including architecture, design, federation, conditional access, Zero Trust enforcement, modern authentication protocols, and hands‑on engineering of complex identity environments.
  • Deep, practical understanding of IAM principles and security frameworks, including identity governance, authentication/authorization models, least privilege, Zero Trust, modern MFA strategies, and alignment with frameworks such as NIST, CIS, ISO 27001, and Microsoft’s identity security baseline.
  • Extensive experience with Joiner‑Mover‑Leaver (JML) lifecycle automation, preferably Workday‑driven, including identity provisioning, role mapping, automated access workflows, and governance controls across HR‑integrated identity platforms.
  • Demonstrated understanding of Privileged Access Management (PAM) solutions—preferably Delinea.
  • Proven leadership delivering large‑scale identity transformation initiatives, including directory consolidation, domain modernization, tenant‑to‑tenant migrations, and M&A or divestiture‑driven identity restructuring.
  • Strong technical mentoring capability, with a track record of guiding engineering teams, influencing architectural decisions, and driving high‑impact identity programs from concept to execution.
  • Exceptional communication and stakeholder engagement skills, capable of presenting complex identity concepts to executives, architects, security leaders, and engineering teams, while building consensus and steering technical direction.
  • Additional Information
  • Travel: 0‑10%

Don’t meet every single requirement?

Elanco is dedicated to building a diverse and inclusive work environment.

If you think you might be a good fit for this role but don’t necessarily meet every requirement, we encourage you to apply.

You may be the right candidate for this role or other roles!

Elanco is an EEO/Affirmative Action Employer and does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.

Elanco may use automated tools, including AI, to support parts of its recruitment process, such as reviewing applications against job‑related criteria and/or transferrable skills.

These tools help ensure a consistent, structured evaluation, but they do not make hiring decisions.

All decisions involve a human reviewer.

For more information on how we handle personal data, please see our Elanco Workforce Privacy Notice.

#J-18808-Ljbffr

Principal Engineer - Identity Access Management in Reading employer: Elanco

Elanco is an excellent employer that champions a diverse and inclusive workplace culture, making it an ideal environment for professionals seeking to make a meaningful impact in the field of quality control. Located in Liverpool, employees benefit from a collaborative atmosphere that encourages continuous improvement and offers ample opportunities for personal and professional growth, alongside the chance to engage in strategic initiatives across a global laboratory network.

Elanco

Contact Details:

Elanco Recruitment Team

We think you need these skills to ace Principal Engineer - Identity Access Management in Reading

Identity & Access Management (IAM)
Active Directory (AD)
Microsoft Entra ID
Joiner-Mover-Leaver (JML) lifecycle automation
Privileged Access Management (PAM)
Zero Trust enforcement
Modern authentication protocols