The Role
We are seeking an Identity Operations Engineer to join our Identity and Access Management (IAM) Operations team. The successful candidate will be responsible for the day-to-day operational support of Active Directory, Microsoft Entra ID, Public Key Infrastructure (PKI), Application Registrations, and Single Sign-On (SSO) services.
This role will focus on identity lifecycle management, authentication and access support, certificate management, application onboarding, incident resolution, and operational monitoring to ensure the availability, security, and compliance of enterprise identity services.
Key Responsibilities
Active Directory (AD) Administration
Manage user, group, and computer accounts within Active Directory.
Perform user provisioning, deprovisioning, account modifications, and access changes.
Handle password resets, account unlocks, and authentication-related requests.
Manage security groups, distribution groups, and organizational units (OUs).
Support Group Policy administration and troubleshooting.
Assist in monitoring AD replication and Domain Controller health.
Analyze and troubleshoot AD-related incidents and service requests.
Microsoft Entra ID Administration
Administer Microsoft Entra ID users, groups, and identity-related configurations.
Support onboarding and offboarding activities across cloud and hybrid environments.
Troubleshoot sign-in issues, Multi-Factor Authentication (MFA), and Self-Service Password Reset (SSPR).
Monitor and investigate Entra ID sign-in logs, audit logs, and identity-related alerts.
Support Conditional Access policy troubleshooting and user access validation.
Monitor Entra Connect synchronization and escalate issues when required.
Conditional Access impact analysis.
Entra ID sign-in log investigation and Entra Connect synchronization troubleshooting.
PowerShell scripting and automation
Application Registration &Enterprise Applications
Create, manage, and maintain Application Registrations and Enterprise Application
support.
Support Enterprise Application onboarding and lifecycle management.
Configure and manag SSO integrations using SAML, OAuth 2.0, and OpenID Connect.
Manage application permissions, service principals, application secrets, and certificates.
Support application access requests and user/group assignments.
Troubleshoot authentication, authorization, and SSO-related issues.
Assist application owners with application onboarding and operational support.
Monitor application authentication logs and resolve access-related incidents.
PKI & Certificate Management
Perform certificate issuance, renewal, revocation, and lifecycle management activities.
Monitor certificate expiration and support proactive renewals.
Troubleshoot certificate enrollment and authentication issues.
Support Microsoft Certificate Services and enterprise PKI environments.
Maintain certificate documentation, inventories, and compliance records.
Coordinate certificate-based authentication support for applications and services.
Incident, Request & Change Management
Provide operational support within defined SLA and KPI targets.
Document troubleshooting activities, root cause findings, and resolutions.
Participate in change implementation and maintenance activities.
Maintain operational runbooks and knowledge base documentation.
Monitoring & Compliance
Monitor identity infrastructure, authentication services, and operational alerts.
Support audit and compliance requirements related to IAM services.
Participate in access reviews and governance activities.
Ensure adherence to security and operational standards.
Technical Skills
Active Directory Administration
Microsoft Entra ID (Azure AD)
Entra Connect / Cloud Sync
Multi-Factor Authentication (MFA)
Conditional Access
Self-Service Password Reset (SSPR)
PKI and Certificate Management
Microsoft Certificate Services
Application Registrations
Enterprise Applications
Single Sign-On (SSO)
OAuth 2.0, OpenID Connect, and SAML
Service Principals
Microsoft 365 Identity Services
ServiceNow or similar ITSM tools
Basic PowerShell scripting and automation
Essential Skills/Qualification/Experience:
Knowledge Areas
Identity and Access Management (IAM)
Authentication and Authorization Technologies
Security Best Practices
Incident, Change, and Problem Management Processes
Hybrid Identity Environments
Microsoft Certifications preferred:
Microsoft Certified: Identity and Access Administrator Associate (SC-300)
Microsoft Azure Fundamentals (AZ-900)
Microsoft 365 Fundamentals (MS-900)
Security, Compliance, and Identity Fundamentals (SC-900)
Good-to-Have:
Windows Server Administration and Infrastructure Operations.
Virtual Machine (VM) provisioning and management (VMware, Hyper-V, Azure).
Server patching, maintenance, and change management activities.
Vulnerability management and remediation support.
Networking fundamentals (DNS, DHCP, TCP/IP).
Ideal Candidate Profile:
A proactive identity operations professional with hands-on experience supporting Microsoft Active Directory, Entra ID, PKI, and Application Registration services in an enterprise environment. The candidate should possess strong troubleshooting skills, a security-first mindset, and the ability to work effectively in a fast-paced operations team supporting critical identity services.
Identity Operation Analyst or Engineer in Wokingham employer: Tcs Uk
As a Provisioning Engineer at our company, you will thrive in a dynamic work culture that prioritises innovation and collaboration. We offer competitive benefits, including professional development opportunities and a supportive environment that encourages growth in the rapidly evolving telecom sector. Located in a vibrant area, our team enjoys a balance of work and life, making it an excellent place for those seeking meaningful and rewarding employment.