At a Glance
- Tasks: Enhance identity and privileged access security across platforms while collaborating with various teams.
- Company: Leading investment management firm focused on cybersecurity and innovation.
- Benefits: Competitive salary package, on-site work, and opportunities for professional growth.
- Other info: Ideal for tech-savvy individuals looking to advance their career in a regulated environment.
- Why this job: Join a dynamic team to strengthen security and make a real impact in the financial sector.
- Qualifications: 3-6 years in identity engineering or related roles, strong Microsoft Entra ID experience.
The predicted salary is between 140000 - 175000 € per year.
Role Overview
We’re representing a leading investment management firm seeking an Identity & Privileged Access Security Engineer to strengthen identity, authentication, and privileged access controls across the estate. Sitting within cybersecurity, the role focuses on reducing excessive admin rights, tightening identity-based attack paths, and ensuring privileged access remains effective in production. You’ll own key Microsoft identity capabilities - including Entra ID, Conditional Access, phishing-resistant MFA, privileged elevation, access reviews, and identity governance - in a hands‑on role that blends platform ownership, automation, and close collaboration with cloud, endpoint, and SecOps teams.
Key Responsibilities
- Operate and enhance privileged access controls across internal platforms, including elevation workflows, policy lifecycle management, audit validation, and resilience testing.
- Maintain and improve Microsoft Entra ID configuration across hybrid identity, external collaboration, authentication methods, and user lifecycle processes.
- Own Conditional Access controls, including device posture requirements, risky sign‑in handling, phishing‑resistant MFA enforcement, and exception governance.
- Run regular privileged access reviews across in-scope systems, identifying excessive permissions and driving remediation activity.
- Manage phishing‑resistant authentication processes, including hardware key enrolment, replacement workflows, recovery routes, and supplier coordination.
- Maintain admin tiering standards across privileged accounts, including naming conventions, lifecycle automation, stale account removal, and drift monitoring.
- Partner with cloud security teams on Azure RBAC, PIM activation patterns, and identity‑to‑resource permission models.
- Work with endpoint engineering teams to ensure Conditional Access policies align with device compliance and posture requirements.
- Collaborate with security operations to improve identity detections covering suspicious sign‑ins, token abuse, MFA fatigue, privileged account anomalies, and related attack patterns.
- Support identity protection for senior or high‑risk users, ensuring hardened authentication, monitoring, and access controls are consistently applied.
- Build PowerShell and Microsoft Graph automation to streamline joiner/mover/leaver processes, access reviews, privileged account management, and reporting.
What You’ll Bring…
- 3-6 years’ experience in identity engineering, IAM, privileged access management, or identity security roles.
- Strong hands‑on experience with Microsoft Entra ID in production environments, including hybrid identity, Entra Connect or Cloud Sync, B2B collaboration, and authentication method migration.
- Practical experience designing and operating Conditional Access policies across enterprise environments.
- Understanding of privileged access models, including Entra PIM, admin tiering, emergency access, JIT elevation, or comparable PAM tooling.
- Hands‑on exposure to Active Directory hardening, including delegation clean‑up, privileged group review, AdminSDHolder, ACL remediation, or Tier‑0 protection.
- Experience with phishing‑resistant authentication approaches such as FIDO2, WebAuthn, passkeys, or hardware security keys.
- Strong PowerShell capability and practical experience using Microsoft Graph for automation or reporting.
- Ability to assess over‑privilege, identify identity control gaps, and drive remediation with technical stakeholders.
- Strong academic background, including a degree from a Russell Group university or international equivalent (Preferred).
- Experience with identity governance platforms such as SailPoint, Saviynt, or Entra ID Governance (Preferred).
- Microsoft identity or security certifications such as SC-300 or SC-100 (Preferred).
- Background in financial services or another regulated environment with strong identity control and audit expectations.
Identity & Privileged Access Security Engineer | Technology-Driven Trading Firm in London employer: Techfellow Limited
Join a leading technology-driven trading firm that prioritises innovation and employee development. With a competitive compensation package of up to £175k, this on-site role offers a collaborative work culture where you can enhance your skills in identity and privileged access security while working alongside top-tier professionals in the financial services sector. The firm is committed to fostering growth through continuous learning opportunities and a supportive environment, making it an excellent choice for those seeking meaningful and rewarding employment.
StudySmarter Expert Advice🤫
We think this is how you could land Identity & Privileged Access Security Engineer | Technology-Driven Trading Firm in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in cybersecurity. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects related to identity engineering and privileged access management. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for those interviews! Research common questions related to Microsoft Entra ID and privileged access management. Practise your answers and be ready to discuss your hands-on experience in detail. Confidence is key!
✨Tip Number 4
Don’t forget to apply through our website! We’ve got some fantastic opportunities waiting for you. Tailor your application to highlight your relevant experience and skills, and let us help you land that dream job!
We think you need these skills to ace Identity & Privileged Access Security Engineer | Technology-Driven Trading Firm in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV speaks directly to the role. Highlight your experience with Microsoft Entra ID and any relevant identity security projects you've worked on. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about identity and privileged access security. Share specific examples of how you've tackled similar challenges in the past, and let us know why you want to join our team.
Show Off Your Technical Skills:Don’t hold back on showcasing your technical expertise! Mention your hands-on experience with PowerShell, Conditional Access policies, and any identity governance platforms you've used. We love seeing candidates who can hit the ground running!
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at Techfellow Limited
✨Know Your Stuff
Make sure you brush up on your knowledge of Microsoft Entra ID and its features. Be ready to discuss how you've used it in past roles, especially in relation to privileged access management and identity security. The more specific examples you can provide, the better!
✨Showcase Your Problem-Solving Skills
Prepare to talk about challenges you've faced in identity engineering or privileged access management. Think of a couple of scenarios where you identified over-privilege or gaps in identity controls and how you drove remediation. This will show your analytical skills and hands-on experience.
✨Get Familiar with Conditional Access
Since this role involves owning Conditional Access controls, be ready to explain your experience with designing and operating these policies. Discuss any specific methods you've implemented to enhance security and how they align with device compliance requirements.
✨Demonstrate Collaboration
This position requires close collaboration with various teams, so think of examples where you've worked with cloud security or endpoint engineering teams. Highlight how you communicated effectively and contributed to improving identity detections or access controls.