At a Glance
- Tasks: Lead the design and delivery of secure identity solutions for Tesco's digital workplace.
- Company: Join Tesco, a global leader in retail with a commitment to innovation and inclusivity.
- Benefits: Enjoy competitive pay, flexible working options, and opportunities for professional growth.
- Why this job: Make a real impact on identity technology while shaping the future of workplace solutions.
- Qualifications: Expertise in Active Directory, Azure AD, PKI, and authentication protocols required.
- Other info: Be part of a diverse team that values your unique contributions and promotes continuous improvement.
The predicted salary is between 60000 - 80000 £ per year.
This role sits within the workplace Identity team which is part of the Tesco Workplace Technology engineering team, part of a global engineering function delivering secure, scalable, and modern workplace solutions for Tesco colleagues. As a senior engineer and domain expert in Identity technologies, you will lead the full technology lifecycle - from strategy and design through to engineering, testing, and delivery - for the services that underpin our digital colleague experience.
Responsibilities
- Act as a senior engineer for Identity within the Workplace Technology team, setting the direction, roadmap, and architectural standards for core identity services including Active Directory, Entra ID, PKI, and modern authentication protocols.
- Align identity strategy to Tesco's broader digital workplace vision, collaborating closely with architects, product managers, security, and infrastructure teams.
- Stay ahead of market trends and emerging technologies in identity and access management, advocating for their adoption where beneficial.
- Design and deliver secure, scalable identity platforms that support global business needs and enable modern digital workplace capabilities.
- Engineer solutions across the identity lifecycle: concept, evaluation, prototyping, testing, production deployment, and service transition.
- Implement automation, codification (IaC), and integration with CI/CD practices to drive efficiency and resilience.
- Act as a senior escalation point for complex issues related to authentication, replication, certificate lifecycle, hybrid identity, and directory services.
- Build systems that are secure, stable, and easy to operate with monitoring, alerting, and lifecycle planning embedded by design.
- Champion remediation of legacy identity components and uplift the security and operational posture of all identity services.
- Ensure knowledge is well documented and transitions smoothly into operational support with clear SLAs and handover practices.
- Drive adoption of Zero Trust principles, secure admin tiering, modern auth standards, conditional access, and multifactor authentication.
- Own the health, design, and policy of PKI infrastructure and associated services (including certificate templates, CRLs, and HSMs).
- Work closely with the Security and Risk teams to ensure compliance with internal controls, regulatory obligations, and audit findings.
- Represent Workplace Technology Identity Engineering across Tesco Technology and into broader cross‑functional initiatives.
- Lead by example in engineering excellence, stakeholder engagement, and mentoring of less experienced engineers.
- Promote a culture of simplification, technical rigour, and continuous improvement.
- Ensure identity services are designed with built‑in resilience, supporting high availability, fault tolerance, and fast recovery across hybrid environments.
- Contribute to and maintain Business Continuity Plans (BCPs), ensuring critical identity components are documented with clear recovery priorities.
- Design and validate Disaster Recovery (DR) strategies for directory services, authentication systems, and PKI, with regular failover testing and documented RTO/RPO.
Qualifications
- Deep expertise in Active Directory: design, hardening, replication, domain controller lifecycle, GPOs, admin tiering.
- Deep expertise in Azure AD / Entra ID: hybrid identity, conditional access, MFA, identity protection, SSO, SCIM.
- Deep expertise in Public Key Infrastructure (PKI): policy, lifecycle, templates, automation, CRL/OCSP, HSMs.
- Deep expertise in Authentication protocols: OAuth2, OpenID Connect, SAML, Kerberos, NTLM, WS‑Fed.
- Demonstrated ability to design and deliver identity platforms in large, complex environments.
- Understanding of identity's role in enterprise security frameworks and compliance requirements.
- Proficiency with scripting and automation tools (PowerShell, Terraform, etc.).
- Familiar with monitoring, backup, recovery, and DR practices for identity systems.
Diversity & Inclusion
We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process.
Workplace Technology - Systems Engineer III employer: Tesco Plc
Contact Detail:
Tesco Plc Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Workplace Technology - Systems Engineer III
✨Tip Number 1
Network like a pro! Reach out to current employees at Tesco or in the workplace technology field. A friendly chat can give you insider info and might just lead to a referral.
✨Tip Number 2
Show off your skills! Prepare a portfolio or case studies that highlight your experience with identity technologies, especially around Active Directory and Azure AD. This will help you stand out during interviews.
✨Tip Number 3
Stay updated on trends! Keep an eye on the latest in identity and access management. Being able to discuss emerging technologies during your interview will show you're passionate and knowledgeable.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the Tesco team.
We think you need these skills to ace Workplace Technology - Systems Engineer III
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Workplace Technology role. Highlight your expertise in identity technologies and any relevant projects you've worked on, as this will show us you're a great fit for the team.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about identity technologies and how you can contribute to our mission at Tesco. Share specific examples of your past work that demonstrate your ability to lead and innovate in this space.
Showcase Your Technical Skills: Don’t forget to mention your deep expertise in Active Directory, Azure AD, and PKI in your application. We want to see how you’ve applied these skills in real-world scenarios, so be specific about your achievements and the impact they had.
Apply Through Our Website: We encourage you to apply directly through our website. This way, your application goes straight to us, and we can review it promptly. Plus, it’s the best way to ensure you’re considered for the role!
How to prepare for a job interview at Tesco Plc
✨Know Your Identity Tech Inside Out
Make sure you brush up on your knowledge of Active Directory, Azure AD, and PKI. Be ready to discuss how you've designed and delivered identity platforms in complex environments. This role is all about expertise, so show them you know your stuff!
✨Showcase Your Problem-Solving Skills
Prepare examples of complex issues you've tackled in the past, especially around authentication and directory services. They’ll want to see how you approach challenges, so think of specific scenarios where you’ve led the charge in finding solutions.
✨Align with Tesco's Vision
Familiarise yourself with Tesco's broader digital workplace vision and be ready to discuss how your identity strategy can align with it. Show that you understand their goals and how you can contribute to achieving them through innovative identity solutions.
✨Emphasise Collaboration and Mentorship
This role involves working closely with various teams, so highlight your experience in collaboration and mentoring. Share instances where you've engaged stakeholders or helped less experienced engineers grow, as this will resonate well with their team culture.