Senior Microsoft Identity Security Specialist
London, England, United Kingdom
Senior Microsoft Identity Security Specialist
- 202605944
- London, England, United Kingdom
Description
The Senior Microsoft Identity Security Specialist will play a key role within the Global Information and Cyber Defence and Identity function, supporting the organisation's Microsoft-first identity security strategy through the design, implementation and optimisation of Microsoft Entra ID and related platforms.
The role will strengthen the organisation's identity security posture through Conditional Access, Identity Protection, Privileged Identity Management, password less authentication and Zero Trust-aligned controls. The role combines hands-on engineering with technical design, automation and continuous improvement, including the appropriate use of AI-assisted analysis to improve identity operations and security monitoring. This position follows a hybrid working model and is based in the London office. The successful candidate will be expected to attend the office when required to meet business and team requirements.
The Role:
Identity Platform Engineering
- Contribute to the design, implementation, and optimisation of Microsoft Entra ID as the organisation's strategic identity platform.
- Configure and enhance Conditional Access, Identity Protection, PIM and Just-in-Time access controls.
- Support identity governance capabilities, including access reviews, entitlement management, Joiner-Mover-Leaver processes and role-based access control models.
- Support workforce identities, external identities, application identities, managed identities and service principals.
- Troubleshoot complex authentication, authorisation, federation and provisioning issues.
Authentication and Access Security
- Support the adoption of phishing-resistant authentication, including FIDO2/passkeys, Windows Hello for Business, certificate-based authentication and hardware-backed credentials.
- Implement and support Zero Trust identity controls across SaaS, cloud and enterprise applications.
- Support secure application integration using OAuth 2.0, OpenID Connect and SAML.
Automation and Platform Enablement
- Develop reusable pipelines, scripts and workflow automation for repeatable identity operations.
- Create approved self-service patterns for activities such as application registration and enterprise application onboarding, using validation, approvals and audit logging to reduce direct administrative access.
- Integrate identity standards and secure defaults into application-modernisation, CI/CD and infrastructure-as-code processes.
- Automate routine activities such as configuration validation, certificate and secret-expiry monitoring, evidence collection and operational reporting.
AI-Assisted Operations and Security Monitoring
- Identify and support practical uses of approved AI capabilities to improve the efficiency and quality of identity engineering and operations.
- Use AI-assisted analysis and automation to help identify Conditional Access gaps, configuration drift, anomalous sign-ins, risky privilege activity, stale identities and excessive permissions.
- Support identity-focused monitoring and signal correlation using Entra ID, Microsoft Defender, Log Analytics and Microsoft Sentinel.
- Help define and apply approved identity controls to AI agents and agent identities, including ownership, least privilege, credential management, monitoring and lifecycle governance.
- Ensure high-impact access, policy and remediation decisions retain appropriate human review and approval.
Threat Detection and Continuous Improvement
- Support detection and remediation of identity threats including credential compromise, privilege escalation, token theft and suspicious authentication activity.
- Collaborate with security operations teams to improve identity threat visibility, triage and response.
- Contribute to technical designs, standards, documentation, operational procedures and control-effectiveness reporting.
- Provide technical guidance and subject matter expertise relating to Microsoft identity technologies.
Qualifications
What you'll bring:
Required Skills and Experience:
- Demonstrable recent, hands-on experience in Identity and Access Management, including substantial expertise in Microsoft Entra ID administration and security within complex enterprise environments.
- Experience implementing and supporting Conditional Access, Identity Protection, PIM and Identity Governance.
- Experience deploying and supporting passwordless and phishing-resistant authentication.
- Strong understanding of OAuth 2.0, OpenID Connect, SAML and modern authentication protocols.
- Experience with scripting and automation and familiarity with source control and deployment pipelines such as Azure DevOps or GitHub.
- Understanding of Zero Trust, least privilege and identity-centric security controls.
- Experience troubleshooting authentication and access issues in enterprise environments.
- Ability to translate architecture and security standards into practical engineering solutions.
- Strong communication, documentation and stakeholder-engagement skills.
Desirable Experience:
- Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security.
- Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced workflow automation.
- Experience using AI/ML or Agentic AI within security or identity operations.
- Application registration, managed identity, service principal, workload identity, and secrets or certificate lifecycle governance.
- Active Directory security, Entra Connect or Cloud Sync, and hybrid identity monitoring.
- SailPoint identity governance or CyberArk privileged access and credential management.
- AWS, Google Cloud Platform or Oracle Cloud Infrastructure identity and access management.
- Relevant Microsoft Security, cloud or industry certifications such as CISSP or CCSP.
What We Offer
Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.
We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.
Equal Opportunity Employer
We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com
D’autres internautes ont également consulté...
Contacts non sollicités
Tous les CV/profils de candidats non sollicités transmis via notre site web ou aux comptes e-mail personnels des employés de Willis Towers Watson sont considérés comme la propriété de Willis Towers Watson et ne sont pas soumis au paiement de frais d’agence. Afin d’agir en qualité d’agence/de cabinet de recrutement autorisé pour le compte de Willis Towers Watson, une telle agence doit disposer d’un contrat formel écrit, en vigueur et signé par un recruteur autorisé de Willis Towers Watson, et entretenir une relation de travail active avec l’entreprise. Les CV doivent être transmis conformément à notre processus de soumission des candidatures, lequel implique une participation active à la recherche en question. De même, pour nos agences/cabinets de recrutement autorisés, si le processus de soumission des candidatures n’est pas respecté, Willis Towers Watson ne versera pas de frais d’agence. Willis Towers Watson est un employeur qui défend l’égalité d’accès à l’emploi. Si vous souhaitez que nous conservions vos coordonnées pour une utilisation ultérieure, veuillez envoyer un e-mail à l’adresse Agency.inquiries@willistowerswatson.com .
Nos bureaux
Nos collaborateurs répondent aux besoins de clients répartis dans plus de 140 pays et marchés à travers le monde. Cela confère une dimension mondiale à tout ce que nous accomplissons, et vous permet de bénéficier de nombreuses opportunités palpitantes de collaboration et de développement professionnel. Explorez la carte ci-dessous pour découvrir où votre carrière pourrait vous mener.