Senior Microsoft Identity Security Specialist

London, England, United Kingdom

Senior Microsoft Identity Security Specialist

  • 202605944
  • London, England, United Kingdom
  • Full time
View favourites

Description

The Senior Microsoft Identity Security Specialist will play a key role within the Global Information and Cyber Defence and Identity function, supporting the organisation's Microsoft-first identity security strategy through the design, implementation and optimisation of Microsoft Entra ID and related platforms.

The role will strengthen the organisation's identity security posture through Conditional Access, Identity Protection, Privileged Identity Management, password less authentication and Zero Trust-aligned controls. The role combines hands-on engineering with technical design, automation and continuous improvement, including the appropriate use of AI-assisted analysis to improve identity operations and security monitoring. This position follows a hybrid working model and is based in the London office. The successful candidate will be expected to attend the office when required to meet business and team requirements.

The Role:


Identity Platform Engineering

  • Contribute to the design, implementation, and optimisation of Microsoft Entra ID as the organisation's strategic identity platform.
  • Configure and enhance Conditional Access, Identity Protection, PIM and Just-in-Time access controls.
  • Support identity governance capabilities, including access reviews, entitlement management, Joiner-Mover-Leaver processes and role-based access control models.
  • Support workforce identities, external identities, application identities, managed identities and service principals.
  • Troubleshoot complex authentication, authorisation, federation and provisioning issues.

Authentication and Access Security

  • Support the adoption of phishing-resistant authentication, including FIDO2/passkeys, Windows Hello for Business, certificate-based authentication and hardware-backed credentials.
  • Implement and support Zero Trust identity controls across SaaS, cloud and enterprise applications.
  • Support secure application integration using OAuth 2.0, OpenID Connect and SAML.

Automation and Platform Enablement

  • Develop reusable pipelines, scripts and workflow automation for repeatable identity operations.
  • Create approved self-service patterns for activities such as application registration and enterprise application onboarding, using validation, approvals and audit logging to reduce direct administrative access.
  • Integrate identity standards and secure defaults into application-modernisation, CI/CD and infrastructure-as-code processes.
  • Automate routine activities such as configuration validation, certificate and secret-expiry monitoring, evidence collection and operational reporting.

AI-Assisted Operations and Security Monitoring

  • Identify and support practical uses of approved AI capabilities to improve the efficiency and quality of identity engineering and operations.
  • Use AI-assisted analysis and automation to help identify Conditional Access gaps, configuration drift, anomalous sign-ins, risky privilege activity, stale identities and excessive permissions.
  • Support identity-focused monitoring and signal correlation using Entra ID, Microsoft Defender, Log Analytics and Microsoft Sentinel.
  • Help define and apply approved identity controls to AI agents and agent identities, including ownership, least privilege, credential management, monitoring and lifecycle governance.
  • Ensure high-impact access, policy and remediation decisions retain appropriate human review and approval.

Threat Detection and Continuous Improvement

  • Support detection and remediation of identity threats including credential compromise, privilege escalation, token theft and suspicious authentication activity.
  • Collaborate with security operations teams to improve identity threat visibility, triage and response.
  • Contribute to technical designs, standards, documentation, operational procedures and control-effectiveness reporting.
  • Provide technical guidance and subject matter expertise relating to Microsoft identity technologies.

Qualifications

What you'll bring:

Required Skills and Experience:

  • Demonstrable recent, hands-on experience in Identity and Access Management, including substantial expertise in Microsoft Entra ID administration and security within complex enterprise environments.
  • Experience implementing and supporting Conditional Access, Identity Protection, PIM and Identity Governance.
  • Experience deploying and supporting passwordless and phishing-resistant authentication.
  • Strong understanding of OAuth 2.0, OpenID Connect, SAML and modern authentication protocols.
  • Experience with scripting and automation and familiarity with source control and deployment pipelines such as Azure DevOps or GitHub.
  • Understanding of Zero Trust, least privilege and identity-centric security controls.
  • Experience troubleshooting authentication and access issues in enterprise environments.
  • Ability to translate architecture and security standards into practical engineering solutions.
  • Strong communication, documentation and stakeholder-engagement skills.

 

Desirable Experience: 

  • Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security.
  • Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced workflow automation.
  • Experience using AI/ML or Agentic AI within security or identity operations.
  • Application registration, managed identity, service principal, workload identity, and secrets or certificate lifecycle governance.
  • Active Directory security, Entra Connect or Cloud Sync, and hybrid identity monitoring.
  • SailPoint identity governance or CyberArk privileged access and credential management.
  • AWS, Google Cloud Platform or Oracle Cloud Infrastructure identity and access management.
  • Relevant Microsoft Security, cloud or industry certifications such as CISSP or CCSP.

 

What We Offer

Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.

We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.

Equal Opportunity Employer

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com

Unsolicited Contact

Any unsolicited resumes/candidate profiles submitted through our web site or to personal e-mail accounts of employees of Willis Towers Watson are considered property of Willis Towers Watson and are not subject to payment of agency fees. In order to be an authorized Recruitment Agency/Search Firm for Willis Towers Watson, any such agency must have an existing formal written agreement signed by an authorized Willis Towers Watson recruiter and an active working relationship with the organization. Resumes must be submitted according to our candidate submission process, which includes being actively engaged on the particular search. Likewise, for our authorized Recruitment Agencies/Search Firms, if the candidate submission process is not followed, no agency fees will be paid by Willis Towers Watson. Willis Towers Watson is an equal opportunity employer. If you would like to have your contact information saved for future consideration, please email: Agency.inquiries@willistowerswatson.com.

Our Offices

Our colleagues serve more than 140 countries and markets around the world. This gives a global dimension to everything we do and creates lots of exciting opportunities for you to collaborate and grow. Explore the map below to see where you career could take you.