Senior Identity Management Engineer
CloudPay, Inc. Andover, Royaume-UniSenior Identity Management Engineer
CloudPay, Inc. Andover, Royaume-Uni
Senior Identity Management Engineer
About this job opportunity
Our Vision
To be the world's most trusted global payroll partner, simplifying pay for all employees.
Our Mission
Empowering global workforces with seamless, compliant, and innovative payroll and payment solutions, enabling businesses to thrive in a connected world.
Our People
Our fundamental beliefs at CloudPay are built on core values of professionalism, passion, empowerment, innovation, and teamwork. We value our employees and strive to create a great workplace where everyone is valued, heard, inspired, and encouraged to bring their authentic selves to work. We're committed to providing an excellent employee experience through fulfilling projects, empowerment to make a difference, and an environment that inspires innovation.
What makes this role exciting
This role balances high-level architectural vision with deep, hands-on technical execution. It is a critical role responsible for end-to-end delivery of our identity modernisation roadmap. The role is expected to define strategy and personally execute configuration, integration, and deployment of our identity fabric.
You will lead our Zero Trust transition by building and scaling identity infrastructure on ForgeRock Identity and Access Management (PingOne Advanced Identity Cloud), with future-state integration of IGA, PAM, and PIM capabilities as part of the roadmap. This role is for a technical leader who delivers results through direct engineering contribution, platform ownership, and technical mentorship.
Main responsibilities:
Roadmap delivery focus
Experience needed for this role:
About you and Our core values
United Kingdom Package and benefits
CloudPay is committed to being an equal opportunities employer. #LI-AC1 #LI-HIBRID #LI-REMOTE
The CloudPay culture is built upon on five core values, from which we develop our service, our technology and our business strategies. Our fundamental beliefs are a promise to our employees, customers and partners, built on the core values of professionalism, passion, empowerment, innovation, and teamwork.
Glassdoor
Our Vision
To be the world's most trusted global payroll partner, simplifying pay for all employees.
Our Mission
Empowering global workforces with seamless, compliant, and innovative payroll and payment solutions, enabling businesses to thrive in a connected world.
Our People
Our fundamental beliefs at CloudPay are built on core values of professionalism, passion, empowerment, innovation, and teamwork. We value our employees and strive to create a great workplace where everyone is valued, heard, inspired, and encouraged to bring their authentic selves to work. We're committed to providing an excellent employee experience through fulfilling projects, empowerment to make a difference, and an environment that inspires innovation.
What makes this role exciting
This role balances high-level architectural vision with deep, hands-on technical execution. It is a critical role responsible for end-to-end delivery of our identity modernisation roadmap. The role is expected to define strategy and personally execute configuration, integration, and deployment of our identity fabric.
You will lead our Zero Trust transition by building and scaling identity infrastructure on ForgeRock Identity and Access Management (PingOne Advanced Identity Cloud), with future-state integration of IGA, PAM, and PIM capabilities as part of the roadmap. This role is for a technical leader who delivers results through direct engineering contribution, platform ownership, and technical mentorship.
Main responsibilities:
- Lead configuration, optimisation, and operational maintenance of ForgeRock Identity and Access Management (PingOne Advanced Identity Cloud).
- Define and deliver ForgeRock deployment and platform strategy, including environment architecture, high availability and resilience design, and controlled release governance.
- Design, configure, and optimise user journeys across authentication, registration, recovery, and federation use cases.
- Build and evolve IAM CI/CD pipelines and promotion strategy for secure, repeatable rollout of configuration, code, and policy across environments.
- Establish and enhance monitoring and operational insights across authentication journeys, platform reliability, security event detection, and connector performance.
- Own configuration and customisation standards, including scripted nodes, journeys, policies, and reusable engineering patterns.
- Establish reusable integration patterns for SAML, OIDC, and OAuth2 across cloud and hybrid applications.
- Own end-to-end connector strategy and lifecycle for enterprise provisioning, reconciliation, and entitlement integration.
- Design, configure, and operate OpenICF connectors, including schema alignment, version governance, secure credential handling, and connector host integration.
- Build and maintain advanced mapping logic with correlation queries, transformation scripts, and policy-driven lifecycle actions.
- Operate scheduled reconciliation and LiveSync with environment-aware controls, clustered reconciliation support, and operational safeguards.
- Define technical standards through high-quality code, robust architecture patterns, and rigorous documentation.
- Act as an escalation point for complex IAM failures and protocol troubleshooting across SAML, OIDC, and OAuth2.
- Mentor junior and mid-level engineers through peer reviews, pairing, and structured technical coaching.
- Partner with security, platform, product, and engineering teams to deliver cross-functional IAM outcomes.
Roadmap delivery focus
- Deliver centralized IGA-driven joiner and leaver automation for internal users managed by Corporate IT.
- Define and govern authoritative identity rules and enterprise RBAC policies to enable immediate day-one access and precise, policy-aligned deprovisioning at exit.
- Replace fragmented, application-specific access controls with a single enterprise RBAC model across the CloudPay platform.
- Harmonise inconsistent access models across Payroll and Payments into a standardised, job-responsibility-based permission framework.
- Decouple access management from individual applications and integrate with IGA capabilities for automated provisioning and deprovisioning across CloudPay and connected third-party applications.
- Drive a phased rollout across third-party applications to reduce delivery risk while increasing automation coverage.
- Modernise foundational setup processes for company details, payrolls, and pay periods by removing monolithic and duplicated organisation setup across systems.
- Deliver a reimagined self-service UI and streamlined process flows for client administrators to manage access, payroll, and payment assignments directly.
- Reduce Tier 1 operational burden by replacing manual identity and role administration with policy-driven automation.
- Enforce least-privilege posture, improve access auditability, reduce orphaned account risk, and strengthen regulatory compliance.
Experience needed for this role:
- Experience: Solid hands-on engineering experience in IAM
- PingIdentity Mastery: Extensive hands-on experience deploying and managing PingFederate (SAML/OAuth/OIDC configurations), PingDirectory, and PingAccess (WAM/API security).
- Identity Modernisation: A proven track record of executing the migration of legacy identity systems to modern, claims-based architectures.
- Tooling & Governance: Direct experience configuring and integrating IGA tools (e.g. SailPoint, Saviynt) and PAM/PIM solutions to enforce the principle of least privilege.
- Protocol Expertise: Expert-level capability in debugging and configuring SAML, OIDC, OAuth2, and SCIM workflows.
- Core IAM Concepts: Strong understanding of RBAC, ABAC, Zero Trust architecture, and Directory Services (LDAP, Active Directory, Azure AD/Entra ID).
- PAM/PIM Knowledge: Proven experience implementing or managing PAM solutions (e.g., vaulting, session recording, password rotation) and PIM principles (role elevation, time-bound access).
- DevOps & Automation: Proficiency in scripting (Python, PowerShell, Bash) and Infrastructure as Code (Terraform, Ansible) to automate IAM deployments.
- Troubleshooting: Ability to analyze HTTP headers, trace logs (Fiddler, Wireshark), and identity telemetry to resolve complex authentication flow issues
- Builder Mindset: A strong preference for hands-on creation and a drive to see technical projects through to completion.
- Strategic Execution: The ability to understand the broader business objective and translate it into a functional, secure technical reality.
- Technical Rigour: A disciplined engineering approach that prioritises correct facts and industry standards over temporary workarounds.
- Certifications: Ping Identity Certified Professional (PingFederate/PingAccess), CISSP, CISM, or vendor-specific PAM certifications (e.g., CyberArk Defender).
- Cloud Identity: Extensive experience with cloud identity providers (Azure AD/Entra ID) and securing workloads in AWS, Azure, or GCP.
- Containerization: Experience deploying IAM solutions in Docker/Kubernetes environments.
About you and Our core values
- Taking ownership, working with integrity and respect
- Being a team player is key to our culture
- Solution and customer focused
- Great initiative with the goal for excellence in achieving results
- Dedicated to developing and always looking for continuous improvements
- Be creative, be committed, be engaged and enjoy what you do
United Kingdom Package and benefits
- Competitive Salary
- Competitive vacation allowance
- Calm app
- WFH Allowance
- Life Assurance
- Private Medical Insurance
- Cycle to Work Scheme
- EAP
- Eye Tests & Glasses Contribution
- Simplyhealth Enhanced Health Plan
- Pension Scheme
- Give-As-You-Earn (GAYE)
- Employee Referral Program
- CloudPay NOW
- Paid Volunteering days
- Marriage Leave
- Bereavement Leave
- Vacation Purchase Plan
CloudPay is committed to being an equal opportunities employer. #LI-AC1 #LI-HIBRID #LI-REMOTE
The CloudPay culture is built upon on five core values, from which we develop our service, our technology and our business strategies. Our fundamental beliefs are a promise to our employees, customers and partners, built on the core values of professionalism, passion, empowerment, innovation, and teamwork.
Glassdoor
Référence JR1001116
Plus d'offres de CloudPay, Inc.
CloudPay, Inc.
London, United Kingdom
CloudPay, Inc.
Andover, United Kingdom
CloudPay, Inc.
Andover, United Kingdom
CloudPay, Inc.
Quiapo District, Philippines
CloudPay, Inc.
Quiapo District, Philippines
CloudPay, Inc.
Quiapo District, Philippines
CloudPay, Inc.
Quiapo District, Philippines
Donnez un nouvel élan à votre carrière
Trouvez des milliers d'opportunités emploi en vous inscrivant sur eFinancialCareers dès aujourd'hui.Plus d'offres d'emploi