Damia Group are supporting a leading global technology organisation with the appointment of an experienced BeyondTrust Endpoint Privilege Management (EPM) Engineer. This is an exciting opportunity to join a large-scale, highly customised EPM environment operating within a secure enterprise setting. The successful candidate will work closely with Application Packaging, Endpoint Engineering and Security teams, providing expert-level administration, troubleshooting and policy engineering across the BeyondTrust EPM platform. Candidates with strong CyberArk Endpoint Privilege Manager experience will also be considered, particularly those with a strong endpoint security background who are willing to cross-train into BeyondTrust. Location: Inverness or Manchester Working Pattern: On-site within secure facilities Shift Pattern: 24x7 operational rota The Role You will play a key role in maintaining and developing a complex enterprise EPM environment, ensuring applications can be deployed securely while maintaining appropriate privilege and application control policies. Key Responsibilities Administer, support and maintain a highly customised BeyondTrust EPM environment. Design, implement and maintain policies covering privilege elevation, application control and allowlisting. Work closely with Application Packaging and Endpoint Engineering teams to support application deployment. Analyse application behaviour and identify appropriate privilege management requirements. Troubleshoot complex EPM issues affecting application deployment, endpoint security and user productivity. Develop, test and implement EPM policy changes while maintaining security and operational stability. Support the onboarding of new applications into the EPM environment. Investigate and resolve incidents relating to privilege elevation, application execution and endpoint control. Collaborate with packaging, infrastructure and security teams to ensure application compatibility. Carry out root cause analysis and implement appropriate remediation. Maintain technical documentation, procedures, support guides and policy standards. Contribute to continuous improvement and optimisation of the EPM platform. Participate in a 24x7 operational support rota, including out-of-hours support where required. Essential Skills & Experience Strong hands-on experience administering and engineering BeyondTrust Endpoint Privilege Management (EPM) . Strong understanding of Windows endpoint security architecture . Proven experience creating, modifying and troubleshooting BeyondTrust EPM policies. Experience supporting application packaging and software deployment . Strong knowledge of: Windows Desktop Operating Systems Application Control Privilege Elevation Endpoint Security Software Packaging & Deployment Group Policy Administration Ability to assess application requirements and develop appropriate privilege management solutions. Experience working with highly customised enterprise EPM environments. Excellent troubleshooting and root cause analysis capabilities. Experience working within secure, controlled or highly regulated environments. Strong technical documentation and communication skills. Ability to work independently within a complex operational environment. Desirable Skills CyberArk Endpoint Privilege Manager experience. Experience migrating between EPM platforms. Microsoft Intune, MECM/SCCM or equivalent endpoint management experience. PowerShell scripting and automation. Experience supporting large-scale enterprise endpoint environments. ITIL-based operational experience. Previous experience working within secure facilities or restricted-access environments. Please note: Candidates must be able to work on-site from either Inverness or Manchester and be willing to participate in a 24x7 support rota . Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
Aug 24, 2026
Contractor
Damia Group are supporting a leading global technology organisation with the appointment of an experienced BeyondTrust Endpoint Privilege Management (EPM) Engineer. This is an exciting opportunity to join a large-scale, highly customised EPM environment operating within a secure enterprise setting. The successful candidate will work closely with Application Packaging, Endpoint Engineering and Security teams, providing expert-level administration, troubleshooting and policy engineering across the BeyondTrust EPM platform. Candidates with strong CyberArk Endpoint Privilege Manager experience will also be considered, particularly those with a strong endpoint security background who are willing to cross-train into BeyondTrust. Location: Inverness or Manchester Working Pattern: On-site within secure facilities Shift Pattern: 24x7 operational rota The Role You will play a key role in maintaining and developing a complex enterprise EPM environment, ensuring applications can be deployed securely while maintaining appropriate privilege and application control policies. Key Responsibilities Administer, support and maintain a highly customised BeyondTrust EPM environment. Design, implement and maintain policies covering privilege elevation, application control and allowlisting. Work closely with Application Packaging and Endpoint Engineering teams to support application deployment. Analyse application behaviour and identify appropriate privilege management requirements. Troubleshoot complex EPM issues affecting application deployment, endpoint security and user productivity. Develop, test and implement EPM policy changes while maintaining security and operational stability. Support the onboarding of new applications into the EPM environment. Investigate and resolve incidents relating to privilege elevation, application execution and endpoint control. Collaborate with packaging, infrastructure and security teams to ensure application compatibility. Carry out root cause analysis and implement appropriate remediation. Maintain technical documentation, procedures, support guides and policy standards. Contribute to continuous improvement and optimisation of the EPM platform. Participate in a 24x7 operational support rota, including out-of-hours support where required. Essential Skills & Experience Strong hands-on experience administering and engineering BeyondTrust Endpoint Privilege Management (EPM) . Strong understanding of Windows endpoint security architecture . Proven experience creating, modifying and troubleshooting BeyondTrust EPM policies. Experience supporting application packaging and software deployment . Strong knowledge of: Windows Desktop Operating Systems Application Control Privilege Elevation Endpoint Security Software Packaging & Deployment Group Policy Administration Ability to assess application requirements and develop appropriate privilege management solutions. Experience working with highly customised enterprise EPM environments. Excellent troubleshooting and root cause analysis capabilities. Experience working within secure, controlled or highly regulated environments. Strong technical documentation and communication skills. Ability to work independently within a complex operational environment. Desirable Skills CyberArk Endpoint Privilege Manager experience. Experience migrating between EPM platforms. Microsoft Intune, MECM/SCCM or equivalent endpoint management experience. PowerShell scripting and automation. Experience supporting large-scale enterprise endpoint environments. ITIL-based operational experience. Previous experience working within secure facilities or restricted-access environments. Please note: Candidates must be able to work on-site from either Inverness or Manchester and be willing to participate in a 24x7 support rota . Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website. Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job. Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds. Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
May 29, 2026
Full time
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
May 29, 2026
Full time
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
May 21, 2026
Full time
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
May 21, 2026
Full time
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments. Responsibilities: Own the end to end technical delivery of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available. Lead design sessions, collaborating with Entrprise Architecture, and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities. Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services. Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives. Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms. Lead modernization initiatives. Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps. Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement. What You'll Bring 10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms. Deep expertise with the majority of our IAM stack Strong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2). Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models. Experience with secrets management solutions. Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools. Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders. Exceptional sense of ownership and the ability to work with a limited set of requirements. Highly advanced ability to breakdown work to deliver value incrementally. Experience leading large-scale IAM programs. Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines. Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity Oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security. Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews. Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite. Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery. Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems. Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations. Develop and implement automated provisioning/deprovisioning workflows Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications. Mentor and develop the skills of senior security engineers, fostering a culture of continuous improvement and innovation. Technical Experience Must-Have: Privileged Access management (CyberArk) Authentication/AuthN (Okta) Federated Identity (EntraID) Cloud Identity (AWS, GCP, Azure) Automation (terraform, codex, claude) Application SSO (OIDC, SAML) Identity Governance (Sailpoint, Okta, Veza) Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk SME on a contract basis. Hybrid working - London based (1 day per week onsite). June 2026 start through to the end of 2026. Role The CyberArk SME will plan, test, and implement major CyberArk platform releases and upgrades, including annual version upgrades (e.g. 14.x to 15.x). Plan, test, and implement monthly operating system patching for CyberArk Vault servers in line with internal patching schedules. Test and coordinate monthly patching activities across CyberArk underlying infrastructure with internal infrastructure and patching teams. Deploy CyberArk security patches to remediate critical vulnerabilities identified in CyberArk advisories. Maintain existing CyberArk integrations including SCIM integration with Saviynt and telemetry integration with Power BI. Support and maintain existing deployed CyberArk connectors and collaborate with permanent teams to deliver configuration changes and onboarding activities. Create up to 10 custom CPM and PSM connectors annually to support new platforms and applications. Drive the adoption and embeddedness of CyberArk controls across the organisation. Utilise CyberArk Discovery, PTA, Splunk dashboards, CrowdStrike, Saviynt and other repositories to identify privileged accounts not currently under CyberArk management. Produce monthly metrics and reporting covering privileged account coverage across CMDB assets, Active Directory, and LDAP environments. Drive BAU onboarding activities to close identified gaps across existing platform types. Create detailed technical documentation including HLDs, LLDs, Safe Design documents, Runbooks, Test Plans and BAU handover documentation. Deploy and integrate CyberArk CP/CCP platforms into pre-production and production environments. Install and configure CP agents on PoC and candidate servers. Define and deploy processes for end-to-end SSH key lifecycle management including rotation. Create and manage Safes, Platforms and application authentication configurations within CyberArk. Conduct discovery and assessment activities for application service accounts, SSH keys, certificates, and secrets across production and pre-production environments. Define remediation and treatment plans for secrets management including CP/CCP adoption, PKI, mTLS and SPIFFE approaches. Deliver monitoring, hypercare, prioritisation, and remediation planning activities for secrets onboarding initiatives. Profile The CyberArk SME will have strong experience administering and engineering CyberArk PAM solutions within enterprise-scale environments. Expert-level knowledge of CyberArk components including Vault, CPM, PSM, CP, CCP, PTA and Discovery. Experience planning and delivering CyberArk upgrades, patching, and vulnerability remediation activities. Strong understanding of privileged access management, secrets management, SSH key management, and certificate-based authentication. Experience integrating CyberArk with enterprise tooling including Saviynt, Splunk, CrowdStrike, Power BI, Active Directory and LDAP. Proven experience creating custom CPM and PSM connectors. Strong knowledge of Linux and Windows server administration and infrastructure patching processes. Experience producing technical documentation including HLDs, LLDs, test plans and operational runbooks. Excellent stakeholder engagement and communication skills with the ability to collaborate across technical and business teams. CyberArk Sentry certification or above highly desirable. Company Market leading financial services organisation with offices in London Hybrid working - 1 day per week onsite Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training. Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
May 21, 2026
Contractor
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk SME on a contract basis. Hybrid working - London based (1 day per week onsite). June 2026 start through to the end of 2026. Role The CyberArk SME will plan, test, and implement major CyberArk platform releases and upgrades, including annual version upgrades (e.g. 14.x to 15.x). Plan, test, and implement monthly operating system patching for CyberArk Vault servers in line with internal patching schedules. Test and coordinate monthly patching activities across CyberArk underlying infrastructure with internal infrastructure and patching teams. Deploy CyberArk security patches to remediate critical vulnerabilities identified in CyberArk advisories. Maintain existing CyberArk integrations including SCIM integration with Saviynt and telemetry integration with Power BI. Support and maintain existing deployed CyberArk connectors and collaborate with permanent teams to deliver configuration changes and onboarding activities. Create up to 10 custom CPM and PSM connectors annually to support new platforms and applications. Drive the adoption and embeddedness of CyberArk controls across the organisation. Utilise CyberArk Discovery, PTA, Splunk dashboards, CrowdStrike, Saviynt and other repositories to identify privileged accounts not currently under CyberArk management. Produce monthly metrics and reporting covering privileged account coverage across CMDB assets, Active Directory, and LDAP environments. Drive BAU onboarding activities to close identified gaps across existing platform types. Create detailed technical documentation including HLDs, LLDs, Safe Design documents, Runbooks, Test Plans and BAU handover documentation. Deploy and integrate CyberArk CP/CCP platforms into pre-production and production environments. Install and configure CP agents on PoC and candidate servers. Define and deploy processes for end-to-end SSH key lifecycle management including rotation. Create and manage Safes, Platforms and application authentication configurations within CyberArk. Conduct discovery and assessment activities for application service accounts, SSH keys, certificates, and secrets across production and pre-production environments. Define remediation and treatment plans for secrets management including CP/CCP adoption, PKI, mTLS and SPIFFE approaches. Deliver monitoring, hypercare, prioritisation, and remediation planning activities for secrets onboarding initiatives. Profile The CyberArk SME will have strong experience administering and engineering CyberArk PAM solutions within enterprise-scale environments. Expert-level knowledge of CyberArk components including Vault, CPM, PSM, CP, CCP, PTA and Discovery. Experience planning and delivering CyberArk upgrades, patching, and vulnerability remediation activities. Strong understanding of privileged access management, secrets management, SSH key management, and certificate-based authentication. Experience integrating CyberArk with enterprise tooling including Saviynt, Splunk, CrowdStrike, Power BI, Active Directory and LDAP. Proven experience creating custom CPM and PSM connectors. Strong knowledge of Linux and Windows server administration and infrastructure patching processes. Experience producing technical documentation including HLDs, LLDs, test plans and operational runbooks. Excellent stakeholder engagement and communication skills with the ability to collaborate across technical and business teams. CyberArk Sentry certification or above highly desirable. Company Market leading financial services organisation with offices in London Hybrid working - 1 day per week onsite Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training. Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk Privilege Cloud Architect on an initial 6 month contract basis. Hybrid working - London based CyberArk Privilege Cloud Architect to join a major enterprise security transformation programme within a complex financial services environment. This is a high-impact role requiring deep CyberArk product expertise across modern Privilege Cloud shared services architecture and multi-cloud deployments. Role Leading architecture and deployment activities across CyberArk Privilege Cloud environments Designing and implementing Secure Cloud Access (SCA) and Secure Infrastructure Access (SIA) capabilities Supporting enterprise-scale PAM transformation initiatives across multi-cloud environments Working closely with security engineering, infrastructure, cloud, and platform teams Driving best practice architecture across modern CyberArk shared services deployments Supporting governance, integration, scalability, resilience, and operational security requirements Profile Strong hands-on CyberArk Architecture experience within enterprise environments Proven Privilege Cloud CDE experience Demonstrable experience deploying SCA and SIA solutions Strong multi-cloud deployment experience (AWS / Azure / GCP) Experience deploying ISPSS (shared services platform) environments rather than legacy standalone Privilege Cloud setups Strong stakeholder engagement and technical leadership capability Financial Services / regulated environment experience Desirable / Nice to Have CyberArk Guardian Certification Experience working within large-scale global transformation programmes Company Market leading financial services organisation 6 month initial contract Hybrid working - London based Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training . Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
May 20, 2026
Contractor
Robert Half Technology are assisting a market leading financial services organisation to recruit a CyberArk Privilege Cloud Architect on an initial 6 month contract basis. Hybrid working - London based CyberArk Privilege Cloud Architect to join a major enterprise security transformation programme within a complex financial services environment. This is a high-impact role requiring deep CyberArk product expertise across modern Privilege Cloud shared services architecture and multi-cloud deployments. Role Leading architecture and deployment activities across CyberArk Privilege Cloud environments Designing and implementing Secure Cloud Access (SCA) and Secure Infrastructure Access (SIA) capabilities Supporting enterprise-scale PAM transformation initiatives across multi-cloud environments Working closely with security engineering, infrastructure, cloud, and platform teams Driving best practice architecture across modern CyberArk shared services deployments Supporting governance, integration, scalability, resilience, and operational security requirements Profile Strong hands-on CyberArk Architecture experience within enterprise environments Proven Privilege Cloud CDE experience Demonstrable experience deploying SCA and SIA solutions Strong multi-cloud deployment experience (AWS / Azure / GCP) Experience deploying ISPSS (shared services platform) environments rather than legacy standalone Privilege Cloud setups Strong stakeholder engagement and technical leadership capability Financial Services / regulated environment experience Desirable / Nice to Have CyberArk Guardian Certification Experience working within large-scale global transformation programmes Company Market leading financial services organisation 6 month initial contract Hybrid working - London based Salary & Benefits The salary range/rates of pay is dependent upon your experience, qualifications or training . Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to diversity, equity and inclusion. Suitable candidates with equivalent qualifications and more or less experience can apply. Rates of pay and salary ranges are dependent upon your experience, qualifications and training. If you wish to apply, please read our Privacy Notice describing how we may process, disclose and store your personal data:
Endpoint Security Engineer - Endpoint Privilege Management (EPM) - Application control - Policies - Engineering Chester, 12 months+ contract Hybrid working Leading financial services client is seeking an accomplished Endpoint Security Engineer to join them on a contract basis. You will contribute to a cloud migration project (AWS and Azure), designing and implementing advanced endpoint security solutions. This is an excellent opportunity to join the platform engineering team within a global banking environment. Skills and experience required: Demonstrated experience in endpoint security, across both engineering and support capacities. Strong expertise in Application Control, ideally with BeyondTrust solutions (similar tools will suffice ie CyberArk, etc) Advanced understanding of Windows Operating Systems Proficiency in scripting PowerShell and Python - desirable Experience with Trellix ePO, BeyondTrust EPM Cloud, and policy management in Azure and AWS environments desirable If this is of interest and you have the required skills, please submit your CV over for immediate consideration. McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.
May 16, 2026
Contractor
Endpoint Security Engineer - Endpoint Privilege Management (EPM) - Application control - Policies - Engineering Chester, 12 months+ contract Hybrid working Leading financial services client is seeking an accomplished Endpoint Security Engineer to join them on a contract basis. You will contribute to a cloud migration project (AWS and Azure), designing and implementing advanced endpoint security solutions. This is an excellent opportunity to join the platform engineering team within a global banking environment. Skills and experience required: Demonstrated experience in endpoint security, across both engineering and support capacities. Strong expertise in Application Control, ideally with BeyondTrust solutions (similar tools will suffice ie CyberArk, etc) Advanced understanding of Windows Operating Systems Proficiency in scripting PowerShell and Python - desirable Experience with Trellix ePO, BeyondTrust EPM Cloud, and policy management in Azure and AWS environments desirable If this is of interest and you have the required skills, please submit your CV over for immediate consideration. McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.
Cyber Security Engineer Day Rate: £500 - £550 per Day (Outside IR35) Duration: 3 Months + Likely Extension Location: London (hybrid working) My client is a rapidly growing global organisation offering a range of services to the Professional Services sector globally. They are recruiting for an experienced hands-on Cyber Security Contractor to support their security operations and compliance initiatives, working closely with their internal Security team to strengthen their cyber resilience and ensure adherence to UK standards. Key Duties: Implement, manage and actively monitor security controls across e-mail, endpoint, and cloud environments Monitor and respond to security incidents using advanced threat detection tools Assist with compliance activities and audits for ISO27001, Cyber Essentials & Cyber Essentials Plus certification Provide technical expertise on security best practices and risk mitigation Collaborate with IT and business teams to ensure secure configuration and data protection Respond to security related DDQs Mimecast, Netskope and CyberArk configuration and administration The Person: Experience of running tech projects end-to-end Proven experience of complete start-to-finish implementation and certification for Cyber Essentials and Cyber Essential Plus Hands-on experience of CyberArk spanning deployment, config, and on-going administration Experience of Netskope as the appointed person will lead the roll-out across their global office network Solid working knowledge and experience of Mimecast required Exposure to Microsoft Purview An appreciation of ISO 27001 and its requirements Strong understanding of UK cyber security regulations and frameworks The role is based at their London HQ, offering hybrid working with 2-3 days in the office per week. Due to the high volume of applications we receive, we are unable to contact every candidate individually. If you do not hear from us within 7 days of submitting your application, please assume that you have not been shortlisted on this occasion. We are committed to fair, consistent, and inclusive recruitment practices, and all applications are reviewed in line with relevant employment legislation and our equal opportunities principles. GEM Partnership is acting as an employment agency on this vacancy.
May 14, 2026
Contractor
Cyber Security Engineer Day Rate: £500 - £550 per Day (Outside IR35) Duration: 3 Months + Likely Extension Location: London (hybrid working) My client is a rapidly growing global organisation offering a range of services to the Professional Services sector globally. They are recruiting for an experienced hands-on Cyber Security Contractor to support their security operations and compliance initiatives, working closely with their internal Security team to strengthen their cyber resilience and ensure adherence to UK standards. Key Duties: Implement, manage and actively monitor security controls across e-mail, endpoint, and cloud environments Monitor and respond to security incidents using advanced threat detection tools Assist with compliance activities and audits for ISO27001, Cyber Essentials & Cyber Essentials Plus certification Provide technical expertise on security best practices and risk mitigation Collaborate with IT and business teams to ensure secure configuration and data protection Respond to security related DDQs Mimecast, Netskope and CyberArk configuration and administration The Person: Experience of running tech projects end-to-end Proven experience of complete start-to-finish implementation and certification for Cyber Essentials and Cyber Essential Plus Hands-on experience of CyberArk spanning deployment, config, and on-going administration Experience of Netskope as the appointed person will lead the roll-out across their global office network Solid working knowledge and experience of Mimecast required Exposure to Microsoft Purview An appreciation of ISO 27001 and its requirements Strong understanding of UK cyber security regulations and frameworks The role is based at their London HQ, offering hybrid working with 2-3 days in the office per week. Due to the high volume of applications we receive, we are unable to contact every candidate individually. If you do not hear from us within 7 days of submitting your application, please assume that you have not been shortlisted on this occasion. We are committed to fair, consistent, and inclusive recruitment practices, and all applications are reviewed in line with relevant employment legislation and our equal opportunities principles. GEM Partnership is acting as an employment agency on this vacancy.
IAM Security Architect Permanent - Up to £120k + benefits Location: Hybrid - Cambridge Your new company: A NASDAQ listed semiconductor organisation in the UK is currently looking for an IAM Security Architect to join their ranks. The organisation is very well known in their world and offers strong benefits and hybrid working, as well as share options in the company. The role responsibilities: You'll play a big role in architecting and designing the organisations zero trust IAM infrastructure and policies, as well as guiding the strategy behind how they secure their global workforce. You'll work across IT and Security to define, design, and integrate. Some of the main elements of your roles, in the clients' words: Lead the design and implementation of enterprise Zero Trust IAM architecture across AD, Entra ID, SSO, MFA, PAM, and PKI. Create and maintain Zero Trust IAM security roadmaps, patterns, and reference designs. Supporting and partner with IT, GRC, and Engineering teams to ensure compliance and security standard processes. Evaluate and integrate new identity tools, authentication platforms and access capabilities. Drive continuous improvement through risk assessments, threat modelling, and automation. You will need: Strong practical experience in designing and running Identity and Access Management (IAM) solutions within large-scale, complex environments. Deep knowledge of identity protocols (SAML, OAuth2, OIDC, SCIM, LDAP/AD, PKI). Strong zero trust mindset. Expertise in at least two IAM product areas such as Okta, CyberArk, Ping, or preferably Microsoft Entra ID. Ability to define standards, partner cross-functionally (IT, GRC, Engineering), and drive risk reduction through threat modelling, compliance (NIST, ISO, GDPR), and ongoing optimisation of identity systems. Experience working with cloud identity (Azure, AWS, or GCP). What you'll get in return: This role is available for hybrid working with a typical requirement to work 2 days per week in the Cambridge office. Strong salary with decent benefits. 7% pension - employers contribution PMI and dental Share options. And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
May 12, 2026
Full time
IAM Security Architect Permanent - Up to £120k + benefits Location: Hybrid - Cambridge Your new company: A NASDAQ listed semiconductor organisation in the UK is currently looking for an IAM Security Architect to join their ranks. The organisation is very well known in their world and offers strong benefits and hybrid working, as well as share options in the company. The role responsibilities: You'll play a big role in architecting and designing the organisations zero trust IAM infrastructure and policies, as well as guiding the strategy behind how they secure their global workforce. You'll work across IT and Security to define, design, and integrate. Some of the main elements of your roles, in the clients' words: Lead the design and implementation of enterprise Zero Trust IAM architecture across AD, Entra ID, SSO, MFA, PAM, and PKI. Create and maintain Zero Trust IAM security roadmaps, patterns, and reference designs. Supporting and partner with IT, GRC, and Engineering teams to ensure compliance and security standard processes. Evaluate and integrate new identity tools, authentication platforms and access capabilities. Drive continuous improvement through risk assessments, threat modelling, and automation. You will need: Strong practical experience in designing and running Identity and Access Management (IAM) solutions within large-scale, complex environments. Deep knowledge of identity protocols (SAML, OAuth2, OIDC, SCIM, LDAP/AD, PKI). Strong zero trust mindset. Expertise in at least two IAM product areas such as Okta, CyberArk, Ping, or preferably Microsoft Entra ID. Ability to define standards, partner cross-functionally (IT, GRC, Engineering), and drive risk reduction through threat modelling, compliance (NIST, ISO, GDPR), and ongoing optimisation of identity systems. Experience working with cloud identity (Azure, AWS, or GCP). What you'll get in return: This role is available for hybrid working with a typical requirement to work 2 days per week in the Cambridge office. Strong salary with decent benefits. 7% pension - employers contribution PMI and dental Share options. And more! Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
PAM Engineer Location: Wokingham Hybrid - 50/50 Duration: role starts with a 6 months contract Rate to SSC Rate - 625 SC CLEARED INSIDE IR35 Role Description: Qualifications Relevant certifications (e.g., CyberArk Defender, CISSP, CISM) Experience in cloud environments (AWS, Azure, GCP) and hybrid infrastructures Knowledge of DevSecOps practices and CI/CD pipeline integration Key Responsibilities Design, deploy, and manage PAM solutions (e.g., CyberArk, BeyondTrust, Delinea) Implement least privilege access models and enforce secure credential management Monitor and audit privileged access activities across systems and applications Integrate PAM tools with SIEM, IAM, and other security platforms Develop and maintain policies, procedures, and documentation for PAM operations Conduct regular access reviews, privilege audits, and risk assessments Collaborate with IT, DevOps, and Security teams to ensure seamless PAM integration Provide technical support and troubleshooting for PAMrelated issues Stay current with industry trends, threats, and best practices in access management Required Skills & Qualifications Experience in PAM engineering or cybersecurity roles Proficiency with PAM tools such as CyberArk, BeyondTrust, or Delinea Strong understanding of Active Directory, LDAP, and authentication protocols Experience with scripting (PowerShell, Python) for automation and reporting Familiarity with compliance frameworks (ISO 27001, NIST, GDPR) Excellent problemsolving, communication, and documentation skills
Apr 30, 2026
Contractor
PAM Engineer Location: Wokingham Hybrid - 50/50 Duration: role starts with a 6 months contract Rate to SSC Rate - 625 SC CLEARED INSIDE IR35 Role Description: Qualifications Relevant certifications (e.g., CyberArk Defender, CISSP, CISM) Experience in cloud environments (AWS, Azure, GCP) and hybrid infrastructures Knowledge of DevSecOps practices and CI/CD pipeline integration Key Responsibilities Design, deploy, and manage PAM solutions (e.g., CyberArk, BeyondTrust, Delinea) Implement least privilege access models and enforce secure credential management Monitor and audit privileged access activities across systems and applications Integrate PAM tools with SIEM, IAM, and other security platforms Develop and maintain policies, procedures, and documentation for PAM operations Conduct regular access reviews, privilege audits, and risk assessments Collaborate with IT, DevOps, and Security teams to ensure seamless PAM integration Provide technical support and troubleshooting for PAMrelated issues Stay current with industry trends, threats, and best practices in access management Required Skills & Qualifications Experience in PAM engineering or cybersecurity roles Proficiency with PAM tools such as CyberArk, BeyondTrust, or Delinea Strong understanding of Active Directory, LDAP, and authentication protocols Experience with scripting (PowerShell, Python) for automation and reporting Familiarity with compliance frameworks (ISO 27001, NIST, GDPR) Excellent problemsolving, communication, and documentation skills