Senior Identity Engineer
at Dijital Team
- Seniority
- Senior
- Employment
- Full Time
- Location
- Colombo
- Posted
- 5d ago
at Dijital Team
About the Role We are seeking a Senior Identity Engineer to design, administer, support and continuously improve enterprise Identity and Access Management (IAM) services across cloud and on-premises environments. This is a hands-on senior technical role within a complex, regulated environment where security, compliance, operational resilience and effective access governance are critical. You will manage identity requests and incidents, implement application integrations, administer privileged and non-human identities, and ensure access is provisioned in line with approved security policies and controls. You will work closely with security, infrastructure, application, risk, audit and business teams, while also contributing to broader security, cloud and infrastructure initiatives as organisational priorities evolve. About the Client You will be working with a large, established financial-services organisation operating in a highly regulated environment. The organisation places strong emphasis on security, risk management, regulatory compliance, operational resilience and the ongoing maturity of its technology and identity capabilities. Ideal Profile Essential Experience & Qualifications Significant professional experience in Identity and Access Management, identity engineering or a closely related discipline. Experience supporting identity services within a large and complex enterprise environment. Previous experience in banking, insurance, superannuation, wealth management, payments or another regulated financial-services environment. Strong understanding of least privilege, segregation of duties, role-based access and enterprise access-control principles. Hands-on experience administering identities across cloud and on-premises environments. Experience managing service accounts, service principals, application identities and associated credentials. Proven experience implementing and supporting Single Sign-On integrations. Strong troubleshooting capabilities across authentication, authorisation, federation and directory services. Experience working within formal incident, problem, request and change-management frameworks. Understanding of security, risk, audit and compliance requirements within regulated organisations. Ability to produce clear technical documentation, implementation plans, support procedures and audit evidence. Strong written and verbal communication skills. Ability to manage competing priorities and collaborate effectively with technical and non-technical stakeholders. Relevant tertiary qualifications, industry certifications or equivalent practical experience. Technical Expertise Strong experience across several of the following: Microsoft Entra ID, Microsoft Active Directory and Group Policy. Hybrid identity and directory synchronisation. Enterprise application and service-principal administration. Managed and workload identities. Role-Based Access Control (RBAC). Privileged Identity Management (PIM) and Privileged Access Management (PAM). Conditional Access and Multi-Factor Authentication (MFA). SAML 2.0, OAuth 2.0 and OpenID Connect. Single Sign-On and federated authentication. Microsoft Azure and Microsoft 365 identity and access controls. PowerShell, Microsoft Graph API or comparable automation technologies. Certificate, secret and credential lifecycle management. Identity governance, access reviews and entitlement management. IT service management and formal change-management practices. Desirable Experience with IAM platforms such as Okta, Ping Identity, SailPoint, CyberArk or similar. Experience with Identity Governance and Administration and PAM solutions. Knowledge of financial-services regulatory and security-control frameworks. Experience supporting identity-related audit, risk and compliance activities. Exposure to cloud-security posture management and identity-threat detection. Familiarity with DevOps, infrastructure-as-code and automated identity deployment. Experience with Azure DevOps, GitHub or similar source-control and delivery platforms. Knowledge of Microsoft Graph, REST APIs and workflow automation. Experience designing or improving enterprise identity operating models. Relevant Microsoft, security, cloud or IAM certifications. Personal Attributes Strong security and risk awareness with exceptional attention to detail. Comfortable operating in a controlled and highly regulated environment. Able to balance security, compliance, operational and user-experience requirements. Proactive, accountable and committed to resolving issues through to completion. Adaptable and comfortable contributing beyond a narrowly defined IAM remit. Able to communicate complex identity concepts clearly to different audiences. Calm and methodical when managing high-priority incidents. Collaborative, dependable and committed to continuous improvement. Confident in challenging requests or proposed solutions where security or control concerns exist. Responsibilities Identity & Access Administration Provision, modify and remove access across cloud and on-premises applications, platforms, infrastructure and data resources. Administer user identities, security groups, roles, entitlements and related access controls. Manage joiner, mover and leaver processes in line with approved policies. Apply least-privilege, need-to-know and segregation-of-duties principles. Review access requests for appropriate approvals and policy alignment. Investigate and remediate excessive, conflicting, inappropriate or orphaned access. Support access reviews, recertification and entitlement audits. Service Account Management Create, maintain and decommission service accounts across cloud and on-premises environments. Ensure service accounts have documented ownership, purpose, dependencies and approved access. Implement appropriate credential, password and authentication controls. Identify and remediate inactive, unmanaged, shared or overprivileged service accounts. Work with application and infrastru