Skip to Main Content
Location icon
London

Senior Microsoft Identity Security Specialist

WTW
Office & Professional
Office & Professional
Company logo image
Description

Location
London office with a hybrid working model. Attendance at the office is required as needed to meet business and team requirements.

Hours
Full Time

Salary
Negotiable

About the Role
The Senior Microsoft Identity Security Specialist will play a key role within the Global Information and Cyber Defence and Identity function, supporting the organisation's Microsoft-first identity security strategy through the design, implementation and optimisation of Microsoft Entra ID and related platforms. This role strengthens the organisation's identity security posture through Conditional Access, Identity Protection, Privileged Identity Management, passwordless authentication and Zero Trust-aligned controls. Combining hands-on engineering with technical design, automation and continuous improvement, the role includes the appropriate use of AI-assisted analysis to enhance identity operations and security monitoring.

The Role Includes
Identity Platform Engineering: Design, implement and optimise Microsoft Entra ID as the strategic identity platform. Configure and enhance Conditional Access, Identity Protection, PIM and Just-in-Time access controls. Support identity governance including access reviews, entitlement management, Joiner-Mover-Leaver processes and role-based access control models. Manage workforce, external, application, managed identities and service principals. Troubleshoot complex authentication, authorisation, federation and provisioning issues.
Authentication and Access Security: Support adoption of phishing-resistant authentication such as FIDO2/passkeys, Windows Hello for Business, certificate-based authentication and hardware-backed credentials. Implement Zero Trust identity controls across SaaS, cloud and enterprise applications. Support secure application integration using OAuth 2.0, OpenID Connect and SAML.
Automation and Platform Enablement: Develop reusable pipelines, scripts and workflow automation for repeatable identity operations. Create approved self-service patterns for application registration and enterprise application onboarding with validation, approvals and audit logging to reduce direct administrative access. Integrate identity standards and secure defaults into application modernisation, CI/CD and infrastructure-as-code processes. Automate routine activities such as configuration validation, certificate and secret-expiry monitoring, evidence collection and operational reporting.
AI-Assisted Operations and Security Monitoring: Identify and support practical uses of approved AI capabilities to improve efficiency and quality of identity engineering and operations. Use AI-assisted analysis and automation to identify Conditional Access gaps, configuration drift, anomalous sign-ins, risky privilege activity, stale identities and excessive permissions. Support identity-focused monitoring and signal correlation using Entra ID, Microsoft Defender, Log Analytics and Microsoft Sentinel. Define and apply approved identity controls to AI agents and agent identities, ensuring high-impact access, policy and remediation decisions retain appropriate human review and approval.
Threat Detection and Continuous Improvement: Support detection and remediation of identity threats including credential compromise, privilege escalation, token theft and suspicious authentication activity. Collaborate with security operations teams to improve identity threat visibility, triage and response. Contribute to technical designs, standards, documentation, operational procedures and control-effectiveness reporting. Provide technical guidance and subject matter expertise relating to Microsoft identity technologies.

Requirements

Experience
- Demonstrable recent, hands-on experience in Identity and Access Management with substantial expertise in Microsoft Entra ID administration and security within complex enterprise environments.
- Experience implementing and supporting Conditional Access, Identity Protection, Privileged Identity Management and Identity Governance.
- Experience deploying and supporting passwordless and phishing-resistant authentication.
- Strong understanding of OAuth 2.0, OpenID Connect, SAML and modern authentication protocols.
- Experience with scripting and automation, familiarity with source control and deployment pipelines such as Azure DevOps or GitHub.
- Understanding of Zero Trust, least privilege and identity-centric security controls.
- Experience troubleshooting authentication and access issues in enterprise environments.
- Ability to translate architecture and security standards into practical engineering solutions.
- Strong communication, documentation and stakeholder engagement skills.

About You
- Proactive and detail-oriented with a passion for identity security.
- Comfortable working in a hybrid environment and collaborating across teams.
- Eager to leverage AI and automation to improve security operations.
- Committed to continuous learning and applying best practices in identity and access management.

Qualifications
- Desirable experience includes Microsoft Sentinel, Log Analytics/KQL, Defender for Identity, Defender for Cloud Apps or Copilot for Security.
- Knowledge of Microsoft Graph, Python, Logic Apps, Azure Functions, policy-as-code, infrastructure-as-code or advanced workflow automation.
- Experience using AI/ML or Agentic AI within security or identity operations.
- Familiarity with application registration, managed identity, service principal, workload identity, and secrets or certificate lifecycle governance.
- Experience with Active Directory security, Entra Connect or Cloud Sync, and hybrid identity monitoring.
- Knowledge of SailPoint identity governance or CyberArk privileged access and credential management.
- Experience with AWS, Google Cloud Platform or Oracle Cloud Infrastructure identity and access management.
- Relevant Microsoft Security, cloud or industry certifications such as CISSP or CCSP are advantageous.

Expiry date: 04/11/2026
Senior Microsoft Identity Security Specialist
Company:
WTW
Job Type:
Full-time
Location:
London