IAM Specialist
Job Title: IAM Specialist
Location: Culham, Oxfordshire - hybrid working (2-3 days/week on site)
Contract Duration: 18/12/26, possible extension
Daily Rate: £55/hr (Umbrella - Maximum)
IR35 Status: Inside IR35
Security Clearance: Must be eligible for SC
Essential:
- Hands-on experience implementing IGA platforms (SailPoint, Saviynt, Omada, One Identity, or similar)
- Proven experience integrating IGA with Microsoft Entra ID/Azure AD
- Experience connecting authoritative sources (HR systems, databases) to IGA platforms
- Strong understanding of identity life cycle management and JML process automation
- Experience building approval workflows and access request processes
- Knowledge of access certification, recertification, and attestation campaigns
- Understanding of RBAC modelling, role mining, and entitlement management
- Experience with application connector development and configuration
- Strong understanding of authentication protocols (SAML, OAuth 2.0, OpenID Connect, SCIM)
- Knowledge of directory services (Active Directory, LDAP) and hybrid identity
- Working knowledge of security frameworks: ISO 27001, NIST CSF
- Strong troubleshooting skills for provisioning and synchronisation issues
- Good documentation skills for technical configurations and runbooks
Desirable:
- Degree in Information Security, Computer Science, or related STEM field
- Vendor certifications in IGA platforms (SailPoint, Saviynt, Omada)
- Microsoft certification: SC-300 (Identity and Access Administrator)
- Experience with segregation of duties (SoD) policies and access risk analytics
- Scripting skills (PowerShell, Python) for automation and connector development
- Experience with API integration and web services
- Familiarity with ITSM workflows and change control procedures
- Experience in public sector or critical national infrastructure environments
Key Accountabilities
- Implement and configure the IGA platform (SailPoint, Saviynt, Omada, or similar) to meet requirements
- Integrate the IGA solution with Microsoft Entra ID as the primary Identity Provider
- Connect authoritative sources (HR systems, contractor databases) to drive identity life cycle
- Design and implement joiner-mover-leaver (JML) processes with automated provisioning and deprovisioning
- Build and configure approval workflows for access requests, role assignments, and exceptions
- Implement access certification campaigns and recertification processes
- Develop role mining and role-based access control (RBAC) models in collaboration with business owners
- Configure application connectors for target systems (AD, Entra ID, SaaS applications, on-prem systems)
- Implement segregation of duties (SoD) policies and access risk analytics
- Configure SSO and federation services using SAML, OAuth 2.0, OpenID Connect, and SCIM
- Support identity data quality management and remediation activities
- Troubleshoot provisioning failures, synchronisation issues, and connector errors
- Collaborate with application owners during onboarding to define access models and entitlements
- Maintain documentation of IGA configurations, workflows, and integration specifications
- Support audit and compliance activities with reporting and evidence gathering
To apply for this role please submit your latest CV or contact Aspect Resources
Disability Confident
As a member of the disability confident scheme, CLIENT guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group.
Armed Forces Covenant
CLIENT is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses/partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates/military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group.
If you qualify for the above, please notify us.
We will be in touch to discuss your suitability and arrange your Guaranteed Interview.
Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let me know.