IAM Platform Engineer - Identity, Entitlements & Authorisation
We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity.From our London HQ, we unite world-class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we’re building a world-class platform to amplify our teams’ most powerful ideas.Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale.Take the next step in your career.The roleWe're looking for an experienced IAM Platform Engineer to own and evolve our authentication, identity federation, credential management and privileged access platforms.You'll help modernise our identity infrastructure, replacing bespoke authentication patterns with scalable, standards-based IAM services that are secure, automated and easy for engineering teams to consume.You'll help shape the future of authentication and privileged access within one of the world's leading quantitative research firms, working on large-scale engineering problems rather than traditional operational IAM.Key responsibilities Improve Joiner, Mover, Leaver (JML) and organisational change processesEnhance identity lifecycle automation across Workday, IdentityIQ and Active DirectoryBuild and maintain a comprehensive entitlement catalogue including:OwnershipBusiness purposeRisk classificationApproval modelsUsage contextImprove access request workflows and access certification processesIdentify stale, orphaned and excessive accessEngineer improvements to SailPoint IdentityIQ workflows, provisioning and connectorsReduce manual operational work through automation and self-service capabilitiesDevelop APIs and tooling to expose identity and entitlement dataProduce operational documentation, runbooks and audit evidenceSupport compliance, security reviews and regulatory auditsDesign and improve modern entitlement models including RBAC, ABAC and policy-based access controlWho are we looking for We're looking for experience in the following areas:Engineering and operating Identity Governance and Administration (IGA) platforms, ideally SailPoint IdentityIQ or an equivalent solution.Identity lifecycle management, including Joiner, Mover and Leaver (JML) processes.Identity data integration with HR systems, ideally Workday.Active Directory, LDAP and enterprise identity data management.Entitlement governance, including entitlement metadata, ownership and access models.Access request, approval workflows, access reviews, certifications and attestations.Identity provisioning and integration technologies, including SCIM, REST APIs and SPML.Coding, platform configuration and automation to improve identity services and reduce manual operational effort.Working collaboratively with engineering, security and application teams to deliver scalable identity solutions.Why join us Highly competitive compensation plus annual discretionary bonusLunch provided via Just Eat for Business and dedicated barista bar35 days’ annual leave9% company pension contributionsInformal dress code and excellent work-life balanceComprehensive healthcare and life assuranceCycle-to-work schemeMonthly company eventsG-Research is committed to cultivating and preserving an inclusive work environment. We are an ideas-driven business and we place great value on diversity of experience and opinions. We want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation please let us know in the relevant sectionSummaryLocation: London, UKType: Full time