51动漫免费在线观看

Principal Microsoft Identity Security Specialist

Spain. London, England, United Kingdom

Principal Microsoft Identity Security Specialist

  • 202604364
  • London, England, United Kingdom
  • Spain
Voir les favoris

Description

The Principal Microsoft Identity Security Specialist will play a key role within the Global Information and Cyber Security Defence function, leading the organisation’s Microsoft-first identity security strategy. The role is responsible for strengthening the identity security posture through the design, implementation, and optimisation of Microsoft Entra ID, Conditional Access, Identity Protection, Privileged Identity Management, passwordless authentication, and Zero Trust-aligned controls.?

The specialist will support the organisation’s transition to phishing-resistant and passwordless authentication, reduce identity-based risk, and ensure secure identity governance across enterprise, hybrid, SaaS, and multi-cloud environments including AWS, GCP, and OCI. They will also support the use of Agentic AI and automation to enhance identity threat detection, investigation, and response.?

The Role:

  • Contribute to the design, implementation, and optimisation of Microsoft Entra ID as the organisation's strategic identity platform.
  • Deliver and maintain Zero Trust identity controls, including strong authentication, least privilege, and continuous verification.
  • Configure, administer, and enhance Conditional Access, Identity Protection, and risk-based access controls.
  • Enable the adoption of phishing-resistant authentication technologies, including FIDO2 passkeys, Windows Hello for Business, hardware-backed credentials, and Certificate-Based Authentication.
  • Support Privileged Identity Management (PIM), Just-in-Time (JIT) access, privileged access governance, and administrative access controls.
  • Contribute to identity governance initiatives, including access reviews, entitlement management, Joiner-Mover-Leaver processes, and role-based access control models.
  • Support the secure integration and management of workforce identities, application identities, service principals, managed identities, and workload identities.
  • Assist in the implementation and optimisation of Microsoft Defender for Cloud Apps controls to govern SaaS access, reduce shadow IT, and manage session-level risks.
  • Support the detection, investigation, and remediation of identity-based threats, including credential compromise, token theft, privilege escalation, and lateral movement.
  • Assist with the integration of identity telemetry and risk signals into Microsoft Sentinel and other SIEM/SOAR platforms.
  • Support secure identity integration across AWS, GCP, OCI, and hybrid environments.
  • Contribute to automation, operational efficiency, and continuous improvement initiatives through scripting, orchestration, and AI-driven capabilities.
  • Assist in developing identity security standards, procedures, and technical documentation.
  • Collaborate with security, cloud, infrastructure, and engineering teams to support identity security projects and strategic initiatives.
  • Provide subject matter expertise, technical guidance, and stakeholder updates relating to identity security technologies and controls.
  • Support the organisation's adoption of Agentic AI and automation capabilities to enhance identity threat detection, investigation, response, and operational effectiveness.

Qualifications

What you'll bring:

  • Extensive enterprise IAM experience with deep expertise in Microsoft Entra ID, Conditional Access, Identity Protection, PIM, and Identity Governance.
  • Hands-on experience with passwordless authentication, Windows Hello for Business, FIDO2/passkeys, and Microsoft Defender for Cloud Apps.
  • Strong knowledge of SAML, OAuth2, OpenID Connect, Kerberos, and modern authentication models.
  • Experience integrating identity signals into SIEM/SOAR platforms, preferably Microsoft Sentinel.
  • Proven experience securing identities across AWS, GCP, and OCI.
  • Strong scripting or automation experience using PowerShell, Python, or similar.
  • Strong understanding of Zero Trust architecture.
  • Experience using AI/ML or Agentic AI within security operations is highly desirable.

?

Preferred Qualifications

  • Experience with CyberArk, SailPoint, or similar PAM/IGA platforms.
  • Microsoft Identity and Security certifications.
  • AWS, GCP, or OCI cloud certifications.
  • CISSP, CCSP, or equivalent industry certifications.

?

What we offer

Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.

We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.

Equal Opportunity Employer

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email?candidatehelpdesk@wtwco.com

Contact non sollicité

Tous les CV/profils de candidats non sollicités soumis par l'intermédiaire de notre site web ou sur les comptes courriel personnels des employés de Willis Towers Watson sont considérés comme la propriété de Willis Towers Watson et ne font pas l'objet d'un paiement de frais d'agence. Pour être une agence de recrutement ou un cabinet de recherche autorisé par Willis Towers Watson, une telle agence doit disposer d'un accord écrit formel signé par un recruteur autorisé de Willis Towers Watson et d'une relation de travail active avec l'organisation. Les CV doivent être soumis conformément à notre processus de présentation des candidats, ce qui implique de participer activement à la recherche en question. De même, pour nos agences de recrutement et cabinets de recherche agréés, si la procédure de présentation des candidats n'est pas respectée, Willis Towers Watson ne paiera pas de frais d'agence. Willis Towers Watson est un employeur qui souscrit au principe de l'égalité des chances. Si vous souhaitez que vos coordonnées soient conservées en vue d'un examen ultérieur, veuillez envoyer un courriel à cette adresse : Agency.inquiries@willistowerswatson.com .

Nos bureaux

Nos collègues sont présents dans plus de 140 pays : de Mumbai à Londres, en passant par Manille et New York, du Moyen-Orient à l’Amérique latine. Gr?ce à notre présence internationale, tout ce que nous accomplissons prend une dimension mondiale et crée des occasions de collaboration et de croissance pour vous. Parcourez la carte ci-dessous pour voir jusqu’où votre carrière pourrait vous mener.