About the Role
We are seeking an experienced Identity and Access Management (IAM) Platform Engineer to modernize our identity infrastructure. You will replace bespoke authentication patterns with scalable, standards-based IAM services, focusing on large-scale engineering problems rather than traditional operational IAM.
Responsibilities
- Design, implement, and support enterprise authentication and identity federation services.
- Develop standard onboarding patterns for applications using SAML, OAuth2, and OpenID Connect.
- Improve and rationalize our identity provider estate, including PingFederate, PingAM, and cloud identity platforms.
- Engineer secure privileged access solutions using Teleport and Just-in-Time access principles.
- Define standards for service accounts, certificates, secrets, and machine identities.
- Build APIs and automation to simplify identity platform operations.
- Partner with engineering teams to deliver reusable, secure authentication services.
- Improve operational maturity through monitoring, alerting, logging, documentation, and automation.
- Support migration away from bespoke authentication implementations towards enterprise IAM standards.
Requirements
- Experience engineering and operating enterprise IAM platforms.
- Experience with enterprise identity providers such as PingFederate, PingAM, Microsoft Entra ID, or Okta.
- Strong understanding of authentication, authorization, Active Directory, LDAP, and privileged access management.
- Experience applying modern platform engineering practices, including infrastructure as code, CI/CD, automation, and observability.
- Software engineering experience in languages such as C#, Java, Python, or Go.
- Experience building APIs and automating identity platform services.
- Experience supporting hybrid on-premises and cloud identity platforms, including Kubernetes.
Skills
- SAML
- OAuth2
- OpenID Connect
- PingFederate
- PingAM
- Microsoft Entra ID
- Okta
- Teleport
- Active Directory
- LDAP
- Infrastructure as Code
- CI/CD
- Automation
- Observability
- C#
- Java
- Python
- Go
- Kubernetes
Location
- London
Work Type
- Full-time
Experience Level
- Experienced
Salary/Compensations
- Highly competitive compensation plus annual discretionary bonus.
Benefits
- Lunch provided via Just Eat for Business and dedicated barista bar.
- 35 days’ annual leave.
- 9% company pension contributions.
- Informal dress code and excellent work-life balance.
- Comprehensive healthcare and life assurance.
- Cycle-to-work scheme.
- Monthly company events.
About the Company
- We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity.
- From our London HQ, we unite world-class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve.
- Together we’re building a world-class platform to amplify our teams’ most powerful ideas.
- Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale.
Equal Opportunity
- G-Research is committed to cultivating and preserving an inclusive work environment.
- We are an ideas-driven business and we place great value on diversity of experience and opinions.
- We want to ensure that applicants receive a recruitment experience that enables them to perform at their best.
- If you have a disability or special need that requires accommodation please let us know in the relevant section.
