About the Role
We are seeking a Senior IAM Engineer to manage and enhance our enterprise identity platform, focusing on Okta and Microsoft Entra ID. This role is highly visible, requiring collaboration across the organization and a proactive, innovative approach within an Agile environment. The team delivers high-quality, customer-centric outcomes that enable critical business services and exceptional user experiences.
Responsibilities
- Design, build, and maintain enterprise Identity and Access Management solutions using Okta and Microsoft Entra ID.
- Engineer and automate Joiner, Mover, Leaver (JML) lifecycle processes using Okta Workflows.
- Design and implement Single Sign-On (SSO), Multi-Factor Authentication (MFA), and identity governance solutions across enterprise applications.
- Integrate cloud and on-premises applications using SAML, OAuth, OIDC, SCIM, and other modern authentication protocols.
- Develop PowerShell automation to streamline identity provisioning, administration, and operational processes.
- Engineer and maintain hybrid identity services across Active Directory and Microsoft Entra ID.
- Administer and optimize Active Directory, including Group Policy management and enterprise domain services.
- Support Azure Application Proxy and secure remote application access.
- Participate in the design, planning, and delivery of identity-related projects and platform enhancements.
- Produce and maintain technical documentation for identity architecture, integrations, and automation.
- Provide third-line technical support for complex IAM issues and contribute to incident response and root cause analysis.
- Stay current with emerging identity technologies and recommend improvements to the platform.
Requirements
- Bachelor's degree in Computer Science or a related discipline (or equivalent practical experience).
- Strong hands-on experience engineering enterprise IAM solutions.
- 2+ years' experience with Okta Single Sign-On (SSO) and Lifecycle Management.
- 2+ years' experience with Okta Identity Governance (OIG).
- 2+ years' experience developing solutions using Okta Workflows.
- 5+ years' experience working with Active Directory in complex enterprise environments.
- Strong knowledge of Active Directory Group Policies (GPO).
- Experience with Microsoft Entra ID (Azure Active Directory).
- Experience with Azure Application Proxy or similar application proxy technologies.
- Strong PowerShell scripting skills with a focus on automation.
- Experience with Microsoft Certificate Services.
- Excellent troubleshooting and problem-solving skills.
- Ability to work independently and thrive in a fast-paced, evolving environment.
Skills
- Okta
- Microsoft Entra ID
- Okta Workflows
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Identity Governance
- SAML
- OAuth
- OIDC
- SCIM
- PowerShell
- Active Directory
- Group Policy
- Azure Application Proxy
- Microsoft Certificate Services
- ServiceNow
- Splunk
- System for Cross-domain Identity Management (SCIM)
- Infrastructure as Code
- Automation tooling
Work Type
- Hybrid
Experience Level
- Senior
Education Level
- Bachelor's degree in Computer Science or related discipline (or equivalent practical experience)
Salary/Compensations
- GBP 59,400.00-82,866.66
- 12.5% Annual Bonus Target
About the Company
- At Morningstar, every hire we make strengthens our mission to empower investor success.
- Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis.
- In most of our locations, our hybrid work model is four days in-office each week.
- A range of other benefits are also available to enhance flexibility as needs change.
- No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
