winterchill jobs
← all jobs
Reed

Identity Infrastructure Engineer

Hays Specialist Recruitment· London· £447/dayClearance BPSS
Posted 17 Sept 2026 · Added 18 Sept 2026, 00:11
View original on Reed
See how well this job fits your CV.

Free Tailor for ATS: 10/10 runs left

Identity Infrastructure Engineer

Rate: £447 per day (inside IR35)

Location: Inverness or Manchester

Working arrangement: Based within secure facilities - 5 days onsite

Contract length: To confirm

Security clearance: BPSS

Your new company

You will be joining an organisation operating within a secure and highly regulated environment, supporting critical Identity and Access Management (IDAM) services. Working closely with security, engineering and IDAM teams, you will help maintain the resilience, availability and security of core identity infrastructure platforms.

Your new role

As a Senior Identity Infrastructure Engineer, you will be responsible for the administration, support, security and continuous improvement of the organisation's identity infrastructure estate. This role focuses on Active Directory, PKI, DNS, Group Policy and authentication services, while also providing L2/L3 operational support across wider identity platforms.

Key responsibilities

Active Directory Infrastructure

Administer and maintain enterprise Active Directory forests, domains and domain controllers.

Manage Active Directory Sites and Services, replication topology, trusts and directory infrastructure.

Maintain AD-integrated DNS and authentication services.

Design, implement and support Group Policy architecture.

Support Active Directory backup, recovery, disaster recovery and business continuity processes.

Monitor platform health, security, performance and replication.

Participate in Active Directory upgrades, migrations and infrastructure improvement programmes.

Implement security hardening standards and privileged access controls.

Public Key Infrastructure (PKI)

Administer Microsoft Active Directory Certificate Services (AD CS).

Manage Certificate Authorities, templates, enrolment processes and certificate lifecycle management.

Support Offline Root CA and Issuing CA environments.

Maintain CRL, AIA and certificate distribution services.

Monitor renewals, revocations, compliance and certificate expiry.

Maintain PKI documentation, recovery procedures and security standards.

Troubleshoot cryptographic and certificate-related issues.

Identity Infrastructure & Authentication Services

Support Microsoft Entra Connect and hybrid identity services.

Maintain LDAP, LDAPS, Kerberos and NTLM authentication platforms.

Support integrations across Active Directory, MIM, Entra ID, Okta and BeyondTrust.

Resolve authentication, directory and infrastructure incidents.

Contribute to service improvements and platform optimisation initiatives.

Automation & Continuous Improvement

Develop and maintain PowerShell automation for infrastructure administration.

Drive operational efficiency and service improvements.

Support security remediation and infrastructure modernisation initiatives.

Produce and maintain technical documentation, support procedures and runbooks.

Essential skills and experience

Extensive experience administering enterprise Active Directory environments.

Strong knowledge of:

Active Directory Domain Services (AD DS)

Active Directory Sites and Services

Forest and domain administration

DNS

Group Policy

LDAP / LDAPS

Kerberos authentication

Trusts and replication

Active Directory backup and recovery

Experience troubleshooting complex authentication and directory service issues.

PKI

Strong experience with Microsoft Active Directory Certificate Services (AD CS).

Experience managing:

Certificate Authorities

Certificate Templates

CRL and AIA infrastructure

Certificate lifecycle management

Certificate enrolment services

Key recovery and archival

Experience supporting enterprise PKI environments.

Infrastructure Platforms

Windows Server and 2022 administration.

PowerShell scripting and automation.

Security hardening and privileged administration.

High availability and disaster recovery planning.

Infrastructure monitoring and operational support.

Identity Technologies

Working knowledge of:

Microsoft Entra ID

Microsoft Entra Connect / Cloud Sync

Microsoft Identity Manager (MIM)

Okta

BeyondTrust

Strong understanding of:

Identity and Access Management (IAM)

Identity lifecycle management

Authentication and authorisation

Access governance

Role-Based Access Control (RBAC)

Joiner, Mover, Leaver processes

Desirable skills and experience

Experience supporting Microsoft Identity Manager (MIM).

Experience supporting hybrid identity architectures.

Experience with Okta administration and integration.

Knowledge of BeyondTrust PAM or Endpoint Privilege Management.

Experience with Tier 0 administration and privileged access models.

Familiarity with CrowdStrike, Zscaler and security platform integrations.

Experience working within highly regulated or secure environments.

Knowledge of ITIL-based operational support models.

Experience supporting large-scale enterprise identity programmes.

What you'll get in return

Opportunity to work on critical enterprise identity and authentication platforms.

Exposure to complex Active Directory, PKI and hybrid identity environments.

How to apply

If you're interested in this opportunity, apply with your latest CV, availability and preferred location. If this role isn't quite right for you, please get in touch for a confidential discussion about similar opportunities.

Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk