Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Identity & Access Engineer (IAM)

Identity & Access Engineer (IAM) - Manchester Based (3 Days Hybrid)

About Finova 

Finova is the UK’s largest financial services technology provider, supporting one in every five mortgages nationwide. Our agile, cloud-native solutions enable over 60 banks, building societies, specialist lenders, equity release providers and a network of 2,400+ brokers to stay ahead in a competitive market.

Built on open architecture and backed by deep industry expertise, our platform is designed to scale. Each year, we process over £50 billion in loans, manage nearly £50 billion in savings, and support the digital servicing of more than 650,000 UK borrower accounts.

Be part of a team that’s driving innovation, enabling growth and shaping the future of UK lending.

For Lenders 

Finova offers a flexible, modular technology suite designed to help lenders move faster, scale efficiently and deliver standout digital experiences.

Financial Institutions use Finova to launch products faster, process applications up to 50% more efficiently and reduce operational costs — all while staying fully compliant in a fast-moving market. 

About the Role:

Finova is seeking a seasoned IAM Specialist to own the design and implementation of identity, access, and entitlements across a multi-cloud SaaS fintech platform.

  • Core Responsibility: Translate architectural choices into practical, automated, and secure IAM implementations spanning workforce, customer, and machine identities.

  • The Stack: Multi-cloud infrastructure across AWS, Azure, and GCP . Applications run on .NET / ASP.NET with SQL Server-backed role systems.

  • Key Challenge: Enforce tenant isolation and strict least-privilege to satisfy regulators, while defining cutting-edge access boundaries for AI pipelines, vector databases, and automated decision engines.

  • Work Model: A highly collaborative, hands-on hybrid role. You will balance high-level access modeling with day-to-day configuration, such as writing OPA Rego rules or configuring Azure AD Conditional Access policies.

About you:

You are a highly analytical identity purist who recognizes that in a modern cloud ecosystem, identity is the actual security perimeter. You bridge the gap between application engineering, cloud infrastructure, and regulatory audit, acting as the subject matter expert on who—and what—has access to everything.

Key Attributes:

  • The Structural Architect: You enjoy mapping complex business roles into clean, automated framework permissions, avoiding the technical debt of "privilege creep."

  • Code-Driven Security Advocate: You prefer policy-as-code over manual UI configurations, favoring auditable git repositories and continuous testing for authorization logic.

  • Pragmatic Problem Solver: You understand that security fails if it creates friction, meaning you are constantly looking for ways to use JIT elevation, automated provisioning, and SSO to make access seamless yet secure.

  • Rigorous Guard of Boundaries: You possess an uncompromising eye for isolation details, instinctively knowing how to defend against cross-tenant data leaks and broken access controls.

  • Experience: 4–6 years in IAM, security engineering, or identity-focused cloud engineering with hands-on enterprise deployment experience.

  • Entra ID Expertise: Deep practical knowledge of Azure AD (Entra ID), encompassing app registrations, Conditional Access, PIM, and federation configurations.

  • Multi-Cloud Competency: Hands-on experience with at least two major cloud providers (AWS IAM, Azure RBAC, or GCP IAM) and operational familiarity with all three.

  • Application & DB IAM: Experience implementing RBAC/ABAC models within .NET / ASP.NET applications (Claims, ASP.NET Identity) alongside practical SQL Server access management (roles, RLS, data masking).

  • Federation Protocols: Strong capabilities with SAML 2.0, OIDC, OAuth 2.0, and SCIM provisioning workflows.

  • Policy-as-Code Skills: Experience writing, testing, and deploying authorization policies (OPA/Rego, Azure Policy, or AWS SCPs) directly within a CI/CD pipeline.

  • Modern IAM Tooling: Familiarity with PIM/PAM, CIEM concepts, secretless DevOps access patterns (OIDC-based pipeline identity), and secrets managers (Azure Key Vault, HashiCorp Vault).

  • SaaS Architecture Intuition: A strong understanding of multi-tenancy, with the ability to easily identify missing tenant contexts or authorization bypass vulnerabilities.

  • Communication: Ability to articulate complex identity structures and compliance mandates clearly to developers, architects, and non-technical auditors alike.

Nice-to-Have

  • Fintech Experience: Prior experience navigating IAM in highly regulated domains like banking, payments, or insurance.

  • CIEM/IGA Platforms: Familiarity with platforms like Microsoft Entra Permissions Management, Ermetic, SailPoint, or Saviynt.

  • AI Infrastructure Security: Experience building access controls explicitly tailored for model training environments, feature stores, or LLM integrations.

  • Certifications: SC-300 (Microsoft Identity Administrator), AWS Security Specialty, AZ-500, CISSP, or CCSP.

  • Automation Scripting: Competency in PowerShell or Python for automating access reviews, reporting, and IAM operations.

  • Zero Trust Strategy: Understanding of broader Zero Trust architectures, integrating device compliance and network trust factors with core identity decisions.

What will you be doing?

Identity Architecture & Federation

  • Platform Architecture: Design and implement the identity framework across workforce (employees/contractors), customer (tenant users/admins), and machine identities (services/AI pipelines).

  • Primary IdP Management: Configure and manage Azure AD (Entra ID) tenant structures, app registrations, Conditional Access policies, and directory sync.

  • Enterprise Federation: Implement SAML 2.0, OIDC, and WS-Federation patterns to smoothly onboard customer-managed IdPs like Okta, Ping, and ADFS for enterprise SSO.

  • Automated Provisioning: Design and operate SCIM-based provisioning and deprovisioning workflows to automate user lifecycles across SaaS tenants.

  • Multi-Cloud Mapping: Map Azure AD identities to AWS IAM roles and GCP Workforce Identity Federation to maintain a cohesive, centralized access model.

Privileged Access & Entitlements Management

  • PIM/PAM Operations: Implement Just-In-Time (JIT) access, time-bound elevation, and multi-stage approval workflows for sensitive administrator roles.

  • CIEM Right-Sizing: Utilize Cloud Infrastructure Entitlements Management (CIEM) concepts to monitor and reduce standing privileges or over-entitled accounts across AWS, Azure, and GCP.

  • Access Certification: Build automated entitlement review campaigns so business managers can attest to access appropriateness with minimal friction.

  • Break-Glass Procedures: Establish emergency access workflows equipped with automated expiration, full audit trails, and post-incident review requirements.

Application-Level Access Control (RBAC / ABAC)

  • Layered Enforcement: Design access models that cross multiple enforcement boundaries, including ASP.NET middleware, API gateways, and SQL Server database layers.

  • Claims Mapping: Maintain the mapping between business roles, ASP.NET Identity/Claims, and database-level permissions (such as SQL Server roles and Row-Level Security).

  • Tenant Isolation: Enforce tenant-scoped RBAC to ensure roles and claims are strictly bound to tenant context, architecturally preventing cross-tenant privilege escalation.

  • Policy-as-Code: Write Open Policy Agent (OPA) / Rego policies to centralize fine-grained authorization, utilizing version control, automated testing, and staged rollouts in CI/CD.

Multi-Cloud IAM Operations

  • Cloud Hardening: Manage cloud-native IAM mechanisms, including AWS SCPs and Permission Boundaries; Azure RBAC and Managed Identities; and GCP Organization Policy Constraints.

  • Least-Privilege Verification: Use automated tooling (permission analyzers, simulation tools) to discover and eliminate unused access before deployments go live.

  • Machine Identities: Enforce short-lived credentials, workload identity federation, and secretless patterns for service accounts and machine-to-machine authentication.

DevOps & SQL Infrastructure Access

  • Pipeline Security: Secure access to CI/CD pipelines (Azure DevOps, GitHub Actions), artifact registries, and IaC codebases using federated workload identity (OIDC) rather than static keys.

  • SQL Governance: Manage SQL Server database role hierarchies, schema-level permissions, Row-Level Security (RLS) policies, dynamic data masking, and Always Encrypted structures.

  • Database DevOps: Design access controls for migration tools, analytics queries, and read-replicas to empower engineering velocity without providing permanent production database access.

  • Database Auditing: Implement and monitor database audit logs to track privileged queries, schema alterations, and potential anomalous data access.

AI & ML Pipeline Access Control

  • Workload Identity: Ensure model training jobs, feature pipelines, and serving endpoints utilize scoped, short-lived credentials to access data.

  • AI Component Protection: Define and implement access controls for vector databases, feature stores, and model registries to secure training datasets and model artifacts.

  • Endpoint Authorization: Establish strict authorization policies controlling which roles or tenants can invoke AI endpoints, minimizing AI service account permissions.

  • Data Boundary Enforcement: Partner with Data and AI teams to enforce isolation in ML pipelines during both training phases and inference-time retrieval.

AppSec & Compliance Integration

  • Automated Evidence: Align IAM configurations with SOC 2 Type II, PCI-DSS, and regulatory mandates, building automated evidence collection natively into the platform.

  • Identity Auditing: Design unified audit logging for all authentication events, authorization decisions, privilege elevations, and policy updates.

  • Threat Modeling & Assessment: Participate in threat modeling sessions to bring deep identity expertise to bear against credential stuffing, token theft, and lateral movement vectors.

  • AI Governance Integration: Address specific access oversight constraints regarding who can approve model deployments and who can access AI decision logs.

What We Offer:

  • Hybrid working ️
    Work in a hybrid way that suits you. Our model is primarily office-based, with flexibility to work remotely as needed. We’re committed to supporting a healthy balance between work and life.

  • Private medical insurance ‍⚕️
    Comprehensive health cover, with the option to add your family to your plan, because your well-being matters to us.

  • Life assurance & income protection
    We provide life assurance and income protection to give you peace of mind for the future

  • Family friendly policies
    Our enhanced family-friendly policy goes beyond maternity and paternity leave, offering paid time off for when plans change or alternative paths to parenthood are needed.

  • Work from anywhere
    Some thrive in the office, others at home — and many do best with choice. With approval, Finova employees can work abroad for up to 4 weeks each year.

  • Flexible holiday package ️
    Enjoy 25 days paid holiday allowance, plus all public holidays. And, you can rebook any public holidays for a day that aligns with your personal beliefs or celebration calendar. We also offer holiday trading allowing you to purchase or sell your holiday allowance.

  • Company pension scheme
    With salary exchange, you save on tax and can build a secure future.

  • Employee assistance programme
    We understand that mental health is just as important as physical health. Access to a 24/7 confidential counselling helpline ensures you have support when you need it.

  • Electric car scheme
    Get a brand-new electric vehicle with salary sacrifice as a benefit, paid for through your gross monthly pay, saving on Income Tax and National Insurance.

  • Health cash plan
    Our Health Cash Plan empowers you to prioritise your wellbeing by providing effortless reimbursement for everyday healthcare costs, from dental and optical visits to physiotherapy.

  • Gym discounts ️
    Achieve your fitness goals for less with GymFlex, which offers significant savings on annual memberships at over 3,000 gyms and leisure centers nationwide.

  • Perks that matter
    We fuel your day with a fully stocked pantry of fresh fruit and snacks and keep the team spirit high with weekly socials and events.

Equal Opportunity Statement

We value diversity and are committed to creating an inclusive environment for all employees. If you’re passionate about this role but don’t meet all the criteria, please reach out, we’d love to discuss how your skills and experiences align with our needs.

Vacancy posted 23 days ago
Similar jobs that could be interesting for youBased on the Identity & Access Engineer (IAM) in Salford, Greater Manchester vacancy
  • £37k - £48k per annumEstimated
     ...regulated environment. Proven experience in IAM leadership with end to end exposure to identity governance and access management. Strong Knowledge of IAM principles...  ...support across operations, projects, and engineering. Experience implementing IAM solutions in hybrid... 
    Suggested
    16 hours
    Full-time
    Hybrid working
    On-site
    Flexible hours

    Starling

    Manchester
    a month ago
  • £53k - £70k per annumEstimated
     ...one of the world's most respected design, engineering, and project management consultancies,...  ...lighting, life safety, telecoms, security, access control, lifts, lightning protection etc....  ...gender, ethnic or national origin, sexual identity and orientation, age, religion or... 
    Suggested
    Full-time
    Hybrid working
    On-site
    Remote
    Flexible hours

    AtkinsRéalis

    Manchester
    19 days ago
  • £52k - £67k per annumEstimated
     ...office a minimum of 1 day per week. Our Engineering Environment Starling engineers are...  ...and driven engineers to join our Customer Identity & Fincrime team. This is a fantastic opportunity...  ...policies ~ Perkbox membership giving access to retail discounts, a wellness platform... 
    Suggested
    16 hours
    Full-time
    Hybrid working
    On-site
    Flexible hours

    Starling

    Manchester
    a month ago
  • £45k - £58k per annumEstimated
     ...At Engine by Starling , we are on a mission to find and work with leading banks all around...  ...scheme ~ Perkbox membership giving access to retail discounts, a wellness platform for...  ...national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital... 
    Suggested
    16 hours
    Hybrid working
    Flexible hours

    Starling

    Manchester
    27 days ago
  • £42k - £53k per annumEstimated
     ...At Engine by Starling , we are on a mission to find and work with leading banks all around...  ...scheme ~ Perkbox membership giving access to retail discounts, a wellness platform for...  ...national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital... 
    Suggested
    16 hours
    Full-time
    Hybrid working
    Flexible hours

    Starling

    Manchester
    10 days ago
  • £35k - £45k per annumEstimated
     ...the following Banking Services & Products, Customer Identity & Financial Crime and Data & ML Engineering. Our Data teams are excited about delivering meaningful...  ...refer a friend scheme ~ Perkbox membership giving access to retail discounts, a wellness platform for physical... 
    16 hours
    Full-time
    Hybrid working
    Flexible hours

    Starling

    Manchester
    a month ago
  • £49k - £65k per annumEstimated
    Are you an experienced Electrical Engineer driven by a passion for sustainable solutions?...  ..., disability, sexual orientation, gender identity or gender expression. We prohibit discrimination...  ...and are committed to ensuring it is accessible to all. If you need any support or require... 
    Full-time
    Flexible hours

    Stantec

    Manchester
    19 days ago
  • £39k - £50k per annumEstimated
     ...: AI Enabled Intermediate Power Platform Engineer Role Location: Belfast Salary: Competitive...  ...working in a vibrant environment with access to training and a global network of...  ...veteran status, sexual orientation, gender identity or expression, genetic information, marital... 
    Full-time
    Flexible hours

    Accenture

    Manchester
    a month ago
  • £35k - £45k per annumEstimated
     ...of Interest from Electrical & Mechanical Engineers at all career stages , from early-...  ...disability, sexual orientation, gender identity or gender expression. We prohibit discrimination...  ...and are committed to ensuring it is accessible to all. If you need any support or require... 
    Full-time

    Stantec

    Manchester
    8 days ago
  • £64k - £85k per annumEstimated
     ...looking to connect with Principal Mechanical Engineers for future opportunities within our...  ...disability, sexual orientation, gender identity or gender expression. We prohibit discrimination...  ...and are committed to ensuring it is accessible to all. If you need any support or... 
    Long-term contract
    Full-time
    Hybrid working
    Flexible hours
    Shift work

    Stantec

    Manchester
    19 days ago
  • £24k - £31k per annumEstimated
     ...Role: Senior Site Reliability Engineer (SRE) – Kubernetes / OpenShift Location: Remote...  ...environments. IIS ,  Providing secure internet access in both the public and private sectors....  ...control plane operations, ingress, identity, monitoring, developer platform tooling and... 
    Long-term contract
    Permanent
    Full-time
    Hybrid working
    Remote
    Rotating shifts

    The Investigo Group

    Manchester
    12 days ago
  • £95k - £117k per annum

     ...built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance,...  ..., agentic AI tools gain privileged access to sensitive data through integrations, creating...  ...IPO readiness. Sr. Site Reliability Engineer (SRE) — Obsidian At Obsidian, our Sr.... 
    Long-term contract
    Flexible hours

    Obsidian Security

    Manchester
    1 day ago
  • £39k - £51k per annumEstimated
     ...the following Banking Services & Products, Customer Identity & Financial Crime and Data & ML Engineering. Our Data teams are excited about delivering meaningful...  ...-friendly policies ~ Perkbox membership giving access to retail discounts, a wellness platform for physical... 
    16 hours
    Full-time
    Hybrid working
    On-site
    Flexible hours

    Starling

    Manchester
    more than 2 months ago
  •  ...Application Security Engineer - Manchester Based (3 Days Hybrid) About...  ...Partner closely with developers, the IAM Specialist, and the Cloud Security Engineer to ensure identity, infrastructure, and code are...  ...(in partnership with IAM) Access Validation: Partner with the IAM... 
    Hybrid working
    On-site
    Remote
    Flexible hours
    Shift work

    Finova

    Salford, Greater Manchester
    23 days ago
  • £42k - £55k per annumEstimated
     ...you a passionate experienced Electrical Engineer with experience of working with HV and EHV...  ..., disability, sexual orientation, gender identity or gender expression. We prohibit discrimination...  ...and are committed to ensuring it is accessible to all. If you need any support or... 
    Full-time
    Flexible hours
    Shift work

    Stantec

    Manchester
    7 days ago
  • £17.91 per hour

     ...time. If you’re an experienced Mechanical Engineer or Mechanical Fitter looking for a...  ...PPE and protective uniform provided ~ Access to Sodexo Rewards and discount schemes...  ...variety of experiences, backgrounds, and identities. We encourage our employees to get involved... 
    40 hours/week
    Long-term contract
    Full-time
    Temporary
    Monday to Friday
    Rotating shifts
    Weekday work

    Sodexo Ltd

    Manchester
    13 days ago
  • £34k - £44k per annumEstimated
     ...looking for   We are looking for Project Engineers, Project Managers, or similar...  ...Fieldwire by Hilti gives site teams reliable access to plans, tasks, and updates on one simple...  ...citizenship, marital status, disability, gender identity, veteran status or any other... 
    Hybrid working
    On-site
    Remote

    Fieldwire

    Manchester
    1 day ago
  • £38k - £41k per annum

     ...energy systems Collaborate with the engineering team to develop innovative solutions for...  ...friendly policies ~ Sureserve Benefits Hub, accessing over 1000 retail discounts ~ Virtual...  ..., marital status, disability, gender identity, or Veteran status. We are committed to... 
    Immediate start

    Sureserve

    Manchester
    a month ago
  • £4,000 per month

     ...Fall Protection Engineer / Access & Safety Operative Location: Field Based – Nationwide £4,000 Sign-On Bonus If you know your way around lifelines, guardrails and working at height, you’ll already know this isn’t your average site role. The work is varied, the standards... 
    Night shift

    PTSG Access & Safety

    Manchester
    8 days ago
  • £53k - £70k per annumEstimated
     ...modernisation programmes to detection engineering, posture management, threat...  ...Cloud, AWS, Azure, endpoint, identity, and network sources Write,...  ...Cloud security primitives: IAM, Organization Policies, VPC...  ...cashback scheme ****@*****.*** app: access to remote GP's, second... 
    Long-term contract
    Remote
    Flexible hours

    Beyond

    Manchester
    3 days ago
  • £90k - £116k per annumEstimated
     ...seeking a Senior AI Product & Research Engineer (Consultant) to help design, prototype,...  ...applications from people of all backgrounds, identities and lived experiences, and we value the...  ...every candidate to have a positive and accessible recruitment experience. If you need... 
    Full-time
    Remote
    Flexible hours

    Version 1

    Manchester
    9 days ago
  • £52k - £67k per annumEstimated
     ...excited about understanding, interpreting, and navigating complex engineering issues? Are you motivated by creating sustainable change that...  ...Committed employer, Ramboll ensures opportunities are accessible to candidates with disabilities. Please let us know if there are... 
    Long-term contract
    Full-time
    Flexible hours

    Ramboll

    Manchester
    25 days ago
  • £67k - £88k per annumEstimated
     ...experienced  Senior Software Engineer – Universal Search to help shape...  ...fast, accurate, and secure access to critical data across our RMS...  ...ECS/EKS, DynamoDB, Aurora/RDS, IAM, and CloudWatch. Prior experience...  ..., sexual orientation, gender identity, national origin, veteran... 
    Hybrid working
    On-site
    Remote
    Work visa
    Shift work

    Mark43

    Manchester
    1 day ago
  • £66k - £88k per annumEstimated
     ...renowned for our leadership in fire protection engineering – a legacy of responsibility we have...  ...security and risk-based fields – from accessibility consulting and risk analysis to process...  ...national origin, sexual orientation, gender identity, disability or protected veteran status.... 
    Long-term contract
    Temporary
    Part-time
    Hybrid working
    Flexible hours

    Jensen Hughes

    Manchester
    1 day ago
  • £54k - £69k per annumEstimated
     ...environments. Are you a Dams & Reservoir Engineer who is passionate about making the world...  ...structures, culverts, scour protection, access and accessibility and construction...  ...gender, ethnic or national origin, sexual identity and orientation, age, religion or disability... 
    Full-time
    Hybrid working
    On-site
    Immediate start
    Flexible hours

    AtkinsRéalis

    Manchester
    11 days ago
  • £62k - £80k per annumEstimated
     ...on secure-by-design practices, helping engineers and product managers build security literacy...  ...cloud platforms, application security, identity and access management, and system integration. You...  ...Azure, including network segmentation, IAM, encryption, secrets management, and security... 
    Full-time
    Remote
    Flexible hours

    Version 1

    Manchester
    5 days ago
  • £73k - £98k per annumEstimated
     ...protection, and risk visibility. •    Strengthen identity protection through Entra ID, Conditional Access, MFA, PIM/JIT, and Defender for Identity. •    Lead...  ..., Incident Response, Threat Hunting, TI and Cloud Engineering teams to deliver unified detection, response, and... 
    Long-term contract
    Full-time
    Temporary
    Hybrid working
    Work visa

    WTW

    Manchester
    15 days ago
  • £90k - £95k per annum

     ...environments Strong knowledge of things such as, SIEM platforms, Endpoint protection and EDR, Data Loss Prevention (DLP) , Identity and Access Management (IAM) and Privileged Access Management (PAM) Cloud security, particularly Microsoft Azure Vulnerability scanning and... 
    Remote

    Apply Recruitment

    Manchester
    a month ago
  • £65k - £86k per annumEstimated
     ...who thrives where strategy meets hands‑on engineering, who can simplify complex challenges,...  ...adoption of Zero Trust architecture and modern identity, access, and privileged access management...  ...with tools such as SIEM, IDS/IPS, DLP, IAM, and encryption, and you stay current with... 
    Ongoing contract
    Full-time
    No agency
    Hybrid working

    Vix Technology

    Manchester
    more than 2 months ago
  • £42k - £53k per annumEstimated
     ...multinational teams are working closely together with project management, engineering as well as with end customers to provide customized solutions...  ...- no matter what ethnic background, gender, age, religion, identity, or disability. We energize society, all of society, and we do... 
    Long-term contract
    Full-time
    Remote
    Flexible hours

    Siemens Energy

    Manchester
    25 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Identity & Access Engineer (IAM). Be the first to apply!