Security Engineer
Dariel
Identity & Access Management (IAM) Security Engineer
Location - Roodepoort
Hybrid
Employment Type – Contract – 12 months
About the Role
We are seeking an experienced Identity & Access Management (IAM) Security Engineer to lead the design, implementation and ongoing enhancement of identity security controls across our Microsoft ecosystem and integrated business platforms.
This role is responsible for securing digital identities, enforcing Zero Trust access principles, governing privileged access, and ensuring strong authentication controls across the organisation. The successful candidate will act as the technical authority for identity security, partnering with infrastructure, application, cloud and cybersecurity teams to reduce identity-related risk while supporting business agility.
The position plays a critical role in maintaining regulatory compliance, supporting audit requirements, and ensuring identity and access controls align with organisational and Group cybersecurity standards.
Key Responsibilitie
sIdentity Security Engineerin
- gDesign, implement and manage identity security controls across Microsoft Entra ID and integrated platforms
- .Develop and maintain secure identity architectures that support Zero Trust security principles
- .Configure and optimise identity security controls to minimise the risk of unauthorised access and credential compromise
- .Ensure identity services are aligned with organisational security standards, regulatory requirements and industry best practices
.Conditional Access & Authentication Securit
- yDesign, implement and manage Conditional Access policies that balance security, risk mitigation and user experience
- .Configure and enforce Multi-Factor Authentication (MFA) controls across the organisation
- .Implement phishing-resistant authentication methods where appropriate, including
- :FIDO2 Security Key
- sPasswordless Authenticatio
- nMicrosoft Authenticato
- rIdentify and eliminate reliance on legacy authentication protocols
- .Manage Self-Service Password Reset (SSPR) and authentication security controls
.Identity Protection & Threat Monitorin
- gConfigure and maintain Microsoft Entra Identity Protection policies
- .Monitor and respond to identity-related threats and suspicious activity, including
- :Risky user
- sRisky sign-in
- sImpossible travel detection
- sUnusual MFA activit
- yCredential compromise indicator
- sPrivileged account anomalie
- sInvestigate and support remediation of high-risk identity events
- .Collaborate with Security Operations and incident response teams during investigations involving identity compromise
.Privileged Access Managemen
- tAdminister and optimise Microsoft Privileged Identity Management (PIM)
- .Implement least-privilege access models across administrative functions and critical business systems
- .Define privileged access governance standards and approval workflows
- .Reduce standing administrative privileges through Just-In-Time (JIT) access controls
- .Monitor privileged access usage and investigate anomalous administrative activities
.Access Governance & Complianc
- eLead periodic user access reviews and privileged access attestations
- .Coordinate remediation of
- :Dormant account
- sOrphaned account
- sExcessive privilege
- sSegregation of duties conflict
- sEnsure identity governance processes produce audit-ready evidence
- .Support internal and external audits relating to identity and access controls
- .Maintain policies, standards and operational procedures related to IAM security
.Identity Lifecycle Securit
- ySupport Joiner, Mover and Leaver (JML) processes by designing secure identity governance controls and automation standards
- .Collaborate with HR, IT Operations and Application Owners to strengthen identity lifecycle security controls
- .Validate that access provisioning and deprovisioning processes operate effectively and within established service levels
- .Identify opportunities for identity process automation and risk reduction
.Federation, SSO & External Identity Securit
- ySupport the secure implementation of
- :Single Sign-On (SSO
- )Federation service
- sBusiness partner integration
- sVendor and external identity acces
- sReview identity integrations for security risks and compliance requirements
- .Configure and secure authentication protocols including
- :SAM
- LOAuth 2.
- 0OpenID Connect (OIDC
- )Ensure third-party access models align with organisational security standards
.Reporting & Governanc
- eDefine, monitor and report key IAM security metrics, including
- :MFA adoption and coverag
- ePrivileged access coverag
- eTime-to-deprovisio
- nLegacy authentication exposur
- eOrphaned account volume
- sAccess review completion rate
- sProvide regular reporting to security leadership, audit and governance stakeholders
- .Support compliance and risk management initiatives through effective security reporting and evidence management
.Collaboration & Stakeholder Engagemen
- tPartner with the Intune, EUC & BYOD Security Engineer to align identity controls with endpoint trust and device compliance requirements
- .Collaborate with the Senior Microsoft Cloud & Platform Security Lead to support broader Microsoft security strategies
- .Work closely with infrastructure, cloud, application and governance teams to ensure identity security requirements are embedded within projects and operational processes
- .Act as a trusted advisor on identity security best practices across the organisation
.
Decision-Making Authori
tyThe successful candidate wil
- l:Implement and manage Conditional Access policies, MFA controls and PIM configurations within delegated authorit
- y.Recommend identity security improvements, governance processes and access control enhancement
- s.Escalate material identity risks, governance failures and non-compliant access practices to cybersecurity leadershi
- p.Validate that IAM controls meet regulatory, audit and organisational evidence requirement
- s.Influence identity security standards and access governance practices across the busines
s.
Essential Skills & Experie
nceTechnical Experie
- nceMinimum 5-8 years' experience in Identity & Access Management, Identity Security or Cyber Security Engineeri
- ng.Strong hands-on experience with Microsoft Entra ID (Azure AD) in enterprise environmen
- ts.Extensive experience implementi
- ng:Conditional Acc
- essMulti-Factor Authentication (M
- FA)Identity Protect
- ionPrivileged Identity Management (P
- IM)Access Revi
- ewsEntitlement Managem
- entExperience designing and supporting Zero Trust identity architectur
- es.Strong understanding of authentication, authorisation and identity federation technologi
- es.Experience supporting hybrid identity environments incorporating Active Directory and Entra
ID.Security & Governance Knowle
- dgeStrong understanding
- of:Zero Trust Architect
- ureLeast Privilege Acc
- essSegregation of Dut
- iesIdentity Governance & Administration (I
- GA)Privileged Access Management (P
- AM)Access Certification Proces
- sesRegulatory and Audit Requireme
- ntsExperience supporting internal audits, compliance assessments and control revie
ws.Professional Ski
- llsStrong analytical, troubleshooting and problem-solving skil
- ls.Excellent communication and stakeholder management capabiliti
- es.Ability to engage effectively with technical and non-technical audienc
- es.Strong attention to detail and governance discipli
- ne.Ability to work independently and manage multiple priorities in a fast-paced environme
nt.
Preferred Qualificat
- ionsMicrosoft Certified: Identity and Access Administrator Associate (SC-
- 300)Microsoft Certified: Cybersecurity Architect Expert (SC-
- 100)Microsoft Certified: Security Operations Analyst Associate (SC-
- 200)Microsoft Certified: Azure Security Engineer Associate (AZ-
- 500)CISSP, CISM, CRISC or equivalent security certifica
- tionCertified Identity and Access Manager (CIAM) or equivalent IAM qualification advantag
eous
Core Technol
ogiesIdentity Pla
- tformMicrosoft Entra ID (Azur
- e AD)Conditional A
- ccessIdentity Prote
- ctionEntra ID
RBACPrivileged Access Manag
- ementPrivileged Identity Management
- (PIM)Administrative Role Gover
- nanceJust-In-Time (JIT) A
ccessAuthentication & Credential Sec
- urityMicrosoft Authenti
- catorFIDO2 Security
- KeysPasswordless Authentic
- ationMulti-Factor Authentication
- (MFA)Self-Service Password Reset (
- SSPR)Legacy Authentication Blo
ckingAccess Gover
- nanceAccess Re
- viewsEntitlement Manag
- ementRole-Based Access Control (
- RBAC)Segregation of Duties Con
trolsHybrid Ide
- ntityActive Dire
- ctoryMicrosoft Entra Co
- nnectHybrid Azure AD
JoinFederation & Application A
- cces
- sSAMLOAut
- h 2.0OpenID Connect (
- OIDC)Single Sign-On
- (SSO)External Identity Integra
tions
Why Jo
in Us?This is an opportunity to play a critical role in protecting one of the organisation’s most important security foundations: identity. You will help shape and mature a modern Zero Trust security model, influence enterprise-wide access governance, and work with leading Microsoft identity technologies to strengthen cyber resilience, compliance and secure digital transform
ation.