CloudPay

Senior Identity Management Engineer

CloudPay

2 LocationsFull timePosted Aug 3, 2026

Job description

About this job opportunity Our Vision To be the world's most trusted global payroll partner, simplifying pay for all employees. Our Mission Empowering global workforces with seamless, compliant, and innovative payroll and payment solutions, enabling businesses to thrive in a connected world. Our People Our fundamental beliefs at Cloud.

Pay are built on core values of professionalism, passion, empowerment, innovation, and teamwork. We value our employees and strive to create a great workplace where everyone is valued, heard, inspired, and encouraged to bring their authentic selves to work. We're committed to providing an excellent employee experience through fulfilling projects, empowerment to make a difference, and an environment that inspires innovation.

What makes this role exciting This role balances high-level architectural vision with deep, hands-on technical execution. It is a critical role responsible for end-to-end delivery of our identity modernisation roadmap. The role is expected to define strategy and personally execute configuration, integration, and deployment of our identity fabric.

You will lead our Zero Trust transition by building and scaling identity infrastructure on Forge. Rock Identity and Access Management (Ping. One Advanced Identity Cloud), with future-state integration of IGA, PAM, and PIM capabilities as part of the roadmap. This role is for a technical leader who delivers results through direct engineering contribution, platform ownership, and technical mentorship.

Main responsibilities: Lead configuration, optimisation, and operational maintenance of Forge. Rock Identity and Access Management (Ping. One Advanced Identity Cloud). Define and deliver Forge. Rock deployment and platform strategy, including environment architecture, high availability and resilience design, and controlled release governance.

Design, configure, and optimise user journeys across authentication, registration, recovery, and federation use cases. Build and evolve IAM CI/CD pipelines and promotion strategy for secure, repeatable rollout of configuration, code, and policy across environments. Establish and enhance monitoring and operational insights across authentication journeys, platform reliability, security event detection, and connector performance.

Own configuration and customisation standards, including scripted nodes, journeys, policies, and reusable engineering patterns. Establish reusable integration patterns for SAML, OIDC, and OAuth2 across cloud and hybrid applications. Own end-to-end connector strategy and lifecycle for enterprise provisioning, reconciliation, and entitlement integration.

Design, configure, and operate OpenICF connectors, including schema alignment, version governance, secure credential handling, and connector host integration. Build and maintain advanced mapping logic with correlation queries, transformation scripts, and policy-driven lifecycle actions. Operate scheduled reconciliation and Live.

Sync with environment-aware controls, clustered reconciliation support, and operational safeguards. Define technical standards through high-quality code, robust architecture patterns, and rigorous documentation. Act as an escalation point for complex IAM failures and protocol troubleshooting across SAML, OIDC, and OAuth2.

Mentor junior and mid-level engineers through peer reviews, pairing, and structured technical coaching. Partner with security, platform, product, and engineering teams to deliver cross-functional IAM outcomes. Roadmap delivery focus Deliver centralized IGA-driven joiner and leaver automation for internal users managed by Corporate IT.

Define and govern authoritative identity rules and enterprise RBAC policies to enable immediate day-one access and precise, policy-aligned deprovisioning at exit. Replace fragmented, application-specific access controls with a single enterprise RBAC model across the Cloud. Pay platform. Harmonise inconsistent access models across Payroll and Payments into a standardised, job-responsibility-based permission framework.

Decouple access management from individual applications and integrate with IGA capabilities for automated provisioning and deprovisioning across Cloud. Pay and connected third-party applications. Drive a phased rollout across third-party applications to reduce delivery risk while increasing automation coverage. Modernise foundational setup processes for company details, payrolls, and pay periods by removing monolithic and duplicated organisation setup across systems.

Deliver a reimagined self-service UI and streamlined process flows for client administrators to manage access, payroll, and payment assignments directly. Reduce Tier 1 operational burden by replacing manual identity and role administration with policy-driven automation. Enforce least-privilege posture, improve access auditability, reduce orphaned account risk, and strengthen regulatory compliance.

Experience needed for this role: Experience: Solid hands-on engineering experience in IAM Ping. Identity Mastery: Extensive hands-on experience deploying and managing Ping. Federate (SAML/OAuth/OIDC configurations), Ping. Directory, and Ping. Access (WAM/API security). Identity Modernisation: A proven track record of executing the migration of legacy identity systems to modern, claims-based architectures.

Tooling & Governance: Direct experience configuring and integrating IGA tools (e.g. Sail. Point, Saviynt) and PAM/PIM solutions to enforce the principle of least privilege. Protocol Expertise: Expert-level capability in debugging and configuring SAML , OIDC , OAuth2 , and SCIM workflows. Core IAM Concepts: Strong understanding of RBAC, ABAC, Zero Trust architecture, and Directory Services (LDAP, Active Directory, Azure AD/Entra ID).

PAM/PIM Knowledge: Proven experience implementing or managing PAM solutions (e.g., vaulting, session recording, password rotation) and PIM principles (role elevation, time-bound access). DevOps & Automation : Proficiency in scripting (Python, Power. Shell, Bash) and Infrastructure as Code (Terraform, Ansible) to automate IAM deployments.

Troubleshooting: Ability to analyze HTTP headers, trace logs (Fiddler, Wireshark), and identity telemetry to resolve complex authentication flow issues Core Competencies Builder Mindset: A strong preference for hands-on creation and a drive to see technical projects through to completion. Strategic Execution: The ability to understand the broader business objective and translate it into a functional, secure technical reality.

Technical Rigour: A disciplined engineering approach that prioritises correct facts and industry standards over temporary workarounds.

Preferred Qualifications

Certifications: Ping Identity Certified Professional (Ping. Federate/Ping. Access), CISSP, CISM, or vendor-specific PAM certifications (e.g., Cyber. Ark Defender). Cloud Identity: Extensive experience with cloud identity providers (Azure AD/Entra ID) and securing workloads in AWS, Azure, or GCP. Containerization: Experience deploying IAM solutions in Docker/Kubernetes environments.

Languages: Excellent written and oral communication skills in English.

About you

and Our core values Taking ownership, working with integrity and respect Being a team player is key to our culture Solution and customer focused Great initiative with the goal for excellence in achieving results Dedicated to developing and always looking for continuous improvements Be creative, be committed, be engaged and enjoy what you do United Kingdom Package and benefits Competitive Salary Competitive vacation allowance Calm app WFH Allowance Life Assurance Private Medical Insurance Cycle to Work Scheme EAP Eye Tests & Glasses Contribution Simplyhealth Enhanced Health Plan Pension Scheme Give-As-You-Earn (GAYE) Employee Referral Program Cloud.

Pay NOW Paid Volunteering days Marriage Leave Bereavement Leave Vacation Purchase Plan Cloud. Pay is committed to being an equal opportunities employer. #LI-AC1 #LI-HIBRID #LI-REMOTE The Cloud. Pay culture is built upon on five core values, from which we develop our service, our technology and our business strategies.

Our fundamental beliefs are a promise to our employees, customers and partners, built on the core values of professionalism, passion, empowerment, innovation, and teamwork. Glassdoor