Allica Bank Logo

Allica Bank

Senior IAM Engineer

Reposted Yesterday
Be an Early Applicant
In-Office
2 Locations
Senior level
In-Office
2 Locations
Senior level
Seeking an experienced IAM Engineer to maintain identity infrastructure and enhance security controls, collaborating with engineering teams on IAM improvements.
The summary above was generated by AI

About Allica Bank

Allica is the UK’s fastest growing company - and the fastest-growing financial technology (Fintech) firm ever. Our purpose is to help established SMEs, one of the last major underserved opportunities in Fintech.

Established SMEs are the backbone of local communities - representing over a third of our economy - yet have been largely neglected both by traditional high street banks and modern fintech providers.

Department Description

The Allica Security team play a key role in protecting the bank and are responsible for all aspects of security surrounding Applications, Infrastructure and Security Operational Policy. Our mission is to provide the best-in-class security to protect the bank. We live and breathe the Allica values and deliver services intelligently using automation, intelligence, and innovation.

Role Description

We are looking for an experienced Identity and Access Management SME to join our security team to help reduce security risks by improving IAM infrastructure and controls. The person we are looking for would work closely with the engineering teams and will require a mix of technical knowledge and collaborative skills.

As part of the Information Security team, you will be supporting Allica’s fast growth momentum with the design, implementation and maintenance of the tools which help to support out internal employees, as well as Allica’s customers. You will work with stakeholders across the business to support Information Security objectives, as well as those related to the wider bank.

Principal Accountabilities

  • Operate and maintain the identity platform – Ensure continuous, secure operation of PingFederate, PingAccess, PingDirectory and PingOne MFA across two Azure regions, achieving a minimum 99.95 percent service availability.

  • Architect and deliver integrations – Define, document and govern reusable patterns for OIDC/OAuth 2.0, SAML 2.0, SCIM, FIDO2/WebAuthn and mTLS to support customer-facing applications, APIs and third-party SaaS.

  • Automate infrastructure and configuration – Implement infrastructure-as-code (Terraform) and Git-based CI/CD pipelines; enforce zero-touch certificate and secret management via Azure Key Vault.

  • Execute hardening and lifecycle management – Plan, test and deploy product upgrades, schema modifications and security patches, maintaining the estate at N-1 or later for all Ping components.

  • Design, perform regular chaos and fail-over exercises, and maintain disaster-recovery artefacts that meet stated RTO/RPO targets.

  • Provide observability and incident response – Develop telemetry dashboards configure actionable alerts and lead incident triage with Security Operations and Incident response team.

  • Produce documentation and knowledge transfer – Maintain comprehensive runbooks, architecture artefacts and compliance evidence, mentor platform and development teams in secure integration practices.

Attributes

  • Specialised Ping expertise – Minimum five years’ production experience administering and upgrading PingFederate, PingAccess and PingDirectory in multi-region environments.

  • Microsoft Entra proficiency – Demonstrable capability with Conditional Access, Identity Governance, External ID and Graph-based automation.

  • Protocol depth – Advanced knowledge of OAuth 2.0/OIDC, SAML 2.0, SCIM, LDAP, mTLS and FIDO2/WebAuthn, including packet-level troubleshooting.

  • Infrastructure-as-code discipline – Proven use of Terraform or Bicep, with CI/CD pipelines in Azure DevOps or GitHub Actions, and scripting fluency in PowerShell, Bash or Python.

  • Security and regulatory acumen – Working understanding of PSD2/Open Banking, PCI-DSS, ISO 27001, PRA/FCA operational-resilience expectations and NIST 800-207 zero-trust principles.

  • Having expertise in SailPoint would be a valuable addition, particularly given its relevance to current and upcoming IAM-related initiatives.

  • Reliability engineering mindset – Experience defining SLOs, managing error budgets, conducting chaos engineering and producing rigorous root-cause analyses.

  • Analytical and sceptical approach – Ability to challenge architectural assumptions, facilitate threat-modelling workshops and substantiate recommendations with empirical data.

  • Exceptional communication skills – Adept at translating complex identity concepts for technical and executive audiences and influencing stakeholders across the organisation.

  • Commitment to continuous improvement – Evidenced engagement with the Ping and broader IAM community, proactive adoption of emerging features and tools that materially enhance security or efficiency.

Working at Allica Bank

At Allica Bank we want to ensure our employees have the right tools and environment in which to succeed in their role and in support of our customers.

Our employees are at the heart of everything we do, so our benefits are designed with you in mind:

  • Full onboarding support and continued development opportunities

  • Options for flexible working

  • Regular social activities

  • Pension contributions

  • Discretionary bonus scheme

  • Private health cover

  • Life assurance

  • Family friendly policies including enhanced Maternity & Paternity leave

Don’t tick every box?

Don’t worry if you don’t have all the skills or requirements listed on the job description. If you think you’ll be a good fit, we’d still love to hear from you!

Flexible working

We know the ‘9-to-5’ isn’t right for everyone. That’s why Allica Bank is fully committed to flexible and hybrid working. Please let us know what is best for you and, if we can, we will do our best to accommodate.

Diversity

We’re a diverse bunch here at Allica, with all kinds of experiences, backgrounds and lifestyles. Our openness and differences make us stronger, and we want everybody to feel comfortable bringing as much of themselves to work with them as they like.

Top Skills

Azure
Azure Key Vault
Bash
Ci/Cd
Fido2
Git
Microsoft Entra
Mtls
Oauth 2.0
Pingaccess
Pingdirectory
Pingfederate
Powershell
Python
Saml 2.0
Scim
Terraform

Similar Jobs

11 Days Ago
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
The Senior IAM Engineer at Rubrik will design, implement, and maintain IAM solutions using SailPoint, ensuring compliance and security, while mentoring junior engineers and optimizing processes.
Top Skills: Active DirectoryAWSAzureBeanshellGoogle Cloud PlatformJavaJavaScriptPythonSailpoint Identity Security Cloud
2 Hours Ago
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Healthtech • Biotech
As a Staff Dev Ops IAM Engineer, you'll manage IAM solutions, design custom development, and support tooling in a collaborative environment.
Top Skills: Active DirectoryAdfsAzure AdBeanshellJavaOauthOktaOpenidSailpointSAMLScim
16 Minutes Ago
Remote or Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Senior Technical Writer collaborates with engineering and product management to create user-focused technical documentation, contributing to content strategy and mentoring other writers.
Top Skills: AIDitaXML

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account