Senior Infrastructure Engineer - Department for Work and Pensions - G7
Government Digital & Data -
Location
This role may be located in one of the following locations; Blackpool or Manchester.
Please find further information on the Corporate hub locations here.
About the job
Job summary
Please note this role requires you to pass Security Check clearance. For further information, please see 'Selection process details'.
Technology Services provide the foundations upon which digital services for Department for Work & Pensions (DWP) are developed and operate. Our purpose is to deliver secure, effective, and cost-efficient digital infrastructure services and to run live IT operations that support DWP business objectives. We do this by putting users and quality of service at the heart of what we do.
Our team is made up of 1,500 colleagues working collaboratively across 10 portfolio led teams in a fast moving environment. Our teams deliver an end-to-end suite of digital products and services that support DWP colleagues and citizens in an ever-evolving technology landscape. Our work is focused around the following 6 themes:
- Delivering a digital workplace that improves the way we work.
- Delivering high-quality and resilient IT services and support.
- Building a world-class performance-focused user experience control centre.
- Exploiting and enhancing hybrid cloud services.
- Protecting and securing our services.
- Developing our people, capability and skills.
If this sounds like you, apply today!
Job description
The Identity Team delivers authentication, authorisation and identity governance services across DWP, supporting both human and non-human identities. Built on Microsoft Active Directory and Microsoft Entra ID, the team is responsible for critical identity capabilities including Identity Governance and Administration (IGA), Joiner-Mover-Leaver (JML) processes, Privileged Access Management (PAM), Multi-Factor Authentication (MFA), Single Sign-On (SSO), PKI, certificate and secrets management.
As a Senior Infrastructure Engineer, you will:
- Provide technical leadership for enterprise-scale identity services across on-premises and cloud platforms, including Microsoft Azure, Amazon Web Services (AWS) and Oracle Cloud Infrastructure (OCI).
- You will help deliver DWP's Identity strategy by strengthening identity governance, advancing Zero Trust principles, modernising access management capabilities, and improving the security and resilience of critical services.
- Work closely with Security, Architecture, DevOps, SRE and supplier teams, you will design and implement secure identity solutions, enhance JML processes through automation, and support privileged access capabilities using technologies such as Microsoft Entra Privileged Identity Management (PIM) and CyberArk.
This is a unique opportunity to play a pivotal role in shaping the future of Identity and Access Management across one of the UK's largest and most complex IT environments. You'll help drive innovation, influence strategic direction and make a real impact on services used by millions.
Please note: This role will require participation in an on call rota, which would involve occasional work outside normal business hours. Further details will be provided to successful candidates during the recruitment process.
Person specification
When giving details in your employment history and personal statement you should highlight your experience in line with essential criteria below:
- Lead Criterion Demonstrable expertise in Microsoft Active Directory and Microsoft Entra ID, including the design, implementation, support and optimisation of enterprise-scale identity and access management services with strong experience of hybrid identity solutions using Microsoft Entra Connect
- Significant experience delivering Identity and Access Management (IAM) services within a large, complex enterprise environment, working effectively across internal teams, multiple suppliers and third-party service providers.
- Strong experience of Identity Governance and Administration (IGA) and Joiner-Mover-Leaver (JML) lifecycle management, including access provisioning, role management, automation, auditing and compliance controls.
- Practical experience designing and implementing modern authentication and authorisation solutions, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, federation, and application integration with Microsoft Entra ID.
- Proven experience implementing and operating Privileged Access Management (PAM) and Privileged Identity Management (PIM) solutions, including privileged account governance, Role-Based Access Control (RBAC), Just-in-Time (JIT) access, and technologies such as Microsoft Entra PIM or CyberArk.
- Experience applying Zero Trust principles to identity architectures, including least-privilege access, identity protection, privileged access controls and threat mitigation, with the ability to provide technical leadership and influence stakeholders at all levels.
If you would like to learn more about the role, please contact Richard.Hanley@dwp.gov.uk.