Cybersecurity - IAM Engineer, PKI & Certificate Services
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
Introduction to the role
Every medicine we discover, every clinical trial we run and every patient record we hold depends on our systems and science being secure. At AstraZeneca, Cyber Security protects the infrastructure behind drug discovery, clinical development, manufacturing and the delivery of medicines to patients around the world.
As a Cybersecurity – IAM Engineer, PKI & Certificate Services , you will help protect the digital identities, certificates and authentication services that enable our researchers, clinicians and colleagues to access critical systems securely and reliably.
You will support, maintain and improve enterprise Identity and Access Management services across on-premises and cloud environments, with a particular focus on Active Directory Certificate Services and Public Key Infrastructure . Working with Active Directory, Microsoft Entra ID and hybrid identity technologies, you will help deliver secure authentication, authorization, certificate-based security and identity lifecycle management at enterprise scale.
Working across Cyber Security, infrastructure, cloud, application and support teams, you will resolve complex identity and certificate-related issues, support high-priority incidents and automate IAM processes. Your work will help protect the integrity and continuity of the science behind life-changing medicines.
Accountabilities
In this role, you will:
- Support, maintain and improve enterprise IAM services across on-premises and cloud environments, ensuring secure and reliable authentication, authorization, certificate-based security and identity lifecycle management.
- Support Active Directory Certificate Services and Public Key Infrastructure, including certificate lifecycle management and certificate-based authentication.
- Administer Active Directory Domain Services, including domain controllers, organizational units, trusts and directory infrastructure.
- Support and troubleshoot hybrid identity environments integrating Active Directory and Microsoft Entra ID, including identity synchronization and provisioning processes.
- Manage and support authentication services, including multifactor authentication, Self-Service Password Reset, passwordless authentication, Conditional Access and federation services.
- Support joiner, mover and leaver processes, including user provisioning, deprovisioning, group management and access reviews.
- Administer Microsoft Entra ID services, including enterprise applications, application registrations, authentication methods and identity governance capabilities.
- Investigate and resolve issues involving certificate services, authentication, account access, identity synchronization, group memberships and authorization.
- Troubleshoot and maintain Active Directory replication, DNS, DHCP, domain controller health, Kerberos authentication, LDAP connectivity and Group Policy Objects.
- Implement and maintain identity security controls and privileged access management processes in line with established security, risk, compliance and architectural standards.
- Support high-priority incidents, including triage, prioritization, stakeholder communication, escalation management and service restoration.
- Manage operational support, project activities, incidents, service requests and unplanned work according to business impact, urgency, risk and established service management processes.
- Identify opportunities to automate repetitive IAM and certificate-management activities using PowerShell and other technologies to improve efficiency, consistency and service reliability.
- Maintain technical documentation, runbooks, operational procedures and knowledge articles to support service continuity and audit readiness.
- Collaborate with business users, Cyber Security, infrastructure, cloud, application and support teams, managing expectations and ensuring requests follow approved support channels and processes.
Essential experience, skills and knowledge
You will need:
- Experience with Active Directory Certificate Services and/or Certificate Services and Public Key Infrastructure .
- Knowledge of certificate lifecycle management, certificate templates and certificate-based authentication.
- Strong experience supporting Active Directory Domain Services in a complex enterprise environment.
- Hands-on experience administering Microsoft Entra ID , including identity synchronization, authentication methods and enterprise applications.
- Experience supporting hybrid identity environments integrating on-premises Active Directory with cloud identity platforms.
- A strong understanding of authentication and federation technologies, including Kerberos, LDAP, SAML, OAuth, OpenID Connect and federation services.
- Experience managing and troubleshooting Group Policy Objects