Information Security Indentity Engineer
Cantor Fitzgerald/BGC London, England, United Kingdom
Financial Services · 10,001+ employees
About the role
The engineer will design, implement, and maintain authentication systems and identity governance platforms while integrating IAM controls into DevSecOps pipelines. They are also responsible for enforcing IAM policies across cloud environments and supporting global incident response and audit compliance.
What they look for
Requirements
Candidates must have a bachelor's degree or equivalent experience with 3-5 years of IAM experience in the financial services sector. Proficiency in authentication protocols, PAM solutions, IGA platforms, and scripting languages like PowerShell or Python is required.
Full description
Cantor Fitzgerald’s Global Information Security team is seeking a proactive Junior Information Security Engineer to join our fast‑paced environment in London. You will plan, coordinate, and execute IAM initiatives across cloud and on‑premise platforms, partner with DevSecOps, support incident response, and ensure compliance with industry standards while continuously improving documentation and automation.
Responsibilities
- Design, implement, and maintain authentication systems (LDAP, AD, Kubernetes, Microsoft Entra) using OIDC, OAuth, and SAML protocols.
- Manage privileged access solutions (CyberArk, Keeper) and identity governance platforms (SailPoint, IBM, Oracle).
- Integrate IAM controls into DevSecOps CI/CD pipelines and automate workflows with AI/automation tools.
- Define and enforce IAM policies across AWS, Azure, and GCP cloud environments.
- Document configurations, standards, and procedures in centralized repositories and maintain run‑books.
- Support global incident response, including tabletop exercises and post‑mortem analysis.
- Provide evidentiary support and remediation tracking for audit, compliance, and risk assessments.
- Advise project teams, application owners, and infrastructure services on security controls and best practices.
- Monitor security metrics, generate reports, and act as regional IAM incident response point of contact.
- Utilize service, incident, and change management tools (ServiceNow, Dynamics 365) to track and resolve issues.
Qualifications
- Bachelor’s degree or equivalent experience; 3‑5 years IAM experience in financial services.
- Hands‑on experience with Microsoft Entra, Okta, Ping One, Auth0, and authentication protocols (OAuth, OIDC, SAML).
- Proven work with PAM solutions (CyberArk, Keeper) and remote‑desktop security tools.
- Deployment and administration of IGA platforms such as SailPoint, Saviynt, or Oracle.
- Strong scripting/automation skills (PowerShell, Python) and API integration experience.
- Familiarity with ticketing and PMO tools (ServiceNow, Dynamics 365, Smartsheet, Monday.com).
- Knowledge of cloud IAM across AWS, Azure, GCP and related security services.
- Experience with SIEM/SOAR (Splunk, PAN Cortex) and firewall technologies (Palo Alto, F5) is a plus.
- Excellent communication, documentation, and cross‑team collaboration abilities.
- Proactive, detail‑oriented, able to manage multiple priorities in a fast‑paced environment.