Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Workplace technology - identity - systems engineer iii

Welwyn Garden City
Tesco Technology
Systems engineer
Posted: 6 September
Offer description

Overview

Workplace Technology - Identity - Systems Engineer III – Tesco Technology

This role sits within the Workplace Identity team, part of the Tesco Workplace Technology engineering function. You will be a senior engineer and domain expert in Identity technologies, leading the full technology lifecycle — from strategy and design through to engineering, testing, and delivery — for the services that underpin our digital colleague experience.


Key Responsibilities

* Strategic Leadership: Act as a senior engineer for Identity within the Workplace Technology team, setting the direction, roadmap, and architectural standards for core identity services including Active Directory, Entra ID, PKI, and modern authentication protocols. Align identity strategy to Tesco’s broader digital workplace vision, collaborating with architects, product managers, security, and infrastructure teams. Stay ahead of market trends and emerging technologies in identity and access management, advocating for their adoption where beneficial. Design and deliver secure, scalable identity platforms that support global business needs and enable modern digital workplace capabilities. Engineer solutions across the identity lifecycle: concept, evaluation, prototyping, testing, production deployment, and service transition. Implement automation, codification (IaC), and CI/CD practices to drive efficiency and resilience. Act as a senior escalation point for complex issues related to authentication, replication, certificate lifecycle, hybrid identity, and directory services.
* Operational Excellence: Build systems that are secure, stable, and easy to operate, with monitoring, alerting, and lifecycle planning embedded by design. Champion remediation of legacy identity components and uplift the security and operational posture of all identity services. Ensure knowledge is well documented and transitions smoothly into operational support with clear SLAs and handover practices.
* Governance & Security: Drive adoption of Zero Trust principles, secure admin tiering, modern auth standards, conditional access, and multifactor authentication. Own the health, design, and policy of PKI infrastructure and associated services (including certificate templates, CRLs, and HSMs). Work with Security and Risk teams to ensure compliance with internal controls, regulatory obligations, and audit findings.
* Leadership & Influence: Represent Workplace Technology Identity Engineering across Tesco Technology and broader cross-functional initiatives. Lead by example in engineering excellence, stakeholder engagement, and mentoring. Promote a culture of simplification, technical rigour, and continuous improvement.


You will need


Required Skills & Experience

* Deep expertise in:
* Active Directory: design, hardening, replication, domain controller lifecycle, GPOs, admin tiering.
* Azure AD / Entra ID: hybrid identity, conditional access, MFA, identity protection, SSO, SCIM.
* Public Key Infrastructure (PKI): policy, lifecycle, templates, automation, CRL/OCSP, HSMs.
* Demonstrated ability to design and deliver identity platforms in large, complex environments.
* Understanding of identity’s role in enterprise security frameworks and compliance requirements.
* Proficiency with scripting and automation tools (PowerShell, Terraform, etc.).
* Familiar with monitoring, backup, recovery, and DR practices for identity systems.
* Ensure identity services are designed with built-in resilience, supporting high availability, fault tolerance, and fast recovery across hybrid environments.
* Contribute to and maintain Business Continuity Plans (BCPs), ensuring critical identity components are documented with clear recovery priorities.
* Design and validate Disaster Recovery (DR) strategies for directory services, authentication systems, and PKI, with regular failover testing and documented RTO/RPO.
* Define and verify backup and recovery plans for identity infrastructure, including domain controllers, certificate authorities, and configuration artifacts.
* Estimate engineering effort and support the costing of identity-related projects, including resource planning, licensing, infrastructure, and delivery timelines.
* Partner with Workplace Technology leadership to shape and manage budgets, forecasts, and business cases for new identity initiatives.


Nice to Have

* Experience integrating identity across Linux, SaaS, and multi-cloud platforms.
* Understanding of M365, Microsoft ecosystem, and their dependency on robust identity infrastructure.
* Exposure to identity governance, entitlement management, and lifecycle workflows.


Complementary Skills

* Strong collaboration and influencing skills across engineering, operations, product, and security domains.
* Commercial and vendor awareness to support technology selection, licensing decisions, and cost optimisation.
* Strong written and verbal communication skills, with the ability to engage both engineers and senior stakeholders.
* A proactive, accountable, and resilient mindset — aligned to Tesco’s values and the mission of the Workplace Technology team.


Whats in it for you?

We’re all about the little helps. That’s why we make sure our Tesco colleague benefits package takes care of you – both in and out of work. Click Here to find out more!

* Annual bonus scheme of up to 20% of base salary
* Holiday starting at 25 days plus a personal day (plus Bank holidays)
* Private medical insurance
* 26 weeks maternity and adoption leave (after 1 year’s service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay; 4 weeks fully paid paternity leave
* Free 24/7 virtual GP service, EAP for you and your family, access to experts for mental wellbeing


About Us

Our vision at Tesco is to become every customer’s favourite way to shop, whether at home or on the move. Our core purpose is “Serving our customers, communities and planet a little better every day.” We are an inclusive culture that values diversity and provides equal opportunities. We are a Disability Confident Leader and offer accessible recruitment and support. Details on accessibility support are available.

We’re a large organisation with a blended working pattern and opportunities across full-time and part-time roles. We work in a hybrid model; offices are a place to connect, collaborate and innovate. Internal applicants should speak to the Hiring Manager about arrangements.


Seniority level

* Mid-Senior level


Employment type

* Full-time


Job function

* Information Technology
* Retail

Note: This description reflects the role and responsibilities of the position. It does not constitute a contract of employment.

#J-18808-Ljbffr

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Electrical electronic architect/systems engineer
Stevenage
Morson Talent
Systems engineer
Similar job
System engineer (m/w/d) - cloud
Watford
SHD Group Holding GmbH
Systems engineer
Similar job
Test rmo - principal systems engineer
Stevenage
Expleo Group
Systems engineer
See more jobs
Similar jobs
It jobs in Welwyn Garden City
jobs Welwyn Garden City
jobs Hertfordshire
jobs England
Home > Jobs > It jobs > Systems engineer jobs > Systems engineer jobs in Welwyn Garden City > Workplace Technology - Identity - Systems Engineer III

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save