Global IT Director – Principal Security Engineer

Company: The Boston Consulting Group
Apply for the Global IT Director – Principal Security Engineer
Location: London
Job Description:

Overview

In this role you will lead and implement enterprise-wide IAM programs, shaping authentication, authorization, and identity lifecycle across hybrid environments. You will collaborate with architecture and security teams to align IAM with enterprise strategy, drive secure modernization, and reduce risk. You’ll mentor engineers, own end-to-end IAM delivery, and advocate for automation and passwordless approaches to enable scalable access across workforce, partners, and customers. This is a senior, impact-focused role that blends hands-on engineering with architecture leadership in a fast-paced, collaborative setting.

Responsibilities

  • Own end-to-end delivery of IAM services (identity lifecycle, authentication, authorization, SSO, privileged access)
  • Lead design sessions and IAM integrations for SaaS, on-prem, and AWS cloud (federation, MFA, passwordless)
  • Serve as escalation point for complex IAM issues; perform root-cause analysis and remediation
  • Align IAM with security strategy, compliance, and business objectives with cross-team collaboration
  • Define engineering standards, patterns, and reference architectures for onboarding into IGA, PAM, and SSO
  • Lead modernization initiatives and contribute to audits, risk assessments, and regulatory reviews
  • Mentor and coach IAM engineers, promoting documentation and continuous improvement
  • Oversee IAM deployment across on-prem and cloud environments ensuring high security and availability
  • Lead complex security assessments (threat modeling, red teaming, cloud security reviews)
  • Architect and implement workforce, PAM, and customer IAM ecosystems
  • Advocate for passwordless, adaptive MFA, and AI-driven access orchestration
  • Develop automated provisioning/deprovisioning workflows and integrate with cloud platforms (Azure, AWS, GCP)

Key requirements

  • 10+ years in information security or infrastructure engineering
  • 5+ years hands-on IAM experience
  • Deep IAM stack expertise; strong Microsoft Entra ID and AD knowledge
  • Federation protocols experience (SAML, OIDC, OAuth2)
  • Hybrid multi-cloud IAM design and automation experience
  • Secrets management experience
  • Scripting/programming (PowerShell, Python, or Java) for automation
  • Excellent communication with technical and non-technical stakeholders
  • Strong ownership and ability to work with limited requirements
  • Experience leading large-scale IAM programs and as technical lead or architect
  • Ability to balance security, usability, and operational efficiency with automation focus
  • Security leadership across cloud security and IAM strategy
  • Ability to oversee IAM across on-prem and cloud, and lead security assessments
  • Experience mentoring senior engineers and aligning security initiatives with business goals
  • Thought leadership in passwordless, passkeys, adaptive MFA, and AI-driven strategies
  • Experience with agentic AI tools integrations for identity lifecycle operations
  • Develop automated provisioning/deprovisioning workflows
  • IAM integration with cloud platforms (Azure, AWS, GCP) and SaaS applications
  • strong communication
  • ownership and accountability
  • mentorship
  • Privileged Access Management (CyberArk)
  • Authentication/AuthN (Okta)
  • Federated Identity (EntraID)

…

Posted: October 1st, 2026