Identity & Infrastructure Engineer (Security-Aware)
If you love beauty, you’re in the right place.
As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go-to destination for worldwide beauty discovery.
Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands.
Identity & Infrastructure Engineer | Space NK, London
Job title: Identity & Infrastructure Engineer
Reporting to: Platform Engineering Principal
Location: London/hybrid
Department: Technology
Role Overview
The Identity & Infrastructure Engineer will support, maintain and modernise Space NK’s identity and infrastructure services across a hybrid Microsoft environment.
This hands-on engineering role is responsible for the administration and continuous improvement of Microsoft Entra ID, Active Directory, Windows infrastructure, Intune and Azure services. The role will help strengthen identity security, improve operational reliability and support Space NK’s transition towards a cloud-native, Entra ID-centric operating model.
Working closely with Security, Cloud, Infrastructure and Application teams, the engineer will implement secure identity controls, resolve technical issues and deliver defined areas of project and transformation work. The role will apply automation, robust governance and secure-by-default principles across identity, infrastructure and endpoint management.
The successful candidate will have strong foundations in Microsoft identity and infrastructure technologies, together with the capability and ambition to develop deeper expertise in cloud identity, security, automation and modern endpoint management.
Key Responsibilities
Identity and Access Management
· Administer and support Microsoft Entra ID and Active Directory Domain Services within the hybrid identity environment.
· Implement, maintain and troubleshoot SSO, MFA, Conditional Access and passwordless authentication.
· Support RBAC, Privileged Identity Management and least-privilege access controls.
· Support identity lifecycle activities, including joiner, mover and leaver processes and access reviews.
· Administer and troubleshoot Entra Connect, Azure AD Connect and Cloud Sync.
· Support application onboarding to Entra ID using SAML, OAuth 2.0 and OpenID Connect.
· Investigate authentication, authorisation and account-related issues across cloud and on-premises environments.
Active Directory and Infrastructure
· Administer and support Active Directory, including users, groups, computers, organisational units, Group Policy and domain services.
· Monitor and troubleshoot domain controllers, replication, DNS, DHCP, authentication and Windows Server infrastructure.
· Support Active Directory Certificate Services and certificate lifecycle activities where required.
· Maintain and troubleshoot Group Policy while supporting the migration of appropriate configurations to modern cloud management.
· Support the secure management of service accounts and non-human identities.
· Maintain technical documentation, configuration records and operational procedures.
Entra ID, Intune and Modern Device Management
· Support Windows device management through Microsoft Intune.
· Assist with the migration from domain and hybrid joined devices to Microsoft Entra Join.
· Support Windows Autopilot, device provisioning and lifecycle management.
· Implement and maintain Intune configuration profiles, compliance policies and security baselines under agreed standards.
· Assist with the migration of appropriate legacy Group Policy settings to Intune.
· Troubleshoot device enrolment, compliance, authentication and registration issues.
Security, Governance and Compliance
· Apply Zero Trust, least-privilege and secure-by-default principles to identity and infrastructure engineering.
· Work with Cyber Security to implement agreed identity security controls and investigate identity-related alerts.
· Support access reviews, privileged access reviews and entitlement governance.
· Assist with audit evidence and remediation activities relating to SOX, PCI DSS, GDPR and other applicable requirements.
· Support incident response by providing identity information, access logs and technical assistance with containment activities.
· Contribute to reducing legacy authentication and unnecessary privileged access.
Monitoring, Automation and Continuous Improvement
· Monitor identity and infrastructure services using Azure Monitor, Log Analytics, Entra logs and Microsoft Defender.
· Troubleshoot authentication, synchronisation and infrastructure issues, escalating complex problems where appropriate.
· Automate repeatable administration activities using PowerShell, Microsoft Graph API, Azure CLI and related services.
· Identify opportunities to improve reliability, security and operational efficiency through automation and process improvement.
· Contribute to projects supporting Space NK’s wider identity and infrastructure modernisation programme.
Qualifications, Knowledge and Experience
Experience
· Hands-on experience administering Microsoft Active Directory and supporting Active Directory Domain Services.
· Practical experience with Microsoft Entra ID, including users, groups, roles and enterprise applications.
· Experience supporting MFA, Conditional Access, SSO and identity access controls.
· Experience with Windows Server, Group Policy and core Microsoft infrastructure services.
· Experience with Microsoft Intune or another modern endpoint management platform.
· Practical experience using PowerShell to support administration and automation.
· Good troubleshooting and problem-solving skills across hybrid Microsoft environments.
· A sound understanding of information security, change control and operational support practices.
Candidates are not expected to be experts in every technology listed. Strong technical foundations, sound judgement and a clear commitment to developing expertise in modern Microsoft identity and cloud technologies are essential.
Technical Skills
Experience in the following areas would be advantageous:
· Entra PIM and Entra ID Governance, including Access Reviews.
· Windows Autopilot, Entra Join and Hybrid Entra Join.
· Entra Connect, Azure AD Connect or Cloud Sync.
· Active Directory Certificate Services and PKI.
· Microsoft Defender for Identity or Microsoft Sentinel.
· Azure Monitor and Log Analytics.
· Microsoft Graph API or Azure automation.
· Passwordless authentication, FIDO2 and passkeys.
· Application SSO integration.
· SOX, PCI DSS, GDPR or ISO 27001 environments.
· General Microsoft Azure administration.
Qualifications and Certifications
A degree in Computer Science, Cyber Security, Infrastructure Engineering or a related discipline is advantageous, although equivalent practical experience will also be considered.
Relevant professional experience in identity, infrastructure, Microsoft 365, Azure or a related engineering role is expected; technical capability, delivery experience and potential are more important than a specific number of years.
Relevant certifications are desirable but not mandatory, including:
· Microsoft Identity and Access Administrator Associate (SC-300).
· Microsoft Endpoint Administrator Associate (MD-102).
· Microsoft Azure Administrator Associate (AZ-104).
· Microsoft Security, Compliance and Identity Fundamentals (SC-900).
· Microsoft Azure Fundamentals (AZ-900).
· CompTIA Security+ or equivalent.
Candidates actively working towards relevant certifications are also encouraged to apply.
Skills and Attributes
· Strong interest in identity, Microsoft cloud technologies and security.
· Ability to take ownership of assigned technical work while recognising when escalation or guidance is required.
· Logical and methodical approach to troubleshooting.
· Clear written and verbal communication skills.
· Ability to collaborate effectively across Platform Engineering, Cyber Security, Cloud, Infrastructure and Application teams.
· Commitment to continuous learning and sharing technical knowledge.
· Good understanding of change control, documentation and production support.
· Ability to balance operational support with project and transformation activities.
· Proactive approach to automation and continuous improvement.
Development and Progression
This role provides the opportunity to develop deeper capability across Entra ID, Identity Governance, PIM, Conditional Access, Intune, modern authentication, automation and Zero Trust.
As technical capability and experience grow, the engineer will take increasing responsibility for complex changes, technical solutions and project delivery, providing a natural development path towards a Senior Identity & Infrastructure Engineer role.
Please note that only successful candidates will be contacted.
All applicants must have the right to live and work in the UK.
If you want to find out more about us, what it is like to work for us, all about our benefits, and our pledges on Diversity, Inclusion and Belonging, please visit our website.
Space NK are an equal opportunities employer.
How We Will Use Your Information
We will use the information you provide to us with your job application to help us process your application for the specific job you have applied for. If you apply speculatively, we will process your application for the job/relevant business area that you detail within your email.
Please note that our current system does not use an automated filtering system.
All applications made via the website, through a third-party website or in-store will be kept on file for a period of 12 months.
This information will be retained and used to assess your suitability to similar positions that may arise in the future, or if the initial vacancy becomes live again during the 12-month period. If you would prefer us to not hold your information on file/ you wish to be ‘forgotten’ if you are not offered a position with Space NK, please email your ‘right to be forgotten’ to our recruitment email address with RIGHT TO BE FORGOTTEN as the title of the email. We will always inform you when we have deleted your application details, otherwise we will treat your application as consent to us holding this information.
- Team
- Technology - Engineering
- Location
- London (Head Office)
- Remote status
- Hybrid