IAM Engineer – Identity & Access Management Engineer

Finning.wd3.external

Apply to this job
Cannock, GB Until 9/29/2026 First posted July 31, 2026 Last posted July 31, 2026
Job description

Company:

Finning International Inc.

Number of Openings:

1

Worker Type:

Permanent

Position Overview:

Finning is the world's largest Caterpillar dealer. We pride ourselves on delivering exceptional customer experiences and innovative solutions. We are looking for an Identity & Access Management (IAM) Engineer who will drive authentication excellence across our global enterprise.

Job Description:

The IAM Engineer will co-own and advance our authentication capabilities end-to-end. In this role, you will work with leading technologies such as Entra ID, OKTA, ClearPass/NPS, and on-prem Active Directory, ensuring secure, modern, and highly available authentication services worldwide.

Key Responsibilities:

Authentication & Identity Management

  • Manage Entra ID configurations for SSO, MFA, and Conditional Access baselines.

  • Oversee app registrations, enterprise app approvals, and environment hygiene.

  • Govern admin consent for Graph/API scopes.

  • Support a multi-domain Active Directory environment and ensure optimised global authentication.

  • Maintain overall GPO health and configuration management.

  • Lead transitions between On-Prem AD and Entra ID.

  • Enhance authentication using FIDO2 and phish-resistant methods.

  • Monitor authentication service health and publish regular performance and risk reports.

Projects & Strategic Initiatives:

  • Implement OIDC/SAML federation patterns and SCIM integrations.

  • Advance Customer IAM journeys and strengthen posture integrations with ClearPass.

  • Drive identity transition projects and collaborate closely with the broader Global IAM team.

Knowledge, Skills and Experience:

  • Relevant IAM experience, with strong expertise in Active Directory and Entra ID.

  • Hands-on experience managing and supporting OKTA, ClearPass, and NPS (asset).

  • Direct experience with AD → Entra ID transitions.

  • Proficiency in automation/scripting, including PowerShell and Power Automate.

  • Proven ownership of GPO design, health, and lifecycle management.

  • Deep understanding of modern authentication technologies and industry standards.

  • Microsoft SC-300 or equivalent IAM/security certification desirable

What We Offer:

In addition to a competitive salary, bonus, 25 days holiday, life insurance and up to 7% pension, you will benefit from:

  • Comprehensive benefits package

  • A supportive and collaborative work environment

  • Opportunities for professional growth and development

At Finning, we prioritize creating a diverse and inclusive environment. We are proud to be an equal opportunity employer, and we actively encourage all individuals to express themselves and achieve their full potential. As a company, we continuously strive to enhance our outreach to individuals of all backgrounds and identities. We do not discriminate against applicants based on gender identity, race, national and ethnic origin, religion, age, sexual orientation, marital and family status, and/or mental or physical disabilities. Furthermore, Finning is committed to collaborating with and providing reasonable accommodations /adjustments to individuals with disabilities. If you require an adjustment/accommodation at any point during the recruitment process, please inform your recruiter. Finning is a forces-friendly employer having signed the Armed Forces Covenant, and pledges to treat those who serve or have served in the armed forces, and their families fairly.

About this role

Summary

Manage enterprise IAM systems, support authentication technologies, lead transition projects, ensure security compliance.

Job title

IAM Engineer – Identity & Access Management Engineer

Experience level

professional level

Industry

software

Location requirements

Cannock, GB, on-site; remote not specified

Salary

Not specified

Management role

No

Skills & keywords

Required skills

Active DirectoryEntra IDOKTAPowerShellGPO

Preferred skills

Microsoft SC-300FIDO2SAMLOIDCSCIM

Specializations

identity managementauthenticationActive DirectoryEntra IDIAM
Locations

Structured locations inferred from the posting.

Cannock, UK

On-site City