Principal IDAM Engineer
OFGEM · Cardiff, Wales
Principal IDAM Engineer at OFGEM, based in Cardiff, Wales, paying £63,443 - £86,547 per annum. This is a permanent role.
- Salary
- £63,443 - £86,547 per annum
- Location
- Cardiff, Wales
- Contract
- Permanent
- Posted
- 14 hours ago
- Closes
- 2 Nov 2026
- Sector
- Security
About 27% above the going rate for security
Reference 9111777ad8671fdc40783c3a72d2ce55cdd153dc
About the role
Job summary
Across government, secure identity and access management is no longer a purely technical concern; it is fundamental to protecting organisational data, maintaining resilience and enabling secure, seamless access to services. As digital transformation accelerates and reliance on cloud-based platforms grows, strong Identity and Access Management (IDAM) capabilities are critical to ensuring that systems remain secure, compliant and fit for the future. Ofgem plays a vital role in the UK’s energy system, protecting consumers and enabling a more secure, fair and sustainable energy future, and effective security and identity management is central to this mission.
Ofgem is on a significant transformation journey. Within the Digital, Data and Security Services (DDSS) directorate, we are strengthening the foundations of our technology and security landscape, modernising infrastructure and enhancing access control across our technology estate. As part of this, we are developing a comprehensive IDAM capability that supports secure access, improves user experience and meets regulatory and compliance requirements.
As a Principal IDAM Engineer, you will play a central role in defining and delivering Ofgem’s identity and access management strategy. You will be responsible for shaping and implementing enterprise-wide IDAM solutions, ensuring that identity governance, access controls and lifecycle management processes are robust, scalable and aligned with industry standards.
This is a senior, technically focused role with leadership responsibility. You will work across architecture, infrastructure, security and delivery teams, translating business and regulatory requirements into secure, practical solutions. You will also provide leadership and mentoring within the team, strengthening capability and embedding best practice in identity and access management across the organisation.
Job description
You will be responsible for:
- Leading the development and implementation of Ofgem’s IDAM strategy, ensuring secure, compliant and efficient access to systems and data across the organisation.
- Establishing and enforcing identity governance frameworks, including policies, standards and controls aligned with industry best practices such as ISO 27001 and NIST.
- Designing and implementing access control models, including Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC), ensuring consistency and security across platforms.
- Overseeing user identity lifecycle management, including provisioning, deprovisioning and automated access workflows integrated with HR systems and enterprise directories.
- Implementing controls and monitoring mechanisms for privileged access, reducing risk and ensuring compliance with security requirements.
- Defining integration patterns for IDAM solutions across enterprise applications, cloud services and systems, ensuring interoperability and scalability.
- Leading technical delivery and ensuring that IDAM solutions are secure, robust and aligned with enterprise architecture principles.
- Engaging with senior stakeholders, translating business requirements into effective IDAM solutions and ensuring alignment with organisational goals.
- Mentoring and supporting engineers within the team, building capability and fostering a culture of collaboration, security awareness and continuous improvement.
- Staying abreast of emerging identity and security technologies, ensuring Ofgem adopts modern, effective approaches to identity management.
We are looking for:
A credible, experienced and technically strong identity and access management professional who can lead at both a strategic and operational level. You will bring deep expertise in IDAM architecture and implementation, alongside the ability to operate effectively in a complex, evolving technology environment.
You may come from an infrastructure, security or architecture background, but you will demonstrate:
- Strong experience delivering enterprise-scale IDAM solutions and identity governance frameworks
- Experience implementing user lifecycle management, provisioning and access recertification processes
- Deep understanding of access control models, identity standards and security frameworks
- The ability to design and integrate IDAM solutions across complex environments, including cloud and on-premise systems
- Confidence engaging with senior stakeholders and translating requirements into scalable technical solutions
Relevant certification such as Microsoft Certified: Identity and Access Administrator Associate or Certified Identity and Access Manager (CIAM) is expected (or willingness to achieve).
Experience in government or regulated environments, and exposure to audit and compliance processes, would be advantageous.
This is an opportunity to play a key role in strengthening Ofgem’s security and technology foundations. You will shape how identity and access are managed across the organisation, ensuring that systems are secure, compliant and able to support Ofgem’s critical work at a time when the importance of digital resilience has never been greater.
Person specification
Essential Criteria
- Lead initiatives to automate user provisioning and access recertification processes, integrating IAM solutions with HR systems and directories (Lead Criteria).
- Demonstrable experience in IAM architecture and enterprise-scale identity governance (Lead Criteria).
- Staying abreast of emerging IAM technologies and trends to enhance the organisations security posture.
- Establishment and enforcement of IAM policies and procedures, ensuring compliance with frameworks such as NIST SP 800-53, ISO/IEC 27001 or other relevant standards.
- Implement and enforce access control policies, including access enforcement, supervision, and review.
- User provisioning and lifecycle management.
- Experience preparing for and supporting internal and external audits related to access controls and IAM processes.
Holds or can obtain the following certifications or equivalent:
- Microsoft Certified: Identity and Access Administrator Associate.
- Certified Identity and Access Manager (CIAM).
Desirable Criteria
- Experience establishing continuous monitoring mechanisms to detect and respond to unauthorised access attempts.
#LI-DNI
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Leadership
- Managing a Quality Service
Technical skills
We'll assess you against these technical skills during the selection process:
- You will also be asked to prepare a presentation. Full details of the presentation will be included in the invitation to interview.
Benefits
Alongside your salary of £63,443, OFGEM contributes £18,379 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).Ofgem can offer you a comprehensive and competitive benefits package which includes; 30 days annual leave after 2 years; Excellent training and development opportunities; The opportunity to join the generous Civil Service pension which also includes a valuable range of ben
Reference: 9111777ad8671fdc40783c3a72d2ce55cdd153dc · Posted 14 hours ago · Closes 2 Nov 2026 · Listed via OFGEM
Apply for this job
This role is listed via OFGEM. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.