hirly

Capgemini

Senior Identity Infrastructure Engineer

Manchester, Inverness, GB

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Capgemini first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Senior
Country
GB
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About the job you’re considering

We are seeking an experienced Senior Identity Infrastructure Engineer to support and maintain the core identity infrastructure platforms that underpin the organisation's Identity and Access Management (IDAM) services.

The successful candidate will be responsible for the administration, support, security, and continuous improvement of the Active Directory, PKI, DNS, Group Policy, and authentication infrastructure. They will work closely with the wider IDAM team, supporting critical identity services and providing L2/L3 operational support across the identity estate where required.

This role requires a highly capable infrastructure engineer with deep expertise in Microsoft Active Directory and Public Key Infrastructure (PKI), combined with a strong understanding of enterprise identity technologies and authentication services.

The position is based 5 days per week within secure facilities in either Inverness or Manchester, working closely with security, engineering, and IDAM teams to ensure the availability, resilience, and security of critical identity platforms.

Your role:

Active Directory Infrastructure

  • Administer and maintain enterprise Active Directory forests, domains, and domain controllers.
  • Manage Active Directory Sites and Services, replication topology, trusts, and directory services infrastructure.
  • Administer AD-integrated DNS and support authentication services across the enterprise.
  • Manage and maintain Group Policy architecture, including policy design, implementation, troubleshooting, and lifecycle management.
  • Support Active Directory backup, recovery, disaster recovery, and business continuity processes.
  • Monitor platform health, performance, security, and replication.
  • Support Active Directory upgrades, migrations, consolidation projects, and infrastructure improvements.
  • Implement and maintain Active Directory security hardening standards and privileged access controls.

Public Key Infrastructure (PKI)

  • Administer and support Microsoft Active Directory Certificate Services (AD CS).
  • Manage Certificate Authorities, certificate templates, certificate enrolment, and certificate lifecycle processes.
  • Support Offline Root CA and Issuing CA infrastructure.
  • Administer Certificate Revocation Lists (CRL), Authority Information Access (AIA), and certificate distribution services.
  • Monitor certificate compliance, renewals, revocations, and expiration management.
  • Maintain PKI operational documentation, recovery procedures, and security standards.
  • Support cryptographic and certificate-related troubleshooting across infrastructure and security platforms.

Identity Infrastructure & Authentication Services

  • Support Microsoft Entra Connect and hybrid identity infrastructure.
  • Maintain LDAP, LDAPS, Kerberos, and NTLM authentication services.
  • Support integrations between Active Directory and enterprise identity platforms including MIM, Entra ID, Okta, and BeyondTrust.
  • Assist with identity-related service improvements and platform optimisation initiatives.
  • Support authentication, directory, and identity infrastructure incidents through to resolution.
  • Work collaboratively with the IDAM engineering team to support critical identity lifecycle services.

IDAM Support Activities

  • Provide L2/L3 support for identity-related incidents and service requests.
  • Assist with troubleshooting user provisioning, synchronisation, and authentication issues.
  • Support MIM, Entra ID, Okta, and BeyondTrust integrations where infrastructure expertise is required.
  • Collaborate with IDAM engineers to investigate root causes and implement long-term solutions.
  • Support operational activities across the wider identity ecosystem during periods of increased demand.

Automation & Continuous Improvement

  • Develop and maintain PowerShell automation for identity infrastructure administration.
  • Drive service improvements, platform optimisation, and operational efficiencies.
  • Contribute to security improvement initiatives, vulnerability remediation, and infrastructure modernisation.
  • Produce and maintain technical documentation, operational procedures, and support runbooks.

You can bring your whole self to work. At Capgemini building an inclusive future is part of everyday life and will be part of your working reality. We have built a representative and welcoming environment, for everyone.

Your skills and experience

Active Directory

  • Extensive hands-on experience administering enterprise Active Directory environments.
  • Strong knowledge of:
  • Active Directory Domain Services (AD DS)
  • Active Directory Sites and Services
  • Forest and Domain Administration
  • DNS
  • Group Policy
  • LDAP / LDAPS
  • Kerberos Authentication
  • Trusts and Replication
  • AD Backup and Recovery
  • Experience troubleshooting complex authentication and directory service issues.

PKI

  • Strong experience administering Microsoft Active Directory Certificate Services (AD CS).
  • Experience managing:
  • Certificate Authorities
  • Certificate Templates
  • CRL and AIA Infrastructure
  • Certificate Lifecycle Management
  • Certificate Enrolment Services
  • Key Recovery and Archival
  • Experience supporting enterprise PKI environments.

Infrastructure Platforms

  • Windows Server 2016/2019/2022 administration.
  • PowerShell scripting and automation.
  • Security hardening and privileged administration.
  • High Availability and Disaster Recovery planning.
  • Infrastructure monitoring and operational support.

Identity Technologies

  • Working knowledge of:
  • Microsoft Entra ID
  • Microsoft Entra Connect / Cloud Sync
  • Microsoft Identity Manager (MIM)
  • Okta
  • BeyondTrust
  • Understanding of:
  • Identity and Access Management (IAM)
  • Joiner, Mover, Leaver Processes
  • Identity Lifecycle Management
  • Authentication and Authorisation
  • Access Governance
  • Role-Based Access Control (RBAC)

Desirable Skills

  • Experience supporting Microsoft Identity Manager (MIM).
  • Experience supporting hybrid identity architectures.
  • Experience with Okta administration and integration.
  • Knowledge of BeyondTrust PAM or Endpoint Privilege Management.
  • Experience with Tier 0 administration and privileged access models.
  • Familiarity with CrowdStrike, Zscaler, and security platform integrations.
  • Experience supporting highly regulated or secure environments.
  • Knowledge of ITIL-based operational support models.
  • Experience supporting large-scale enterprise identity programmes.

We are a Disability Confident Employer

Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government’s Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:

  • Declare they have a disability, and
  • Meet the minimum essential criteria for the role.

Please opt in during the application process.

Your security clearance and pre-employment checks

If you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service)

Some roles will also require an additional level of security clearance:

Security Check (SC) Clearance:

To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance .

To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements.

Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality.

Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process.

Make it real – what does it mean for you?

Flexibili

Original posting on Capgemini's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job