Über diese Security Engineer - Identity & Access Management (Ghent) Stelle bei D-ploy
D-ploy is a dynamic IT and Engineering Solutions company operating across Europe and the USA, including Switzerland, Germany, the Czech Republic, Austria and the UK. We are committed to delivering reliable and efficient services to our clients through strong partnerships and a people-focused culture.
We are looking for an experienced Security Engineer specializing in Identity and Access Management to strengthen the security of enterprise identities, authentication services, privileged access and access governance processes.
This is a hands-on role combining security engineering, operational ownership and continuous improvement. You will design, implement and maintain identity security controls, reduce access-related risks and contribute to broader Zero Trust initiatives.
You will work closely with Infrastructure, Cloud, Workplace Technology, Enterprise Architecture, HR, application owners, Security Operations and external technology partners.
Responsibilities:
- Manage and improve security controls for employee, contractor, partner, service and privileged identities throughout their lifecycle.
- Contribute to and, when required, lead identity security and access governance projects.
- Configure, maintain and enhance security controls across Microsoft Entra ID, Okta and other IAM platforms.
- Manage Conditional Access, Multi-Factor Authentication, passwordless authentication and risk-based access policies.
- Develop and maintain identity security standards, authentication requirements and access governance guidelines.
- Ensure roles, permissions, service identities and privileged accounts are properly documented and governed.
- Improve processes for joiners, movers and leavers, access reviews, access certification and service account management.
- Support the implementation and governance of Role-Based Access Control across applications and technology platforms.
- Review security-sensitive changes and participate in identity-related technical risk assessments.
- Translate identified risks into practical remediation plans with clear actions, owners and timelines.
- Help reduce excessive permissions, standing privileges and unnecessary local administrator access.
- Coordinate privileged access activities, including Privileged Identity Management and administrative role reviews.
- Collaborate with Enterprise and Security Architecture teams on identity strategy, authentication models and Zero Trust principles.
- Support internal audits, external assessments and regulatory reviews.
- Work with Security Operations and Incident Response teams to ensure identity events generate appropriate logs and security telemetry.
- Assist with investigations involving compromised identities, suspicious authentication activity or access control weaknesses.
Requirements
- At least five years of relevant experience in Identity and Access Management, Security Engineering, Cybersecurity Engineering or Security Architecture.
- Strong hands-on experience with enterprise IAM technologies, particularly Microsoft Entra ID and Okta.
- Strong knowledge of authentication, authorization, federation, identity provisioning and deprovisioning.
- Practical experience with Conditional Access, Multi-Factor Authentication, Identity Protection, Privileged Identity Management and access governance.
- Experience administering and securing Okta environments.
- Good understanding of identity and authentication protocols, including SAML, OAuth 2.0, OpenID Connect and SCIM.
- Strong understanding of Privileged Access Management and least-privilege principles.
- Knowledge of Role-Based Access Control, entitlement management, access certification and segregation of duties.
- Experience implementing and governing authentication, authorization, privileged access and identity governance controls.
- Experience supporting IAM transformation programmes, access governance initiatives or Zero Trust implementations.
- Familiarity with Microsoft Defender, ServiceNow or comparable security and IAM tools.
- Ability to translate security requirements and technical risks into clear operational actions and business outcomes.
- Confidence working with technical teams, application owners, business stakeholders and external suppliers.
- Familiarity with security standards and frameworks such as ISO 27001, NIS2, Zero Trust and CIS Controls.
- Experience with PowerShell, Microsoft Graph, APIs or workflow automation tools is highly desirable.
- Experience in regulated, security-sensitive or audit-intensive environments is an advantage, particularly within life sciences, pharmaceuticals or financial services.
- Familiarity with AI or Large Language Model platforms would be considered an advantage.
- Relevant security or identity certifications are welcome but not mandatory.
- Valid criminal record extract, not older than three months, required.
Benefits
- Broad range of tasks and responsibilities
- Friendly and international working environment
- Professional development opportunities
- Referral program (“Fishing for Friends”)
- Company-sponsored events
Is IT in your DNA?