UK Health Security Agency

Modern Identity Specialist

Information:

This job is now closed

Job summary

Job title - Modern Identity Specialist

Profession- Engineer

Directorate - Technology

Full Time equivalent - 37.5 hours

No of Roles - 2

Contract Type - Permanent

Location - Home/local office hybrid, with travel to other UKHSA sites as required

UKHSA offers hybrid working or home working for its employees - this means that whilst the role will be based in one of our UKHSA offices, there will be opportunities for an element of working from home. The balance between home and workplace working is to be agreed with the line manager, determined primarily by business need and in line with departmental policy. Some business travel will be required to other UKHSA offices.Please be aware that this role can only be worked from within the UK and not overseas. Relocation expenses are not available

Working Pattern - Full Time /Flexible Working / Hybrid Working

Grade & Salary - Grade SEO. National banding -£37,056 -£42,481 per annum. Outer London - £38,967- £44,240 per annum. Inner London - £40,876- £45,998 per annum.

New entrants to the Civil Service are expected to start on the minimum of the pay band.

The internal roles rules apply to existing Civil Servants, i.e. level transfers move on current salary or the pay range minimum, transfers on promotion move to new pay range minimum or receive 10% increase. Either case is determined by whichever is the highest.

Main duties of the job

As part of our Identity Management team, as senior member, you will get the opportunity to work on vital projects with a wide range of responsibilities. You will work within specified technical specialties and provide technical expertise in the configuration, implementation and automation of relevant applications. You should expect to be involved in a wide range of challenging engagements, from strategy roll-out, to large scale Modern Identity transformations, to controls review.

Daily Operational Duties

  • Incident and Request management via ITSM suite.
  • Management and Monitoring of key UKHSA IAM services:
    • Certificate \ PKI lifecycle
    • Entra ID Privileged Access Management
    • Azure Enterprise Applications onboarding and lifecycle
    • SCIM Provisioning and SSO Alignment.
    • Active Directory Domain services, Identity, DNS, GPO etc.
    • Microsoft Direct Access
    • Microsoft ADFS
    • Microsoft Defender for Identity and Server Endpoints

Ongoing alignment of services to best practices with Cyber Security

About us

The Technology Directorate provides business-critical systems and services to UKHSA business users at all locations at which UKHSA staff work. ICT has primary responsibility for technical infrastructure and the corporate services running upon it. ICT has staff at a number of locations throughout UKHSA.

Details

Date posted

15 August 2023

Pay scheme

Other

Salary

£37,056 to £42,481 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working, Home or remote working

Reference number

UKHSA00259

Job locations

Colindale

London

NW9 5EQ


Job description

Job responsibilities

Main duties and responsibilities

  • Investigate and provide accurate responses to requests for support. For example: making system modifications, developing work-around enhancements, manipulating data, reconfiguring systems, changing operating procedures, training users or operations staff, producing additional documentation, or escalating requests to systems development staff or software suppliers.
  • Ensure all work is carried out and documented in accordance with required standards, methods and procedures.
  • Ensure documentation is available and securely accessible to relevant parties
  • Deliver subject matter expertise in Identity and Access management (IAM), ensuring delivery of business requirements
  • Creating IAM solution blueprints and producing high-level designs for technical and process solutions for multiple IAM domains.
  • Managing the designs, development, test, launch, and continuous improvement of UKHSAs identity solutions.
  • Developing an understanding of access needs, and platform progress, leading to improvements on UKHSAs identity and access policies
  • In accordance with agreed procedures, monitors application and infrastructure systems by regular scrutiny of reports from the applications software, systems software or service delivery staff. Notes problems and identifies performance trends and statistics. Referring to more senior colleagues where necessary, takes corrective action to improve performance and to avoid problems arising.
  • Manage and monitor systems associated to IAM, Privileged Access Management (PAM), Single Sign-On (SSO)/Federation and Multi-factor Authentication (MFA).
  • Enforce security policies and support existing systems in accordance with policies, standards, guidelines, and procedures.
  • Participate in the evaluation, design, development, and implementation of IAM solutions to enhance information systems security and prevent the unauthorized use, release, modification, or destruction of data.
  • Provides an effective interface between users and service providers, including external commercial suppliers where applicable. This interface includes documenting problems, progress checking, and ensuring all diagnostic information is provided for error resolution and incident analysis.
  • Contributes to the availability management process and its operation by reporting on service and component availability, reliability, maintainability and serviceability.
  • Conducts investigations of operational problems and makes proposals for improvement. Participates in reviews of systems performance, provide advice, and assist service specialists or other system or service providers to plan details of amendments and upgrades to systems.
  • Identifies and implements areas of improvement through automation or efficiencies with use of technology.
  • Supports and mentors junior team members and assists in their development to provide an excellent level of service to all customers.
  • Identifies areas of potential security enhancement whilst maintaining an excellent end user working experience.

Essential Experience

  • Experience with Microsoft Azure Active Directory (AD), AD Connect, Multi-Factor authentication
  • Microsoft AZ-900 certified or sufficient working experience within Microsoft Azure.
  • Experience of Azure Active Directory, with a good understanding of authentication principals and multi-cloud identity models.
  • Experience in building and maintaining access management systems with non-Microsoft technologies such as FreeIPA, OpenAM, AWS Cognito or other OpenID connect, Oauth or SAML services providers.
  • Opportunity to be a key strategic contributor from the ground up
  • Design and implement sustainable solutions to be used for authentication, authorization, user life-cycle management, role-based access control, privileged account management (PAM), audit, and monitoring
  • Assist project managers in various project execution phases
  • Daily systems monitoring
  • Incident management. You can diagnose and prioritise incidents, investigate their causes and find resolutions. (Skill level: working)
  • Problem management. You can initiate and monitor actions to investigate patterns and trends to resolve problems. You can determine the appropriate remedy and assist with its implementation. You can determine preventative measures. (Skill level: working)
  • Service focus. You can take inputs and establish coherent frameworks that work. (Skill level: working)
  • Service management framework knowledge. An understanding of level 3 service management framework. (Skill level: awareness)
  • Technical specialism. You can use management system software and tools. You can use logical schemata to investigate problems, collect performance statistics and create reports. You can carry out the routine configuration, installation and reconfiguration of database and related products. You can optimise performance and forecast resource needs. (Skill level: working)
  • Technical understanding. You can understand the core technical concepts related to the role and apply them with guidance. (Skill level: working)
  • Testing. You can review requirements and specifications and define test conditions. You can identify issues and risks associated with work. You can analyse and report test activities and results. (Skill level: working)

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Selection Process

This vacancy is using Success Profiles, and will assess your Behaviours, Experience and Strengths

Stage 1: Application & SiftAs part of the application process, you will be asked to provide a Statement of Suitability in no more than 1000 words. This part of the selection process should outline how you consider your skills, experience and achievements, and provide evidence of your suitability for the role, with particular reference to the essential criteria outlined.

When completing your statement of suitability, please read and understand the Essential Criteria thoroughly as this is what your written evidence will assessed against.

Please ensure you evidence the key personal requirements and what you have done that relates to these requirements. You dont have to explain the whole process, just what you have done and the skills and experience you have used. Share with us why you are most suited to this role, what you can do, the skills you have that are transferable to the key requirements, and the life experiences or passion you have that are linked to this role.

You will also be asked to provide information within the Employer/ Activity history section of the application form. This is equivalent to the information you would provide on a CV, setting out your career history. This will be used in sifting process and will be scored.

If you are successful at this stage, you will progress to interview

Stage 2: Panel Interview

All candidates who are successful at the sift stage will be invited to an interview on site at Colindale, where you may be asked to do a presentation on a topic given to you prior to the interview

The Behaviours tested during the interview stage will be:

  • Working Together
  • Managing a Quality Service
  • Making effective decisions
  • Communicating & Influencing

Reserve List:

Candidates who pass the interview criteria but are not offered a post will be kept on a reserve list for 12 months and may be contacted if similar roles become available.

If you are interviewed for the post and do not meet the required threshold for the specified grade, your application may be assessed against a similar, lower grade role and you may be offered the post should one be available.

Benefits

  • A Civil Service pension with an average employer contribution of 27%
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Range of health and wellbeing support

Any move to UKHSA from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare.

Eligibility Criteria

Open to all external applicants (anyone) from outside the Civil Service (including by definition internal applicants)

Nationality requirements

Appointments to roles within UKHSA will be made in accordance with the Civil Service nationality rules. These can be found athttps://www.gov.uk/government/publications/nationality-rulesThis job is broadly open to the following groups:

  • UK nationals
  • Nationals of Commonwealth countries who have the right to work in the UK
  • Nationals of the Republic of Ireland
  • Nationals from the EU, EEA or Switzerland with settled or pre-settled status or who apply for either status by the deadline of theEuropean Union Settlement Scheme (EUSS)
  • Relevant EU, EEA, Swiss or Turkish nationals working in the Civil Service
  • Relevant EU, EEA, Swiss or Turkish nationals who have built up the right to work in the Civil Service
  • Certain family members of the relevant EU, EEA, Swiss or Turkish nationals

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's Recruitment Principles.

Job description

Job responsibilities

Main duties and responsibilities

  • Investigate and provide accurate responses to requests for support. For example: making system modifications, developing work-around enhancements, manipulating data, reconfiguring systems, changing operating procedures, training users or operations staff, producing additional documentation, or escalating requests to systems development staff or software suppliers.
  • Ensure all work is carried out and documented in accordance with required standards, methods and procedures.
  • Ensure documentation is available and securely accessible to relevant parties
  • Deliver subject matter expertise in Identity and Access management (IAM), ensuring delivery of business requirements
  • Creating IAM solution blueprints and producing high-level designs for technical and process solutions for multiple IAM domains.
  • Managing the designs, development, test, launch, and continuous improvement of UKHSAs identity solutions.
  • Developing an understanding of access needs, and platform progress, leading to improvements on UKHSAs identity and access policies
  • In accordance with agreed procedures, monitors application and infrastructure systems by regular scrutiny of reports from the applications software, systems software or service delivery staff. Notes problems and identifies performance trends and statistics. Referring to more senior colleagues where necessary, takes corrective action to improve performance and to avoid problems arising.
  • Manage and monitor systems associated to IAM, Privileged Access Management (PAM), Single Sign-On (SSO)/Federation and Multi-factor Authentication (MFA).
  • Enforce security policies and support existing systems in accordance with policies, standards, guidelines, and procedures.
  • Participate in the evaluation, design, development, and implementation of IAM solutions to enhance information systems security and prevent the unauthorized use, release, modification, or destruction of data.
  • Provides an effective interface between users and service providers, including external commercial suppliers where applicable. This interface includes documenting problems, progress checking, and ensuring all diagnostic information is provided for error resolution and incident analysis.
  • Contributes to the availability management process and its operation by reporting on service and component availability, reliability, maintainability and serviceability.
  • Conducts investigations of operational problems and makes proposals for improvement. Participates in reviews of systems performance, provide advice, and assist service specialists or other system or service providers to plan details of amendments and upgrades to systems.
  • Identifies and implements areas of improvement through automation or efficiencies with use of technology.
  • Supports and mentors junior team members and assists in their development to provide an excellent level of service to all customers.
  • Identifies areas of potential security enhancement whilst maintaining an excellent end user working experience.

Essential Experience

  • Experience with Microsoft Azure Active Directory (AD), AD Connect, Multi-Factor authentication
  • Microsoft AZ-900 certified or sufficient working experience within Microsoft Azure.
  • Experience of Azure Active Directory, with a good understanding of authentication principals and multi-cloud identity models.
  • Experience in building and maintaining access management systems with non-Microsoft technologies such as FreeIPA, OpenAM, AWS Cognito or other OpenID connect, Oauth or SAML services providers.
  • Opportunity to be a key strategic contributor from the ground up
  • Design and implement sustainable solutions to be used for authentication, authorization, user life-cycle management, role-based access control, privileged account management (PAM), audit, and monitoring
  • Assist project managers in various project execution phases
  • Daily systems monitoring
  • Incident management. You can diagnose and prioritise incidents, investigate their causes and find resolutions. (Skill level: working)
  • Problem management. You can initiate and monitor actions to investigate patterns and trends to resolve problems. You can determine the appropriate remedy and assist with its implementation. You can determine preventative measures. (Skill level: working)
  • Service focus. You can take inputs and establish coherent frameworks that work. (Skill level: working)
  • Service management framework knowledge. An understanding of level 3 service management framework. (Skill level: awareness)
  • Technical specialism. You can use management system software and tools. You can use logical schemata to investigate problems, collect performance statistics and create reports. You can carry out the routine configuration, installation and reconfiguration of database and related products. You can optimise performance and forecast resource needs. (Skill level: working)
  • Technical understanding. You can understand the core technical concepts related to the role and apply them with guidance. (Skill level: working)
  • Testing. You can review requirements and specifications and define test conditions. You can identify issues and risks associated with work. You can analyse and report test activities and results. (Skill level: working)

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Selection Process

This vacancy is using Success Profiles, and will assess your Behaviours, Experience and Strengths

Stage 1: Application & SiftAs part of the application process, you will be asked to provide a Statement of Suitability in no more than 1000 words. This part of the selection process should outline how you consider your skills, experience and achievements, and provide evidence of your suitability for the role, with particular reference to the essential criteria outlined.

When completing your statement of suitability, please read and understand the Essential Criteria thoroughly as this is what your written evidence will assessed against.

Please ensure you evidence the key personal requirements and what you have done that relates to these requirements. You dont have to explain the whole process, just what you have done and the skills and experience you have used. Share with us why you are most suited to this role, what you can do, the skills you have that are transferable to the key requirements, and the life experiences or passion you have that are linked to this role.

You will also be asked to provide information within the Employer/ Activity history section of the application form. This is equivalent to the information you would provide on a CV, setting out your career history. This will be used in sifting process and will be scored.

If you are successful at this stage, you will progress to interview

Stage 2: Panel Interview

All candidates who are successful at the sift stage will be invited to an interview on site at Colindale, where you may be asked to do a presentation on a topic given to you prior to the interview

The Behaviours tested during the interview stage will be:

  • Working Together
  • Managing a Quality Service
  • Making effective decisions
  • Communicating & Influencing

Reserve List:

Candidates who pass the interview criteria but are not offered a post will be kept on a reserve list for 12 months and may be contacted if similar roles become available.

If you are interviewed for the post and do not meet the required threshold for the specified grade, your application may be assessed against a similar, lower grade role and you may be offered the post should one be available.

Benefits

  • A Civil Service pension with an average employer contribution of 27%
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Range of health and wellbeing support

Any move to UKHSA from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare.

Eligibility Criteria

Open to all external applicants (anyone) from outside the Civil Service (including by definition internal applicants)

Nationality requirements

Appointments to roles within UKHSA will be made in accordance with the Civil Service nationality rules. These can be found athttps://www.gov.uk/government/publications/nationality-rulesThis job is broadly open to the following groups:

  • UK nationals
  • Nationals of Commonwealth countries who have the right to work in the UK
  • Nationals of the Republic of Ireland
  • Nationals from the EU, EEA or Switzerland with settled or pre-settled status or who apply for either status by the deadline of theEuropean Union Settlement Scheme (EUSS)
  • Relevant EU, EEA, Swiss or Turkish nationals working in the Civil Service
  • Relevant EU, EEA, Swiss or Turkish nationals who have built up the right to work in the Civil Service
  • Certain family members of the relevant EU, EEA, Swiss or Turkish nationals

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's Recruitment Principles.

Person Specification

Experience

Essential

  • oExperience with Microsoft Azure Active Directory (AD), AD Connect, Multi-Factor authentication
Person Specification

Experience

Essential

  • oExperience with Microsoft Azure Active Directory (AD), AD Connect, Multi-Factor authentication

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Additional information

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Employer details

Employer name

UK Health Security Agency

Address

Colindale

London

NW9 5EQ


Employer's website

https://www.gov.uk/government/organisations/uk-health-security-agency (Opens in a new tab)

Employer details

Employer name

UK Health Security Agency

Address

Colindale

London

NW9 5EQ


Employer's website

https://www.gov.uk/government/organisations/uk-health-security-agency (Opens in a new tab)

Employer contact details

For questions about the job, contact:

lead recruiter

Sophie rigney

sophie.rigney@reed.com

Details

Date posted

15 August 2023

Pay scheme

Other

Salary

£37,056 to £42,481 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working, Home or remote working

Reference number

UKHSA00259

Job locations

Colindale

London

NW9 5EQ


Supporting documents

Privacy notice

UK Health Security Agency's privacy notice (opens in a new tab)