368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$75k – $153k per year (Estimated)
Location
In office (London)
Employment
Full-Time
Overview
Company
Impact
Profile match
Tokio Marine HCC (TMHCC) is a leading international specialty insurance group headquartered in Houston, Texas, operating as a subsidiary of Japan's Tokio Marine Group. Operating across more than 180 countries, the company underwrites over 100 distinct classes of specialty insurance, including medical stop-loss, directors and officers (D&O) liability, professional indemnity, agricultural coverage, and casualty risks. Backed by high financial strength ratings, TMHCC leverages deep underwriting expertise to provide customized risk management and specialty coverage solutions for businesses, public entities, and high-risk commercial operations worldwide.

Job Title: Identity Systems Engineer

Reporting to: Manager, Identity and Access Management

Position Type: Permanent, 35 hours per week

Hybrid

Overview:

Why Tokio Marine HCC?

Standing still is not an option in the current world of Insurance. TMHCCare one of the world’s leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, and so is a desire to grow and provide creative and innovative solutions to our clients.

Job Purpose:

The Infrastructure Collaboration Engineering team is seeking a highly experienced Senior Identity & Privileged Access Management (PAM) Engineer with expertise in enterprise Identity and Access Management, with primary specialization in CyberArk.

This role will serve as the technical lead and subject matter expert for Privileged Access Management (PAM), responsible for designing, architecting, implementing, operating, and maintaining CyberArk solutions integrated across Entra ID, Active Directory, and Okta environments.

The ideal candidate will possess deep end-to-end identity expertise while maintaining advanced hands-on skills in CyberArk PAS, Privilege Cloud, EPM, Secrets Manager, and identity governance integration patterns.

Key Responsibilities:

CyberArk (Primary Skillset - Privileged Access Management)

  • Proven expert knowledge of CyberArk Privilege Access Security (PAS) and/or Privilege Cloud architecture, deployment, and administration
  • Design, implement, and maintain CyberArk Vault, CPM (Central Policy Manager), PSM (Privileged Session Manager), and PTA (Privilege Threat Analytics)
  • Manage safes, platforms, account onboarding, credential rotation policies, and access controls
  • Implement Just-in-Time (JIT) privileged access models integrated with Entra PIM and AD tiering
  • Secure and rotate domain admin, enterprise admin, service accounts, application accounts, SSH keys, and cloud credentials
  • Integrate CyberArk with Entra ID, Active Directory, and Okta for authentication and authorization workflows
  • Deploy and manage CyberArk Endpoint Privilege Manager (EPM) for least privilege enforcement
  • Implement CyberArk Secrets Manager / Conjur for DevOps and Kubernetes environments
  • Develop automation using REST APIs, PowerShell, and CyberArk tools
  • Design CyberArk disaster recovery and vault backup strategies
  • Integrate CyberArk logs with SIEM platforms and support audit/compliance requirements
  • Maintain alignment with Zero Trust security architecture principles
  • Stay current on CyberArk roadmap, new features, and evolving PAM security threats

Entra

  • Proven expert knowledge of Azure Entra ID capabilities such as Conditional Access Policies, Privileged Identity Manager and Application Registrations, integrated with CyberArk privileged access controls
  • Strong understanding of PIM and the assignment of roles / IAM permissions on Management Groups, Subscriptions and Resources, aligned with Just-in-Time access principles
  • Azure Infrastructure Management to include user accounts, groups, conditional policies, Intune management, mobile device management, and endpoint security
  • Strong understanding of App registration, Enterprise Apps, SPN’s and managed identities with the understanding of least privileged administration when it comes to MS Graph API allocation of permissions and secure credential storage in CyberArk
  • Strong understanding of multifactor authentication, SSPR and WHfB, ensuring secure privileged authentication workflows
  • Strong PowerShell scripting Skills, automation, and scheduling skills when working with data in Azure and integrating with CyberArk APIs
  • Good understanding of Intune polices management and autopilot
  • An individual that stays abreast of the latest Entra ID features, best practices, and security trends, and make recommendations for continuous improvement

Active Directory

  • Strong background in Active Directory covering domains that span geo locations with numerous DCs and a user base of 5000+
  • Strong understanding of DNS and GPOs, user object and OU administration
  • Solid understanding of Microsoft Tiering, IAM, and PAM concepts with CyberArk vaulting integration for Tier 0 accounts
  • Strong knowledge of server operating systems from Windows 2016 to Windows 2025
  • Strong understanding of the FSMO roles when it comes to maintaining the security and the integrity of the domain
  • Strong understanding of the delegation of permissions across the domain OU structure aligned with least privilege principles
  • Strong PowerShell scripting skills, automation, and scheduling skills including AD account onboarding into CyberArk
  • Solid understanding of the recovery steps needed to recover a domain in the event of a disaster

OKTA

  • Able to demonstrate a strong understanding of IAM concepts, including identity federation, SSO, SAML, OAuth, OIDC, MFA, role-based access control (RBAC), and least privilege principles, integrated with CyberArk privileged authentication workflows
  • Able to provide Okta subject matter expertise to a variety of program stakeholders on application integration, IAM functionality, and Okta’s feature roadmap
  • Capable of designing and implementing Okta platform configurations to align with overall solution architecture and customer requirements while integrating CyberArk for privileged user authentication
  • Willing to collaborate with Solution Architects, other solution component SMEs and stakeholders to develop and refine solution requirements, ensuring secure and efficient access for on-premises and cloud-based applications and resources
  • Able to drive and support customer application integrations into Okta-based IAM solutions and align privileged access controls through CyberArk
  • Troubleshoot and resolve technical issues before, during and after application integration

Skills and Experience Specification:

Competencies

Planning

  • Follow work plans, established timelines, and predefined goals for assigned work.
  • Meet commitments on deadlines.

Communication

  • Communicate activities, results, and observations with employees and management as appropriate.

Cost Management

  • Identify areas for improvement in existing business practices.
  • Perform work thoroughly in a cost-efficient manner and at a high productivity level.

Business Controls and Policies

  • Comply with all corporate policies and procedures.
  • Report any breakdowns in controls to management.
  • Conduct all activities in a safe manner.

People Management

  • No people management responsibility.

Other

  • Excellent troubleshooting, architectural, and documentation skills
  • Knowledge and experience with Rubrik advantageous.
  • Microsoft, Azure or Okta certification are highly beneficial.

Tokio Marine HCC is a leading specialty insurance group with offices in the United States, the United Kingdom, Europe, and other locations. With the strength and stability that comes from being a member of the Tokio Marine group, and more than forty years of growth, profitability, and stability, we offer important insurance products that most people do not even know exist.

The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit www.tmhcc.com for more information about our companies.

  • #LI-PS1
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
London
$79k – $159k per year (Estimated) • In office • Full-Time • 6+ years exp • Lincoln
C#
C#
.NET
DevOps
AWS
Azure
CI/CD
Docker
Dynatrace
GCP
GitHub
GitHub Actions
Grafana
Jenkins
Kubernetes
Splunk
QA
Cypress
JMeter
k6
Pact
Playwright
Postman
Rest-Assured
Selenium
Supertest
WebDriverIO
Apply
$91k – $177k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Tampa • Arlington
PowerShell
SQL
Java
Java
Apache Tomcat
Databases
MS SQL
MySQL
PostgreSQL
AI/ML
Copilot
DevOps
Azure
CentOS Stream
Hyper-V
Kubernetes
Nagios
Nginx
SLI/SLO/SLA
Ubuntu
VMWare
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
$220k – $350k per year • Remote/Hybrid • Full-Time • 15+ years exp • New York • Princeton
AI/ML
AI Agents
LLM Guardrails
Model Context Protocol
DevOps
Azure
Azure DevOps
CI/CD
GitHub
Platform Engineering
Design
Figma
Management
Jira
QA
Playwright
Apply
$70k – $150k per year • Remote • Full-Time • 4+ years exp • Canada
PowerShell
AI/ML
Copilot
DevOps
Platform Engineering
Cybersecurity
Microsoft Entra ID
Management
Power Apps
Power Automate
ServiceNow
Apply
DevOps Engineer 6 days ago
$93k – $110k per year • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Warwick
Python
DevOps
Terraform
Amazon EC2
Amazon EKS
AWS
CI/CD
CloudFormation
Datadog
Docker
GitHub Actions
GitLab CI
Grafana
Incident Management
Jenkins
Kubernetes
Prometheus
Amazon CloudWatch
Amazon ECS
Amazon S3
GitHub
GitLab
IAM
Cybersecurity
PCI DSS
SOC 2
Apply
$130k – $271k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Glastonbury
Apply
$60k – $116k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Troy
Databases
MongoDB
Analytics
ETL/ELT
Apply
$98k – $191k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Houston
SQL
Databases
MS SQL
DevOps
CentOS Stream
Red Hat
Ubuntu
VMWare
Windows Server
Apply
$120k – $222k per year (Estimated) • Remote • Full-Time • 4+ years exp • Bachelor's Degree • United States
Apply
$65k – $155k per year (Estimated) • In office • Internship • Bachelor's Degree • London
Go
JavaScript
Ruby
Scala
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • London
Go
JavaScript
Ruby
Scala
Apply
$221k – $370k per year • In office • Full-Time • 5+ years exp • London
AI/ML
OpenAI
Apply
$72k – $136k per year (Estimated) • Equity • Remote/Hybrid • 5+ years exp • London
Python
SQL
Databases
Snowflake
AI/ML
AI Agents
DevOps
Kibana
Marketing
Salesforce
Apply
$77k – $148k per year (Estimated) • Equity • In office • Master's Degree • London
JavaScript
Python
Scala
AI/ML
AI Agents
DevOps
GitHub
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.