KEYSTONE CYBER

Home Disciplines Identity & access management

IDENTITY & ACCESS MANAGEMENT

Identity and access management recruitment

IAM is the scarcest engineering skill in security and the one employers most often try to fill with an infrastructure generalist. Identity work is part engineering, part process design and part organisational negotiation, and candidates who can do all three are genuinely hard to find.

What we place

IAM ENGINEER
Builds and runs the identity platform: directories, federation, single sign-on, conditional access, lifecycle automation.
IGA SPECIALIST
Identity governance — access certification, role modelling, joiner-mover-leaver, and the cleanup of two decades of privilege creep.
PAM ENGINEER
Privileged access: vaulting, session management, secrets, and the migration projects that make administrators unhappy.
IDENTITY ARCHITECT
Authentication and authorisation design across the estate, including customer identity where it applies.
CIAM
Customer identity for product organisations — registration, consent, fraud signals and the conversion trade-offs.
ACCESS MANAGEMENT LEAD
Owns the function, the vendor relationships and the multi-year programme that always runs longer than planned.

How we screen

We ask what someone has migrated and what broke. Identity projects are famous for locking people out of things, and the useful answer describes discovery, phased rollout, break-glass and the application owner who refused to cooperate. Candidates who only describe tooling configuration have usually worked in a stable estate rather than built one.

Process depth matters as much as platform depth. We test whether a candidate understands joiner-mover-leaver as an HR-driven process, because IAM roles fail where the engineer treats it as a purely technical problem.

The market, honestly

Supply is tight in both markets and the tooling fragments it further: SailPoint, Okta, Entra ID, CyberArk and Saviynt experience are not interchangeable, and employers who insist on an exact tool match often wait months. We advise on which adjacent platform experience transfers cleanly and which does not.

Programme-driven demand makes timing important. Large IAM implementations pull the available engineers into fixed-term work at contract rates, which thins the permanent market for the duration. When that is happening, we say so rather than let a search drift.

If your IAM role is really an Active Directory administration job with a modern title, experienced identity engineers will spot it immediately. Scope it honestly and it becomes a good hire for a different candidate.

Where we recruit

Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.

Common questions

Which IAM platforms do you recruit for?

Most commonly Microsoft Entra ID, Okta, SailPoint, CyberArk and Saviynt, plus legacy estates still running Active Directory federation. We are explicit about which platforms a candidate has really operated versus configured once.

Is IAM a security role or an infrastructure role?

Both, and the reporting line varies. Identity increasingly sits in security because it is the primary control plane, but the day-to-day work is engineering and process. We scope which side the role leans.

Do you place privileged access management specialists?

Yes. PAM is a distinct market with fewer candidates than general IAM, and CyberArk experience in particular commands a premium in both markets.

Can you recruit customer identity (CIAM) specialists?

Yes, mostly for product and fintech employers. CIAM candidates think about conversion, consent and fraud as well as security, and they rarely come from enterprise IAM backgrounds.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.