Home Disciplines Identity & access management
IDENTITY & ACCESS MANAGEMENT
Identity and access management recruitment
IAM is the scarcest engineering skill in security and the one employers most often try to fill with an infrastructure generalist. Identity work is part engineering, part process design and part organisational negotiation, and candidates who can do all three are genuinely hard to find.
What we place
- IAM ENGINEER
- Builds and runs the identity platform: directories, federation, single sign-on, conditional access, lifecycle automation.
- IGA SPECIALIST
- Identity governance — access certification, role modelling, joiner-mover-leaver, and the cleanup of two decades of privilege creep.
- PAM ENGINEER
- Privileged access: vaulting, session management, secrets, and the migration projects that make administrators unhappy.
- IDENTITY ARCHITECT
- Authentication and authorisation design across the estate, including customer identity where it applies.
- CIAM
- Customer identity for product organisations — registration, consent, fraud signals and the conversion trade-offs.
- ACCESS MANAGEMENT LEAD
- Owns the function, the vendor relationships and the multi-year programme that always runs longer than planned.
How we screen
We ask what someone has migrated and what broke. Identity projects are famous for locking people out of things, and the useful answer describes discovery, phased rollout, break-glass and the application owner who refused to cooperate. Candidates who only describe tooling configuration have usually worked in a stable estate rather than built one.
Process depth matters as much as platform depth. We test whether a candidate understands joiner-mover-leaver as an HR-driven process, because IAM roles fail where the engineer treats it as a purely technical problem.
The market, honestly
Supply is tight in both markets and the tooling fragments it further: SailPoint, Okta, Entra ID, CyberArk and Saviynt experience are not interchangeable, and employers who insist on an exact tool match often wait months. We advise on which adjacent platform experience transfers cleanly and which does not.
Programme-driven demand makes timing important. Large IAM implementations pull the available engineers into fixed-term work at contract rates, which thins the permanent market for the duration. When that is happening, we say so rather than let a search drift.
If your IAM role is really an Active Directory administration job with a modern title, experienced identity engineers will spot it immediately. Scope it honestly and it becomes a good hire for a different candidate.
Where we recruit
Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.
Common questions
Which IAM platforms do you recruit for?
Most commonly Microsoft Entra ID, Okta, SailPoint, CyberArk and Saviynt, plus legacy estates still running Active Directory federation. We are explicit about which platforms a candidate has really operated versus configured once.
Is IAM a security role or an infrastructure role?
Both, and the reporting line varies. Identity increasingly sits in security because it is the primary control plane, but the day-to-day work is engineering and process. We scope which side the role leans.
Do you place privileged access management specialists?
Yes. PAM is a distinct market with fewer candidates than general IAM, and CyberArk experience in particular commands a premium in both markets.
Can you recruit customer identity (CIAM) specialists?
Yes, mostly for product and fintech employers. CIAM candidates think about conversion, consent and fraud as well as security, and they rarely come from enterprise IAM backgrounds.
Related disciplines
Talk to us about your search
A short conversation is usually enough to tell you whether we can help.