Register for Retail & Hospitality Live Now - 24th Sept 2026

Search
Senior Security Analyst - Active Directory

Senior Security Analyst - Active Directory

PublishedPublished: 15/09/2026
Digital / Ecommerce
About the role We are seeking a highly skilled Lead IAM Security Analyst to drive the improvement of the organization's Active Directory and Microsoft Windows IAM security posture.
The role focuses on strengthening identity security controls, reducing risks, and ensuring secure management of identities, privileges, authentication, and access across the Windows ecosystem.
The successful candidate will work closely with platform engineering teams, infrastructure teams, security stakeholders, and other IAM functions to define security requirements, influence roadmaps, and deliver continuous security improvements. What is in it for you Tesco is a diverse and exciting employer, dedicated to being #aplacetogeton, providing career-defining opportunities to all of our colleagues. If you choose to join our business, we will provide you with (for all):

  • Up to 20% yearly salary bonus - based on both individual and business performance
  • Sick leave Compensation
  • 1 extra week of annual leave above your legal entitlement of 4 weeks of annual leave of paid leave to support our well-being and family life
  • Pension insurance contribution
  • Cafeteria benefit system & Multisport card
  • Training and Development Plan, supported by certified training and learning platforms like Udemy, Udemy Pro and LinkedIn
  • Referral Bonus
  • Flexible work time
You will be responsible for
  • Lead initiatives to improve the security posture of Microsoft Active Directory and Windows-based identity services.
  • Assess, identify, and remediate IAM security risks, misconfigurations, and control gaps within Active Directory environments.
  • Develop and drive implementation of AD security hardening standards, privileged access controls, and identity protection measures.
  • Partner with infrastructure and engineering teams to embed IAM security requirements into platform designs and operational processes.
  • Collaborate with stakeholders across IAM functions, including PAM, Governance, Authentication, and Access Management teams, to ensure alignment of security controls and strategy.
  • Review and enhance privileged access models, administrative tiering, service account management, and authentication mechanisms.
  • Support security assessments, audits, risk reviews, and remediation activities related to Active Directory and Windows platforms.
  • Monitor industry best practices and emerging threats affecting identity systems and recommend security improvements.
  • Contribute to IAM strategy, roadmaps, standards, and governance activities.
  • Provide technical leadership and guidance to security and engineering teams on identity security matters.
You will need Required Qualifications
Minimum 8 years of experience in Active Directory administration, security, hardening, identity management, or closely related disciplines.

Strong expertise in:
  • Microsoft Active Directory
  • Group Policy (GPO) security
  • Kerberos and authentication protocols
  • Privileged Access Management concepts
  • Active Directory hardening and secure configuration
  • Identity threat detection and mitigation
  • Windows Server security architecture
  • Experience conducting security assessments and implementing remediation plans within enterprise Windows environments.
  • Strong understanding of IAM principles, access controls, privileged access security, and identity lifecycle management.
  • Ability to work effectively with engineering, infrastructure, and security stakeholders across multiple teams.
  • Excellent analytical, communication, and stakeholder management skills.

Preferred Qualifications
  • Experience with Microsoft Entra ID (Azure AD) and hybrid identity environments.
  • Knowledge of Microsoft security technologies such as Entra ID Protection, LAPS, and Tiered Administration models.
  • Relevant certifications such as CISSP, Microsoft Security certifications, or equivalent IAM-related certifications.
  • Knowledge of CyberArk Privileged Access Management (PAM) solutions, including privileged account onboarding, credential management, privileged session controls, and privileged access governance, is considered a strong advantage.
About us Tesco Technology was established in Prague to support Tesco’s retail business in Central Europe and across the Tesco Group. What began as a regional center over 25 years ago has evolved into a modern, forward-thinking team, driving innovation and digital transformation throughout the region. With operations in the UK, Ireland, India, Hungary, Poland, and the Czech Republic, we’re committed to delivering great value to our customers every day. Let’s {code} the future together at {Tesco Technology}!