Systems Engineer III

7 days ago


Welwyn Garden City, Hertfordshire, United Kingdom Tesco Full time £60,000 - £100,000 per year

About the role

This role sits within the workplace Identity team which is

part of the Tesco
Workplace Technology engineering team
, part of a

global engineering function delivering secure, scalable, and modern workplace

solutions for Tesco colleagues. As a senior engineer and domain expert in
**Identity

technologies**
, you will lead the full technology lifecycle — from strategy

and design through to engineering, testing, and delivery — for the services

that underpin our digital colleague experience.

You will be responsible for

Strategic Leadership

  • Act as a senior engineer for Identity within the Workplace Technology team, setting the 
    direction, roadmap, and architectural standards

for core identity services including 
Active Directory, Entra ID, PKI

, and modern authentication protocols.
- Align identity strategy to Tesco's broader digital

workplace vision, collaborating closely with architects, product managers,

security, and infrastructure teams.

  • Stay ahead of market trends and emerging

technologies in identity and access management, advocating for their

adoption where beneficial.

Engineering & Delivery

  • Design and deliver secure, scalable identity

platforms that support global business needs and enable modern digital

workplace capabilities.

  • Engineer solutions across the identity lifecycle:

concept, evaluation, prototyping, testing, production deployment, and

service transition.

  • Implement automation, codification (IaC), and

integration with CI/CD practices to drive efficiency and resilience.

  • Act as a senior escalation point for complex issues

related to authentication, replication, certificate lifecycle, hybrid

identity, and directory services.

Operational Excellence

  • Build systems that are
    **secure, stable, and easy

to operate**
, with monitoring, alerting, and lifecycle planning embedded

by design.

  • Champion remediation of legacy identity components

and uplift the security and operational posture of all identity services.

  • Ensure knowledge is well documented and transitions

smoothly into operational support with clear SLAs and handover practices.

Governance & Security

  • Drive adoption of Zero Trust principles, secure

admin tiering, modern auth standards, conditional access, and multifactor

authentication.

  • Own the health, design, and policy of PKI

infrastructure and associated services (including certificate templates,

CRLs, and HSMs).

  • Work closely with the Security and Risk teams to

ensure compliance with internal controls, regulatory obligations, and

audit findings.

Leadership & Influence

  • Represent
    **Workplace Technology Identity

Engineering**
across Tesco Technology and into broader cross-functional

initiatives.

  • Lead by example in engineering excellence,

stakeholder engagement, and mentoring of less experienced engineers.

  • Promote a culture of simplification, technical

rigour, and continuous improvement.

You will need

  • Deep expertise in:

  • Active Directory
    : design, hardening,

replication, domain controller lifecycle, GPOs, admin tiering.

  • Azure AD / Entra ID
    : hybrid identity,

conditional access, MFA, identity protection, SSO, SCIM.

  • Public Key Infrastructure (PKI)
    : policy,

lifecycle, templates, automation, CRL/OCSP, HSMs.

  • Authentication protocols
    : OAuth2, OpenID

Connect, SAML, Kerberos, NTLM, WS-Fed.

  • Demonstrated ability to design and deliver identity

platforms in large, complex environments.

  • Understanding of identity's role in enterprise

security frameworks and compliance requirements.

  • Proficiency with scripting and automation tools

(PowerShell, Terraform, etc.).

  • Familiar with monitoring, backup, recovery, and DR

practices for identity systems.

  • Ensure identity services are designed with built-in

resilience, supporting high availability, fault tolerance, and fast

recovery across hybrid environments.

  • Contribute to and maintain Business Continuity

Plans (BCPs), ensuring critical identity components are documented with

clear recovery priorities.

  • Design and validate Disaster Recovery (DR)

strategies for directory services, authentication systems, and PKI, with

regular failover testing and documented RTO/RPO.

Whats in it for you?
We're all about the little helps. That's why we make sure our Tesco colleague benefits package takes care of you – both in and out of work. Click Here to find out more 

  • Annual bonus scheme of up to 20% of base salary

  • Holiday starting at 25 days plus a personal day (plus Bank holidays)

  • Private medical insurance

  • 26 weeks maternity and adoption leave (after 1 years' service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave

  • Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing

About Us
Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet. 

We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here. 

We're a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you.  We work in a more blended pattern - combining office and remote working.  Our offices will continue to be where we connect, collaborate and innovate.  If you are applying internally, please speak to the Hiring Manager about how this can work for you - Everyone is welcome at Tesco.



  • Welwyn Garden City, Hertfordshire, United Kingdom hackajob Full time £60,000 - £100,000 per year

    hackajob*is collaborating withTesco*to connect them with exceptional tech professionals for this role.What's in it for youWe're all about the little helps. That's why we make sure our Tesco colleague benefits package takes care of you - both in and out of work.Annual bonus scheme of up to 20% of base salaryHoliday starting at 25 days plus a personal day...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Full time £60,000 - £80,000 per year

    About the roleThe Treasury Technology team will be based across India andUK, part of a wider Finance systems engineering team. You will be joining theUK team where you will focus on enhancing the treasury system with a widerroadmap for developing alongside the strategic solution of Findur. The Indiateam will focus on maintaining and running the current...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Technology Full time £40,000 - £80,000 per year

    About the roleWithin Tesco Data & Analytics, we find ways to use data to help our customers and the communities where we operate. We build and run Tesco's data platforms, architect and engineer data onto these platforms, provide capabilities and tools to the analytics community across Tesco, and develop data products at scale.As a backend engineer within...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Technology Full time £80,000 - £120,000 per year

    About the roleWithin Tesco Data & Analytics, we help our customers and the communities where we operate get the most value from data. We build and run Tesco's data platforms, we architect and engineer data onto these platforms, provide capabilities and tools to the analytics community across Tesco, and develop data products at scale.Our Data Science teams...


  • Welwyn Garden City, Hertfordshire, United Kingdom Glow Green Ltd Full time £540,000 - £576,000 per year

    Gas Breakdown Engineer£45,000k to £48,000 p/aFounded in 2011, Glow Green is a FCA regulated renewable technology installation and finance business. Glow Green aims to become the most successful UK wide installer of solar, battery and heat pumps.Glow Green is now rated "The UK's Top Pick Installer" of 2025 by The Independent.Glow Green are proud to have...


  • Welwyn Garden City, Hertfordshire, United Kingdom Calibre Full time £45,000 - £55,000 per year

    BMS Service Engineer (Mobile) - London & South East (Majority Inside M25)An excellent opportunity has arisen for an experienced BMS Service Engineer to join our client, a leading building services company, working across London and the South East. The majority of work will be based in London and within the M25, with some travel required across the wider...

  • Security Engineer I

    3 days ago


    Welwyn Garden City, Hertfordshire, United Kingdom Tesco Technology Full time £30,000 - £60,000 per year

    About the roleAs a Junior Cyber Security Detection Engineer, you willcontribute to the continuous improvement of Tesco's cyber security detectioncapability. You will be required to understand the changing threat landscape,see opportunities for improvement in existing detections, contribute to the detectionlifecycle process, and ensure appropriate detection...

  • IT Engineer

    2 weeks ago


    Welwyn Garden City, Hertfordshire, United Kingdom Sika Full time £40,000 - £80,000 per year

    Company Description Sika is a specialty chemicals company with a globally leading position in the development and production of systems and products for bonding, sealing, damping, reinforcing, and protection in the building sector and industry. Sika has subsidiaries in 103 countries around the world, produces in over 400 factories, and develops innovative...


  • Welwyn Garden City, Hertfordshire, United Kingdom CBRE Full time £40,000 - £70,000 per year

    Welwyn Garden City - England - United Kingdom of Great Britain and Northern IrelandCompany ProfileCBRE is the global leader in real estate services and leverages the industry's most powerful knowledge base to meet the commercial real estate needs of its clients worldwide. Our vision is to be the preeminent, vertically integrated, globally capable real estate...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Technology Full time £40,000 - £80,000 per year

    About the roleTesco's Scan As You Shop service is an in-storeexperience that lets customers build their basket on a handheld device duringtheir shopping journey so that they can keep a close eye on their budget andskip the queues at checkout. Since late 2021, we've brought the solutionentirely in house, and we're now live in over 800 stores across the UK and...