Search by job, company or skills

Tesco

Systems Engineer II

This job is no longer accepting applications

new job description bg glownew job description bg glow
  • Posted 4 days ago

Job Description

About the role

This role sits within the workplace
Identity team which is part of the Tesco Workplace Technology engineering team,
part of a global engineering function delivering secure, scalable, and modern
workplace solutions for Tesco colleagues. As advanced engineer with expertise
in Identity technologies, you will contribute (with opportunity to lead)
to full technology lifecycle — from strategy and design through to engineering,
testing, and delivery — for the services that underpin our digital colleague
experience.

You will be responsible for

Strategic Leadership


  • Act as an advanced engineer for
    Identity within the Workplace Technology team, contributing to direction,
    roadmap, and architectural standards
    for core identity services
    including Active Directory, Entra ID, PKI, and modern
    authentication protocols.

  • Understanding the Identity strategy in
    relation to Tesco's broader digital workplace vision, collaborating
    closely with senior engineers, project management, architects, product
    managers, security, and infrastructure teams.

  • Keep yourself up to date with market
    trends and emerging technologies in identity and access management,
    contribute to advocation for their adoption where beneficial.


Engineering
& Delivery


  • Deliver secure, scalable identity
    platforms that support global business needs and enable modern digital
    workplace capabilities. Contribute to the design with opportunity to lead.

  • Engineer solutions across the
    identity lifecycle: concept, evaluation, prototyping, testing, production
    deployment, and service transition.

  • Implement automation, codification
    (IaC), and integration with CI/CD practices to drive efficiency and
    resilience.

  • Contribute to escalations for
    complex issues related to authentication, replication, certificate
    lifecycle, hybrid identity, and directory services.

Operational
Excellence


  • Build systems that are secure,
    stable, and easy to operate
    , with monitoring, alerting, and lifecycle
    planning embedded by design.

  • Champion remediation of legacy
    identity components and uplift the security and operational posture of all
    identity services.

  • Ensure knowledge is well documented
    and transitions smoothly into operational support with clear SLAs and
    handover practices.

Governance
& Security


  • Contribute to adoption of Zero Trust
    principles, secure admin tiering, modern auth standards, conditional
    access, and multifactor authentication.

  • Co-own the health, design, and
    policy of PKI infrastructure and associated services (including
    certificate templates, CRLs, and HSMs).

  • Work closely with the Security and
    Risk teams to ensure compliance with internal controls, regulatory
    obligations, and audit findings.

Leadership
& Influence


  • Represent Workplace Technology
    Identity Engineering
    across Tesco Technology and into broader
    cross-functional initiatives.

  • Lead by example in engineering
    excellence, stakeholder engagement, and mentoring of less experienced
    engineers.

  • Promote a culture of simplification,
    technical rigour, and continuous improvement.


You will need

Required
Skills & Experience


  • Deep expertise in at least one, and
    experience with all:


    • Active Directory: design, hardening, replication, domain controller lifecycle,
      GPOs, admin tiering.

    • Azure AD / Entra ID: hybrid identity, conditional access, MFA, identity
      protection, SSO, SCIM.

    • Public Key Infrastructure (PKI): policy, lifecycle, templates, automation, CRL/OCSP, HSMs.

    • Authentication protocols: OAuth2, OpenID Connect, SAML, Kerberos, NTLM, WS-Fed.


  • Demonstrated ability to significantly
    contribute to design and delivery of identity platforms in large, complex
    environments.

  • Understanding of identity's role in
    enterprise security frameworks and compliance requirements.

  • Proficiency with scripting and
    automation tools (PowerShell, Terraform, etc.).

  • Familiar with monitoring, backup,
    recovery, and DR practices for identity systems.

  • Ensure identity services are
    designed with built-in resilience, supporting high availability, fault
    tolerance, and fast recovery across hybrid environments.

  • Contribute to Business Continuity
    Plans (BCPs), ensuring critical identity components are documented with
    clear recovery priorities.

  • Contribute to design and validation
    of Disaster Recovery (DR) strategies for directory services,
    authentication systems, and PKI, with regular failover testing and
    documented RTO/RPO.

  • Contribute to defining, and verify
    backup and recovery plans for identity infrastructure, including domain
    controllers, certificate authorities, and configuration artifacts.

  • Estimate engineering effort and
    support the costing of identity-related projects, including resource
    planning, licensing, infrastructure, and delivery timelines.

  • Partner with senior colleagues to
    help shaping and managing budgets, forecasts, and business cases for new
    identity initiatives.

Nice to Have


  • Experience integrating identity
    across Linux, SaaS, and multi-cloud platforms.

  • Understanding of M365, Microsoft
    ecosystem, and their dependency on robust identity infrastructure.

  • Exposure to identity governance,
    entitlement management, and lifecycle workflows.

Complementary
Skills


  • Strong collaboration skills across
    engineering, operations and security domains.

  • Experience with collaboration with
    product teams.

  • Commercial and vendor awareness to
    support technology selection, licensing decisions, and cost optimisation.

  • Strong written and verbal
    communication skills, with the ability to engage both engineers and senior
    stakeholders.

  • A proactive, accountable,
    influential and resilient mindset — aligned to Tesco's values and the
    mission of the Workplace Technology team.


Whats in it for you

At Tesco, we are committed to providing the best for you. 
 
As a result, our colleagues enjoy a unique, differentiated, market- competitive reward package, based on the current industry practices, for all the work they put into serving our customers, communities and planet a little better every day. 
 
Our Tesco Rewards framework consists of pillars - Fixed Pay, Incentives, and Benefits.  
 
Total Rewards offered at Tesco is determined by four principles -simple, fair, competitive, and sustainable. 
 
Salary - Your fixed pay is the guaranteed pay as per your contract of employment. 
 
Leave & Time-off - Colleagues are entitled to 30 days of leave (18 days of Earned Leave, 12 days of Casual/Sick Leave) and 10 national and festival holidays, as per the company's policy. 
 
Making Retirement Tension-FreeSalary - In addition to Statutory retirement beneets, Tesco enables colleagues to participate in voluntary programmes like NPS and VPF. 
 
Health is Wealth - Tesco promotes programmes that support a culture of health and wellness including insurance for colleagues and their family. Our medical insurance provides coverage for dependents including parents or in-laws. 
 
Mental Wellbeing - We offer mental health support through self-help tools, community groups, ally networks, face-to-face counselling, and more for both colleagues and dependents.  
 
Financial Wellbeing - Through our financial literacy partner, we offer one-to-one financial coaching at discounted rates, as well as salary advances on earned wages upon request.  
 
Save As You Earn (SAYE) - Our SAYE programme allows colleagues to transition from being employees to Tesco shareholders through a structured 3-year savings plan.  
 
Physical Wellbeing - Our green campus promotes physical wellbeing with facilities that include a cricket pitch, football field, badminton and volleyball courts, along with indoor games, encouraging a healthier lifestyle. 

About Us
At Tesco, inclusion is at the heart of everything we do. We believe in treating everyone fairly and with respect, valuing individuality and uniqueness to create a true sense of belonging. Diversity and inclusion are deeply embedded in our values—we treat people how they want to be treated. Our goal is for all colleagues to feel they can be themselves at work, and we are committed to helping them thrive. Across the Tesco group, we are building an inclusive workplace that actively celebrates the cultures, personalities, and preferences of our colleagues, who in turn contribute to the success of our business and reflect the diversity of the communities we serve. 
 
 At Tesco Bengaluru, we are proud to be a Disability Confident Committed Employer, highlighting our commitment to creating a supportive environment for individuals with disabilities. We are dedicated to offering equal opportunities for all candidates and encourage applicants with disabilities to apply. Our recruitment process is fully accessible, and we are happy to provide reasonable adjustments during interviews. If you need any accommodations to participate in the recruitment process, please let us know. We are here to ensure that everyone has the chance to succeed. 
 
 We also believe in fostering a work environment where you can excel both professionally and personally. Our hybrid model allows you to work flexibly—spend 60% of your week collaborating in person with colleagues at our office locations or local sites, and the rest of the time working remotely. We understand that everyone's life journey is unique, whether you are starting your career, pursuing passions, or navigating life changes, and we are here to support you. Flexibility is a core part of our culture, and we encourage open conversations about how we can best accommodate your needs, so talk to us throughout your application process on the support required.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 147871883