Senior IDAM Architect – Identity Pillar

location_onCoventry, United Kingdomschedule21 घंटे पहले
sync_altकाम का तरीका:हाइब्रिड
trending_upअनुभव स्तर:वरिष्ठ
historyन्यूनतम अनुभव:12+ वर्ष

पद का विवरण

Senior IDAM Architect – Identity Pillar

(Lot 1)

Location – Coventry, UK

Role Purpose

The Senior IDAM Architect is the end to

end technical authority for all Identity Pillar scope under Lot 1,

accountable for Initiate, Discovery, Design, and Implementation across Identity

Governance & Administration (IGA), Active Directory/Entra ID, RBAC/ABAC,

PKI, Conditional Access, Identity Lifecycle, CIEM, and identity threat

protection capabilities.

This role acts as the single technical

point of contact for all identity related decisions, integrations, designs, and

technical escalations, ensuring adherence to Zero Trust principles, Client

Delivery & Cyber frameworks, and the architectural governance process.

________________________________________

Key Responsibilities

1. Programme-Level Identity Architecture

Leadership

• Serve

as the lead architect for all identity capabilities: IGA, directories (AD/OT

AD/Entra ID), RBAC/ABAC, Conditional Access, PKI, CIEM, machine identity,

identity lifecycle automation.

• Own

the architectural strategy and roadmap for the Identity Pillar across Year 1

(I&D) and influence Year 2 planning.

• Act

as the single technical authority across all identity workstreams, ensuring

coherence, interoperability, and alignment with Zero Trust Identity outcomes.

• Lead

technical governance engagement: Information Security TAG, PESA approvals,

Design Authority reviews, and cross pillar integration sessions.

________________________________________

2. Initiate & Discovery

Responsibilities (Identity Specific)

• Lead

comprehensive DAAS discovery for identity components:

o identity

stores and directories

o AD

forests/domains and OT AD footprint

o application

identity models

o entitlements,

access patterns, privileged roles

o IGA

process and connector readiness

o non

human / service identities

• Conduct

identity specific discovery across:

o JML

processes, access request flows, attestation cycles

o directory

security posture (CIS benchmarks, Microsoft best practices)

o account

discovery (human, service, machine) across IT, OT, cloud, SaaS, air gapped

systems

• Evaluate

and document:

o identity

risks

o excessive

privileges

o identity

lifecycle issues

o unmanaged

accounts

o access

policy gaps

• Produce:

o discovery

logs

o dependency

registers

o technical

constraints

o discovery

outputs traceable to future designs

________________________________________

3. Identity Architecture Design

Responsibilities

IGA Architecture

• Produce

HL/ML/LLD for the IGA platform (SailPoint/Saviynt/etc.).

• Define

architecture for:

o lifecycle

automation (Joiner/Mover/Leaver)

o access

request & approval workflows

o entitlements

management

o attestation

& certification

o role

mining & identity analytics

• Define

integration patterns with:

o HR

(authoritative source)

o AD/OT

AD/Entra ID

o ServiceNow

o SIEM

for identity related detections

o PAM/PIM

for privileged identities

Directory Services & Identity Core

• Produce

architecture for AD, Entra ID, and OT AD identity capabilities:

o secure

configuration baselines

o naming

conventions, OU design, GPO strategy

o trust

boundaries, domain/forest design

o identity

lifecycle & sync patterns

o directory-tiering

strategy (Tier 0)

RBAC / ABAC

• Define

enterprise RBAC/ABAC models:

o business

roles

o application

roles

o segregation

of duties

o governance

and lifecycle of roles

• Ensure

alignment with HR data models and IGA role mining outputs.

Conditional Access & Authentication

• Architect

conditional access policies (CA rules, sign in risk, device trust, session

controls).

• Define

MFA strategy: Authenticator App, FIDO2, passwordless, biometrics.

• Define

Zero Trust authentication patterns for:

o privileged

identities

o third

parties

o mobile/remote

users

o OT

identities where applicable

PKI & Certificate Lifecycle

• Produce

architecture for PKI, certificate issuance, renewal, and lifecycle governance.

• Define

trust anchors and certificate policies for:

o user

identities

o device

identities

o service

principals

o OT

and cloud workloads

CIEM (Cloud Infrastructure Entitlement

Management)

• Define

cloud identity entitlement patterns (Azure/AWS).

• Establish

least privilege, JIT/JEA patterns for cloud workloads.

________________________________________

4. Implementation Responsibilities

(Identity-Focused)

• Provide

hands on architectural oversight to ensure implementations follow approved

designs.

• Oversee

rollout and validation of:

o IGA

connectors, workflows, lifecycle processes

o AD/Entra

ID configuration updates and hardening

o Conditional

access/MFA/policy rollout

o RBAC

role deployment and attestation setup

o PKI

enhancements, CA templates, certificate workflows

o CIEM

configuration and governance

• Guide

identity engineers and application onboarding teams through technical

sequencing, integration steps, and issue resolution.

• Validate

end to end identity flows (authentication, provisioning, deprovisioning,

attestation).

________________________________________

5. Identity Governance, Compliance &

Risk

• Ensure

all identity designs align with:

o Zero

Trust Identity requirements

o CAF/eCAF

outcomes

o regulatory

and compliance frameworks (GDPR, NIS R, PCI DSS)

• Define

governance processes for:

o privileged

identity control

o identity

data quality

o access

attestation

o policy

exceptions

• Support

the audit and compliance teams with identity reporting, evidence, and control

design.

________________________________________

6. Stakeholder & Technical Leadership

• Act

as the single point of contact for all identity related technical matters

across the programme.

• Lead

communication with:

o Cyber

Architecture

o HR,

IT Ops, Security Operations

o Application

teams

o OT

Identity & OT Engineering teams

• Conduct

design walkthroughs, knowledge handovers, and training sessions for BAU teams.

• Resolve

identity related escalations, engineering blockers, and architecture decision

disputes.

________________________________________

Skills & Experience Requirements

(Identity Scope)

Technical Expertise

• 12+

years in Identity & Access Management architecture.

• Deep

expertise in:

o IGA

(SailPoint/Saviynt), RBAC/ABAC

o AD/Entra

ID/OT AD

o Authentication/Federation

(SAML, OAuth2, OIDC)

o Conditional

Access & MFA

o PKI

& Certificate Lifecycle

o CIEM,

cloud identity & Zero Trust identity patterns

• Extensive

experience designing and integrating identity capabilities across hybrid

(IT/OT) landscapes.

Delivery & Architecture

• Proven

experience delivering large-scale IAM transformations end to end.

• Strong

architectural documentation and governance skills.

• Ability

to lead multi vendor and multi platform identity delivery teams.

Behavioural

• Executive-level

communication and architectural leadership.

• Operates

confidently across strategic, detailed technical, and operational domains.

• Structured,

methodical, collaborative, and outcome driven.

________________________________________

Key Deliverables

• Identity

DAAS Discovery Reports

• Requirements

(Functional & Non Functional)

• High/Mid/Low-Level

Identity Designs

• IGA

Architecture, Connector Designs & Workflow Specifications

• Directory

Services Architecture Pack

• RBAC/ABAC

Role Taxonomy & Governance Framework

• Conditional

Access & MFA Design Pack

• PKI

Architecture & Lifecycle Model

• Identity

Implementation Playbooks

• Governance,

Controls & Attestation Designs

• Technical

submissions for TAG/PESA/Design Authority

उल्लिखित कौशल

इस पद के लिए आवेदन करें

Use the application link supplied with this listing to apply to Test Triangle. Check the destination before entering personal information.