IAM Security Architect
- Salary
- £780/day
- Hiring from
- United Kingdom
- Work type
- Remote
- Posted
530,570 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
IAM Cloud Security Architect
£780 PER DAY
INSIDE IR35
12 MONTH CONTRACT
UK REMOTE
Role purpose
Provide senior architecture and delivery capability across Identity & Access Management (IAM), Identity Governance and Administration (IGA), and Cloud Security, translating a complex identity and cloud-security modernisation agenda into robust target-state architectures, reusable security patterns, governance artefacts and implementation roadmaps.
Working closely with the IAM domain owner, enterprise architects, cloud/platform teams and security engineering, the architect will help drive the organisation from current-state identity and cloud controls towards a scalable, risk-based and well-governed target architecture across workforce, privileged, non-human and agentic identities.
Key responsibilities
- Define and maintain the target-state IAM and Cloud Security architecture, aligned to enterprise security strategy, regulatory requirements and technology roadmaps.
- Develop the architecture and implementation approach for IGA and access certification, including risk-based certification models, identity lifecycle governance, tooling/vendor assessment and migration strategy.
- Support the design, pilot and phased implementation of IGA / Access Certification platforms, ensuring appropriate integration with Active Directory, Entra ID, applications and privileged-access capabilities.
- Assess and architect Identity Verification (ID&V) solutions for helpdesk, self-service and identity recovery journeys, including integration with external identity-verification providers.
- Define architecture for Enterprise Password Management, including workforce identity integration, privileged access considerations and security/tooling governance.
- Develop target-state architecture for Non-Human and Machine Identity, covering service accounts, workload identities, secrets, certificates, ownership, lifecycle management and access governance.
- Define the architecture for AI and Agentic Identity Lifecycle Management, covering discovery, authentication, authorisation, identity propagation, accountability and cross-domain security controls for AI agents and machine identities.
- Develop and maintain IAM security patterns covering:
- Non-Human Identity
- Agentic / AI Identity
- Federation and SSO
- Privileged Access Management
- Identity Propagation
- Cross-Account Cloud Access
- Mobile Access Credentials
- Machine and Workload Identity
- Develop and maintain cloud security architecture patterns covering:
- Public Cloud Landing Zones
- Multi-Cloud Security
- Secure Workload Deployment
- Cloud Control Evidence
- Third-Party Managed Compute
- Cloud File Transfer
- SaaS Connectivity and Ingress/Egress
- Architect secure identity integration across Microsoft Entra ID, Active Directory, cloud platforms, SaaS applications and third-party services.
- Assess and design appropriate controls for AWS / Azure / GCP cloud environments, including identity federation, workload identity, privileged access, cross-account access and least-privilege controls.
- Support technology and vendor assessments, including evaluation of IAM, IGA, PAM, ID&V and cloud-security platforms.
- Identify architectural risks, dependencies and gaps across IAM and cloud environments and define pragmatic remediation strategies.
- Drive consistency and reuse through a controlled library of IAM and cloud-security reference patterns and standards.
Required experience & skills
- Significant experience as a Security Architect, IAM Architect, Cloud Security Architect or Enterprise/Solution Architect within a complex enterprise environment.
- Strong hands-on architecture experience across both IAM and Cloud Security; candidates should have genuine depth in both areas rather than being primarily a generic cloud architect.
- Experience designing and delivering IAM solutions across Active Directory and Microsoft Entra ID, including authentication, authorisation, federation, SSO and identity lifecycle management.
- Practical experience with IGA / access certification technologies, such as SailPoint, Saviynt or equivalent platforms.
- Strong understanding of Privileged Access Management (PAM), least privilege, identity governance and access-control models.
- Experience with non-human identities, workload identities, service accounts, secrets, certificates and machine-to-machine authentication.
- Strong understanding of cloud IAM and security architecture across one or more of Azure, AWS and GCP, with exposure to multi-cloud environments highly desirable.
- Experience designing cloud landing zones, cloud identity models, cross-account access, workload security and secure cloud connectivity.
- Experience with federation protocols and standards, such as SAML, OAuth 2.0 and OpenID Connect.
- Understanding of modern identity technologies including Zero Trust, passwordless authentication, FIDO2/WebAuthn and conditional access.
- Awareness of emerging AI/agentic identity and machine identity challenges, including authentication, authorisation, identity lifecycle, non-human access and accountability.
- Experience working in regulated environments, with financial services, banking or similarly controlled industries strongly preferred.
- Strong understanding of security governance, risk management, architecture principles and regulatory/control frameworks.
- Comfortable operating through Architecture Review Boards, Design Authorities, Security Governance and Risk/Exception processes.
- Able to produce detailed and structured architecture artefacts rather than providing purely advisory or verbal input.
- Strong stakeholder-management skills, with the ability to work effectively with enterprise architects, security teams, IAM engineers, cloud/platform teams, product owners, vendors and senior governance stakeholders.
- Ability to translate complex technical and security concepts into clear architecture decisions and actionable implementation plans.
Desirable experience
- Experience with SailPoint, Saviynt, CyberArk, BeyondTrust or equivalent IAM/PAM platforms.
- Experience with Microsoft Entra ID Governance / Entra ID Protection.
- Knowledge of NIST, ISO 27001, CIS, SOC 2, DORA, EBA or equivalent regulatory/security frameworks.
- Experience producing security architecture using recognised frameworks such as SABSA, TOGAF or equivalent.