NineTech logo

IAM Security Architect

Salary
£780/day
Hiring from
United Kingdom
Work type
Remote
Posted
Is this job info correct?

530,570 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

IAM Cloud Security Architect

£780 PER DAY

INSIDE IR35

12 MONTH CONTRACT

UK REMOTE


Role purpose

Provide senior architecture and delivery capability across Identity & Access Management (IAM), Identity Governance and Administration (IGA), and Cloud Security, translating a complex identity and cloud-security modernisation agenda into robust target-state architectures, reusable security patterns, governance artefacts and implementation roadmaps.

Working closely with the IAM domain owner, enterprise architects, cloud/platform teams and security engineering, the architect will help drive the organisation from current-state identity and cloud controls towards a scalable, risk-based and well-governed target architecture across workforce, privileged, non-human and agentic identities.


Key responsibilities

  • Define and maintain the target-state IAM and Cloud Security architecture, aligned to enterprise security strategy, regulatory requirements and technology roadmaps.
  • Develop the architecture and implementation approach for IGA and access certification, including risk-based certification models, identity lifecycle governance, tooling/vendor assessment and migration strategy.
  • Support the design, pilot and phased implementation of IGA / Access Certification platforms, ensuring appropriate integration with Active Directory, Entra ID, applications and privileged-access capabilities.
  • Assess and architect Identity Verification (ID&V) solutions for helpdesk, self-service and identity recovery journeys, including integration with external identity-verification providers.
  • Define architecture for Enterprise Password Management, including workforce identity integration, privileged access considerations and security/tooling governance.
  • Develop target-state architecture for Non-Human and Machine Identity, covering service accounts, workload identities, secrets, certificates, ownership, lifecycle management and access governance.
  • Define the architecture for AI and Agentic Identity Lifecycle Management, covering discovery, authentication, authorisation, identity propagation, accountability and cross-domain security controls for AI agents and machine identities.
  • Develop and maintain IAM security patterns covering:
  • Non-Human Identity
  • Agentic / AI Identity
  • Federation and SSO
  • Privileged Access Management
  • Identity Propagation
  • Cross-Account Cloud Access
  • Mobile Access Credentials
  • Machine and Workload Identity
  • Develop and maintain cloud security architecture patterns covering:
  • Public Cloud Landing Zones
  • Multi-Cloud Security
  • Secure Workload Deployment
  • Cloud Control Evidence
  • Third-Party Managed Compute
  • Cloud File Transfer
  • SaaS Connectivity and Ingress/Egress
  • Architect secure identity integration across Microsoft Entra ID, Active Directory, cloud platforms, SaaS applications and third-party services.
  • Assess and design appropriate controls for AWS / Azure / GCP cloud environments, including identity federation, workload identity, privileged access, cross-account access and least-privilege controls.
  • Support technology and vendor assessments, including evaluation of IAM, IGA, PAM, ID&V and cloud-security platforms.
  • Identify architectural risks, dependencies and gaps across IAM and cloud environments and define pragmatic remediation strategies.
  • Drive consistency and reuse through a controlled library of IAM and cloud-security reference patterns and standards.


Required experience & skills

  • Significant experience as a Security Architect, IAM Architect, Cloud Security Architect or Enterprise/Solution Architect within a complex enterprise environment.
  • Strong hands-on architecture experience across both IAM and Cloud Security; candidates should have genuine depth in both areas rather than being primarily a generic cloud architect.
  • Experience designing and delivering IAM solutions across Active Directory and Microsoft Entra ID, including authentication, authorisation, federation, SSO and identity lifecycle management.
  • Practical experience with IGA / access certification technologies, such as SailPoint, Saviynt or equivalent platforms.
  • Strong understanding of Privileged Access Management (PAM), least privilege, identity governance and access-control models.
  • Experience with non-human identities, workload identities, service accounts, secrets, certificates and machine-to-machine authentication.
  • Strong understanding of cloud IAM and security architecture across one or more of Azure, AWS and GCP, with exposure to multi-cloud environments highly desirable.
  • Experience designing cloud landing zones, cloud identity models, cross-account access, workload security and secure cloud connectivity.
  • Experience with federation protocols and standards, such as SAML, OAuth 2.0 and OpenID Connect.
  • Understanding of modern identity technologies including Zero Trust, passwordless authentication, FIDO2/WebAuthn and conditional access.
  • Awareness of emerging AI/agentic identity and machine identity challenges, including authentication, authorisation, identity lifecycle, non-human access and accountability.
  • Experience working in regulated environments, with financial services, banking or similarly controlled industries strongly preferred.
  • Strong understanding of security governance, risk management, architecture principles and regulatory/control frameworks.
  • Comfortable operating through Architecture Review Boards, Design Authorities, Security Governance and Risk/Exception processes.
  • Able to produce detailed and structured architecture artefacts rather than providing purely advisory or verbal input.
  • Strong stakeholder-management skills, with the ability to work effectively with enterprise architects, security teams, IAM engineers, cloud/platform teams, product owners, vendors and senior governance stakeholders.
  • Ability to translate complex technical and security concepts into clear architecture decisions and actionable implementation plans.
  • Desirable experience

    • Experience with SailPoint, Saviynt, CyberArk, BeyondTrust or equivalent IAM/PAM platforms.
    • Experience with Microsoft Entra ID Governance / Entra ID Protection.
    • Knowledge of NIST, ISO 27001, CIS, SOC 2, DORA, EBA or equivalent regulatory/security frameworks.
    • Experience producing security architecture using recognised frameworks such as SABSA, TOGAF or equivalent.


    Similar jobs

    Apply on LinkedIn