Senior IDAM Architect - Identity Pillar

Posted 4 hours 2 minutes ago by Zohorecruit

Permanent
Full Time
Other
Warwickshire, Coventry, United Kingdom, CV1 1
Job Description

Coventry, United Kingdom Posted on 10/05/2026

Senior IDAM Architect - Identity Pillar(Lot 1)

Location - Coventry, UK

Role Purpose

The Senior IDAM Architect is the end toend technical authority for all Identity Pillar scope under Lot 1,accountable for Initiate, Discovery, Design, and Implementation across IdentityGovernance & Administration (IGA), Active Directory/Entra ID, RBAC/ABAC,PKI, Conditional Access, Identity Lifecycle, CIEM, and identity threatprotection capabilities.

This role acts as the single technicalpoint of contact for all identity related decisions, integrations, designs, andtechnical escalations, ensuring adherence to Zero Trust principles, ClientDelivery & Cyber frameworks, and the architectural governance process.

Key Responsibilities 1. Programme-Level Identity ArchitectureLeadership
  • Serveas the lead architect for all identity capabilities: IGA, directories (AD/OTAD/Entra ID), RBAC/ABAC, Conditional Access, PKI, CIEM, machine identity,identity lifecycle automation.
  • Ownthe architectural strategy and roadmap for the Identity Pillar across Year 1(I&D) and influence Year 2 planning.
  • Actas the single technical authority across all identity workstreams, ensuringcoherence, interoperability, and alignment with Zero Trust Identity outcomes.
  • Leadtechnical governance engagement: Information Security TAG, PESA approvals,Design Authority reviews, and cross pillar integration sessions.
2. Initiate & DiscoveryResponsibilities (Identity Specific)
  • Leadcomprehensive DAAS discovery for identity components:
    • oidentitystores and directories
    • oADforests/domains and OT AD footprint
    • oapplicationidentity models
    • oentitlements,access patterns, privileged roles
    • oIGAprocess and connector readiness
    • ononhuman / service identities
  • Conductidentity specific discovery across:
    • oJMLprocesses, access request flows, attestation cycles
    • odirectorysecurity posture (CIS benchmarks, Microsoft best practices)
    • oaccountdiscovery (human, service, machine) across IT, OT, cloud, SaaS, air gappedsystems
  • Evaluateand document:
    • oidentityrisks
    • oidentitylifecycle issues
    • ounmanagedaccounts
    • oaccesspolicy gaps
    • odiscoverylogs
    • otechnicalconstraints
    • odiscoveryoutputs traceable to future designs
3. Identity Architecture DesignResponsibilities
  • ProduceHL/ML/LLD for the IGA platform (SailPoint/Saviynt/etc.).
    • olifecycleautomation (Joiner/Mover/Leaver)
    • oentitlementsmanagement
    • orolemining & identity analytics
  • Defineintegration patterns with:
    • oServiceNow
    • oSIEMfor identity related detections
    • oPAM/PIMfor privileged identities
  • Producearchitecture for AD, Entra ID, and OT AD identity capabilities:
    • osecureconfiguration baselines
    • onamingconventions, OU design, GPO strategy
    • oidentitylifecycle & sync patterns
    • odirectory-tieringstrategy (Tier 0)
  • Defineenterprise RBAC/ABAC models:
    • obusinessroles
    • oapplicationroles
    • osegregationof duties
    • ogovernanceand lifecycle of roles
Conditional Access & Authentication
  • Architectconditional access policies (CA rules, sign in risk, device trust, sessioncontrols).
  • DefineMFA strategy: Authenticator App, FIDO2, passwordless, biometrics.
  • DefineZero Trust authentication patterns for:
    • othirdparties
    • oOTidentities where applicable
PKI & Certificate Lifecycle
  • Producearchitecture for PKI, certificate issuance, renewal, and lifecycle governance.
  • Definetrust anchors and certificate policies for:
    • ouseridentities
    • oOTand cloud workloads
  • Definecloud identity entitlement patterns (Azure/AWS).
  • Establishleast privilege, JIT/JEA patterns for cloud workloads.
4. Implementation Responsibilities(Identity-Focused)
  • Providehands on architectural oversight to ensure implementations follow approveddesigns.
  • Overseerollout and validation of:
    • oIGAconnectors, workflows, lifecycle processes
    • oAD/EntraID configuration updates and hardening
    • oConditionalaccess/MFA/policy rollout
    • oRBACrole deployment and attestation setup
    • oPKIenhancements, CA templates, certificate workflows
    • oCIEMconfiguration and governance
  • Guideidentity engineers and application onboarding teams through technicalsequencing, integration steps, and issue resolution.
  • Validateend to end identity flows (authentication, provisioning, deprovisioning,attestation).
5. Identity Governance, Compliance &Risk
  • Ensureall identity designs align with:
    • oZeroTrust Identity requirements
    • oCAF/eCAFoutcomes
    • oregulatoryand compliance frameworks (GDPR, NIS R, PCI DSS)
  • Definegovernance processes for:
    • oprivilegedidentity control
    • opolicyexceptions
  • Supportthe audit and compliance teams with identity reporting, evidence, and controldesign.
6. Stakeholder & Technical Leadership
  • Actas the single point of contact for all identity related technical mattersacross the programme.
  • Leadcommunication with:
    • oHR,IT Ops, Security Operations
    • oApplicationteams
    • oOTIdentity & OT Engineering teams
  • Conductdesign walkthroughs, knowledge handovers, and training sessions for BAU teams.
  • Resolveidentity related escalations, engineering blockers, and architecture decisiondisputes.
Skills & Experience Requirements(Identity Scope) Technical Expertise
  • 12+years in Identity & Access Management architecture.
  • oIGA(SailPoint/Saviynt), RBAC/ABAC
  • oAD/EntraID/OT AD
  • oConditionalAccess & MFA
  • oPKI& Certificate Lifecycle
  • oCIEM,cloud identity & Zero Trust identity patterns
  • Extensiveexperience designing and integrating identity capabilities across hybrid(IT/OT) landscapes.
Delivery & Architecture
  • Provenexperience delivering large-scale IAM transformations end to end.
  • Strongarchitectural documentation and governance skills.
  • Abilityto lead multi vendor and multi platform identity delivery teams.
Behavioural
  • Executive-levelcommunication and architectural leadership.
  • Operatesconfidently across strategic, detailed technical, and operational domains.
  • Structured,methodical, collaborative, and outcome driven.

Requirements(Functional & Non Functional)
  • High/Mid/Low-LevelIdentity Designs
  • ConditionalAccess & MFA Design Pack
  • Technicalsubmissions for TAG/PESA/Design Authority