Senior IDAM Architect – Identity Pillar

Posted 3 Days Ago
Be an Early Applicant
Coventry, West Midlands, England, GBR
In-Office
Senior level
Information Technology • Software • Consulting
The Role
Leads end-to-end identity architecture across IGA, Active Directory, Entra ID, RBAC/ABAC, PKI, Conditional Access, CIEM, lifecycle automation, and identity threat protection. Owns discovery, architecture, governance, implementation oversight, technical escalations, and stakeholder leadership across hybrid IT/OT environments. Develops identity designs, security baselines, authentication strategies, role models, certificate lifecycle processes, and compliance controls while guiding multi-vendor delivery teams.
Summary Generated by Built In

Senior IDAM Architect – Identity Pillar (Lot 1)
Location – Coventry, UK

Role Purpose

The Senior IDAM Architect is the ** end to end technical authority for all Identity Pillar scope under Lot 1**, accountable for Initiate, Discovery, Design, and Implementation across Identity Governance & Administration (IGA), Active Directory/Entra ID, RBAC/ABAC, PKI, Conditional Access, Identity Lifecycle, CIEM, and identity threat protection capabilities.

This role acts as the single technical point of contact for all identity related decisions, integrations, designs, and technical escalations, ensuring adherence to Zero Trust principles, Client Delivery & Cyber frameworks, and the architectural governance process.

________________________________________

Key Responsibilities

1. Programme-Level Identity Architecture Leadership

•            Serve as the lead architect for all identity capabilities: IGA, directories (AD/OT AD/Entra ID), RBAC/ABAC, Conditional Access, PKI, CIEM, machine identity, identity lifecycle automation.

•            Own the architectural strategy and roadmap for the Identity Pillar across Year 1 (I&D) and influence Year 2 planning.

•            Act as the single technical authority across all identity workstreams, ensuring coherence, interoperability, and alignment with Zero Trust Identity outcomes.

•            Lead technical governance engagement: Information Security TAG, PESA approvals, Design Authority reviews, and cross pillar integration sessions.

________________________________________

2. Initiate & Discovery Responsibilities (Identity Specific)

•            Lead comprehensive DAAS discovery for identity components:

o            identity stores and directories

o            AD forests/domains and OT AD footprint

o            application identity models

o            entitlements, access patterns, privileged roles

o            IGA process and connector readiness

o            non human / service identities

•            Conduct identity specific discovery across:

o            JML processes, access request flows, attestation cycles

o            directory security posture (CIS benchmarks, Microsoft best practices)

o            account discovery (human, service, machine) across IT, OT, cloud, SaaS, air gapped systems

•            Evaluate and document:

o            identity risks

o            excessive privileges

o            identity lifecycle issues

o            unmanaged accounts

o            access policy gaps

•            Produce:

o            discovery logs

o            dependency registers

o            technical constraints

o            discovery outputs traceable to future designs

________________________________________

3. Identity Architecture Design Responsibilities

IGA Architecture

•            Produce HL/ML/LLD for the IGA platform (SailPoint/Saviynt/etc.).

•            Define architecture for:

o            lifecycle automation (Joiner/Mover/Leaver)

o            access request & approval workflows

o            entitlements management

o            attestation & certification

o            role mining & identity analytics

•            Define integration patterns with:

o            HR (authoritative source)

o            AD/OT AD/Entra ID

o            ServiceNow

o            SIEM for identity related detections

o            PAM/PIM for privileged identities

Directory Services & Identity Core

•            Produce architecture for AD, Entra ID, and OT AD identity capabilities:

o            secure configuration baselines

o            naming conventions, OU design, GPO strategy

o            trust boundaries, domain/forest design

o            identity lifecycle & sync patterns

o            directory-tiering strategy (Tier 0)

RBAC / ABAC

•            Define enterprise RBAC/ABAC models:

o            business roles

o            application roles

o            segregation of duties

o            governance and lifecycle of roles

•            Ensure alignment with HR data models and IGA role mining outputs.

Conditional Access & Authentication

•            Architect conditional access policies (CA rules, sign in risk, device trust, session controls).

•            Define MFA strategy: Authenticator App, FIDO2, passwordless, biometrics.

•            Define Zero Trust authentication patterns for:

o            privileged identities

o            third parties

o            mobile/remote users

o            OT identities where applicable

PKI & Certificate Lifecycle

•            Produce architecture for PKI, certificate issuance, renewal, and lifecycle governance.

•            Define trust anchors and certificate policies for:

o            user identities

o            device identities

o            service principals

o            OT and cloud workloads

CIEM (Cloud Infrastructure Entitlement Management)

•            Define cloud identity entitlement patterns (Azure/AWS).

•            Establish least privilege, JIT/JEA patterns for cloud workloads.

________________________________________

4. Implementation Responsibilities (Identity-Focused)

•            Provide hands on architectural oversight to ensure implementations follow approved designs.

•            Oversee rollout and validation of:

o            IGA connectors, workflows, lifecycle processes

o            AD/Entra ID configuration updates and hardening

o            Conditional access/MFA/policy rollout

o            RBAC role deployment and attestation setup

o            PKI enhancements, CA templates, certificate workflows

o            CIEM configuration and governance

•            Guide identity engineers and application onboarding teams through technical sequencing, integration steps, and issue resolution.

•            Validate end to end identity flows (authentication, provisioning, deprovisioning, attestation).

________________________________________

5. Identity Governance, Compliance & Risk

•            Ensure all identity designs align with:

o            Zero Trust Identity requirements

o            CAF/eCAF outcomes

o            regulatory and compliance frameworks (GDPR, NIS R, PCI DSS)

•            Define governance processes for:

o            privileged identity control

o            identity data quality

o            access attestation

o            policy exceptions

•            Support the audit and compliance teams with identity reporting, evidence, and control design.

________________________________________

6. Stakeholder & Technical Leadership

•            Act as the single point of contact for all identity related technical matters across the programme.

•            Lead communication with:

o            Cyber Architecture

o            HR, IT Ops, Security Operations

o            Application teams

o            OT Identity & OT Engineering teams

•            Conduct design walkthroughs, knowledge handovers, and training sessions for BAU teams.

•            Resolve identity related escalations, engineering blockers, and architecture decision disputes.

________________________________________

Skills & Experience Requirements (Identity Scope)

Technical Expertise

•            12+ years in Identity & Access Management architecture.

•            Deep expertise in:

o            IGA (SailPoint/Saviynt), RBAC/ABAC

o            AD/Entra ID/OT AD

o            Authentication/Federation (SAML, OAuth2, OIDC)

o            Conditional Access & MFA

o            PKI & Certificate Lifecycle

o            CIEM, cloud identity & Zero Trust identity patterns

•            Extensive experience designing and integrating identity capabilities across hybrid (IT/OT) landscapes.

Delivery & Architecture

•            Proven experience delivering large-scale IAM transformations end to end.

•            Strong architectural documentation and governance skills.

•            Ability to lead multi vendor and multi platform identity delivery teams.

Behavioural

•            Executive-level communication and architectural leadership.

•            Operates confidently across strategic, detailed technical, and operational domains.

•            Structured, methodical, collaborative, and outcome driven.

________________________________________

Key Deliverables

•            Identity DAAS Discovery Reports

•            Requirements (Functional & Non Functional)

•            High/Mid/Low-Level Identity Designs

•            IGA Architecture, Connector Designs & Workflow Specifications

•            Directory Services Architecture Pack

•            RBAC/ABAC Role Taxonomy & Governance Framework

•            Conditional Access & MFA Design Pack

•            PKI Architecture & Lifecycle Model

•            Identity Implementation Playbooks

•            Governance, Controls & Attestation Designs

•            Technical submissions for TAG/PESA/Design Authority

 



Skills Required

  • 12+ years of experience in Identity and Access Management architecture
  • Deep expertise in IGA platforms such as SailPoint or Saviynt
  • Expertise in RBAC and ABAC
  • Expertise in Active Directory, Entra ID, and OT Active Directory
  • Expertise in authentication and federation technologies including SAML, OAuth2, and OIDC
  • Expertise in Conditional Access and MFA
  • Expertise in PKI and certificate lifecycle management
  • Expertise in CIEM, cloud identity, and Zero Trust identity patterns
  • Extensive experience designing and integrating identity capabilities across hybrid IT/OT landscapes
  • Proven experience delivering large-scale IAM transformations end to end
  • Strong architectural documentation and governance skills
  • Ability to lead multi-vendor and multi-platform identity delivery teams
  • Executive-level communication and architectural leadership
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dublin
104 Employees
Year Founded: 2012

What We Do

Test Triangle is a Dublin-headquartered technology services company founded in 2012. It helps organizations transform operations through IT service management, digital transformation, software testing and quality assurance, cloud solutions, consulting, managed services, and recruitment. The company also provides application testing, DevOps, robotic process automation, software and mobile development, technology training, staffing, and resource augmentation across Ireland, the UK, and international markets.

Similar Jobs

CrowdStrike Logo CrowdStrike

Senior Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
London, Greater London, England, GBR
11000 Employees
Remote or Hybrid
2 Locations
1100 Employees
Hybrid
London, Greater London, England, GBR
1100 Employees

NBCUniversal Logo NBCUniversal

Design Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Hybrid
Bedford, Bedfordshire, England, GBR

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account