Job description
Senior IDAM Architect – Identity Pillar
(Lot 1)
Location – Coventry, UK
Role Purpose
The Senior IDAM Architect is the ** end to
end technical authority for all Identity Pillar scope under Lot 1**,
accountable for Initiate, Discovery, Design, and Implementation across Identity
Governance & Administration (IGA), Active Directory/Entra ID, RBAC/ABAC,
PKI, Conditional Access, Identity Lifecycle, CIEM, and identity threat
protection capabilities.
This role acts as the single technical
point of contact for all identity related decisions, integrations, designs, and
technical escalations, ensuring adherence to Zero Trust principles, Client
Delivery & Cyber frameworks, and the architectural governance process.
________________________________________
Key Responsibilities
1. Programme-Level Identity Architecture
Leadership
• Serve
as the lead architect for all identity capabilities: IGA, directories (AD/OT
AD/Entra ID), RBAC/ABAC, Conditional Access, PKI, CIEM, machine identity,
identity lifecycle automation.
• Own
the architectural strategy and roadmap for the Identity Pillar across Year 1
(I&D) and influence Year 2 planning.
• Act
as the single technical authority across all identity workstreams, ensuring
coherence, interoperability, and alignment with Zero Trust Identity outcomes.
• Lead
technical governance engagement: Information Security TAG, PESA approvals,
Design Authority reviews, and cross pillar integration sessions.
________________________________________
2. Initiate & Discovery
Responsibilities (Identity Specific)
• Lead
comprehensive DAAS discovery for identity components:
o identity
stores and directories
o AD
forests/domains and OT AD footprint
o application
identity models
o entitlements,
access patterns, privileged roles
o IGA
process and connector readiness
o non
human / service identities
• Conduct
identity specific discovery across:
o JML
processes, access request flows, attestation cycles
o directory
security posture (CIS benchmarks, Microsoft best practices)
o account
discovery (human, service, machine) across IT, OT, cloud, SaaS, air gapped
systems
• Evaluate
and document:
o identity
risks
o excessive
privileges
o identity
lifecycle issues
o unmanaged
accounts
o access
policy gaps
• Produce:
o discovery
logs
o dependency
registers
o technical
constraints
o discovery
outputs traceable to future designs
________________________________________
3. Identity Architecture Design
Responsibilities
IGA Architecture
• Produce
HL/ML/LLD for the IGA platform (SailPoint/Saviynt/etc.).
• Define
architecture for:
o lifecycle
automation (Joiner/Mover/Leaver)
o access
request & approval workflows
o entitlements
management
o attestation
& certification
o role
mining & identity analytics
• Define
integration patterns with:
o HR
(authoritative source)
o AD/OT
AD/Entra ID
o ServiceNow
o SIEM
for identity related detections
o PAM/PIM
for privileged identities
Directory Services & Identity Core
• Produce
architecture for AD, Entra ID, and OT AD identity capabilities:
o secure
configuration baselines
o naming
conventions, OU design, GPO strategy
o trust
boundaries, domain/forest design
o identity
lifecycle & sync patterns
o directory-tiering
strategy (Tier 0)
RBAC / ABAC
• Define
enterprise RBAC/ABAC models:
o business
roles
o application
roles
o segregation
of duties
o governance
and lifecycle of roles
• Ensure
alignment with HR data models and IGA role mining outputs.
Conditional Access & Authentication
• Architect
conditional access policies (CA rules, sign in risk, device trust, session
controls).
• Define
MFA strategy: Authenticator App, FIDO2, passwordless, biometrics.
• Define
Zero Trust authentication patterns for:
o privileged
identities
o third
parties
o mobile/remote
users
o OT
identities where applicable
PKI & Certificate Lifecycle
• Produce
architecture for PKI, certificate issuance, renewal, and lifecycle governance.
• Define
trust anchors and certificate policies for:
o user
identities
o device
identities
o service
principals
o OT
and cloud workloads
CIEM (Cloud Infrastructure Entitlement
Management)
• Define
cloud identity entitlement patterns (Azure/AWS).
• Establish
least privilege, JIT/JEA patterns for cloud workloads.
________________________________________
4. Implementation Responsibilities
(Identity-Focused)
• Provide
hands on architectural oversight to ensure implementations follow approved
designs.
• Oversee
rollout and validation of:
o IGA
connectors, workflows, lifecycle processes
o AD/Entra
ID configuration updates and hardening
o Conditional
access/MFA/policy rollout
o RBAC
role deployment and attestation setup
o PKI
enhancements, CA templates, certificate workflows
o CIEM
configuration and governance
• Guide
identity engineers and application onboarding teams through technical
sequencing, integration steps, and issue resolution.
• Validate
end to end identity flows (authentication, provisioning, deprovisioning,
attestation).
________________________________________
5. Identity Governance, Compliance &
Risk
• Ensure
all identity designs align with:
o Zero
Trust Identity requirements
o CAF/eCAF
outcomes
o regulatory
and compliance frameworks (GDPR, NIS R, PCI DSS)
• Define
governance processes for:
o privileged
identity control
o identity
data quality
o access
attestation
o policy
exceptions
• Support
the audit and compliance teams with identity reporting, evidence, and control
design.
________________________________________
6. Stakeholder & Technical Leadership
• Act
as the single point of contact for all identity related technical matters
across the programme.
• Lead
communication with:
o Cyber
Architecture
o HR,
IT Ops, Security Operations
o Application
teams
o OT
Identity & OT Engineering teams
• Conduct
design walkthroughs, knowledge handovers, and training sessions for BAU teams.
• Resolve
identity related escalations, engineering blockers, and architecture decision
disputes.
________________________________________
Skills & Experience Requirements
(Identity Scope)
Technical Expertise
• 12+
years in Identity & Access Management architecture.
• Deep
expertise in:
o IGA
(SailPoint/Saviynt), RBAC/ABAC
o AD/Entra
ID/OT AD
o Authentication/Federation
(SAML, OAuth2, OIDC)
o Conditional
Access & MFA
o PKI
& Certificate Lifecycle
o CIEM,
cloud identity & Zero Trust identity patterns
• Extensive
experience designing and integrating identity capabilities across hybrid
(IT/OT) landscapes.
Delivery & Architecture
• Proven
experience delivering large-scale IAM transformations end to end.
• Strong
architectural documentation and governance skills.
• Ability
to lead multi vendor and multi platform identity delivery teams.
Behavioural
• Executive-level
communication and architectural leadership.
• Operates
confidently across strategic, detailed technical, and operational domains.
• Structured,
methodical, collaborative, and outcome driven.
________________________________________
Key Deliverables
• Identity
DAAS Discovery Reports
• Requirements
(Functional & Non Functional)
• High/Mid/Low-Level
Identity Designs
• IGA
Architecture, Connector Designs & Workflow Specifications
• Directory
Services Architecture Pack
• RBAC/ABAC
Role Taxonomy & Governance Framework
• Conditional
Access & MFA Design Pack
• PKI
Architecture & Lifecycle Model
• Identity
Implementation Playbooks
• Governance,
Controls & Attestation Designs
• Technical
submissions for TAG/PESA/Design Authority