Senior IDAM Architect – Identity Pillar in Coventry

Senior IDAM Architect – Identity Pillar in Coventry

Coventry Full-Time On-site
Z

Senior IDAM Architect – Identity Pillar (Lot 1)

Location – Coventry, UK

Role Purpose

The Senior IDAM Architect is the ** end to end technical authority for all Identity Pillar scope under Lot 1**, accountable for Initiate, Discovery, Design, and Implementation across Identity Governance & Administration (IGA), Active Directory/Entra ID, RBAC/ABAC, PKI, Conditional Access, Identity Lifecycle, CIEM, and identity threat protection capabilities.

This role acts as the single technical point of contact for all identity related decisions, integrations, designs, and technical escalations, ensuring adherence to Zero Trust principles, Client Delivery & Cyber frameworks, and the architectural governance process.

Key Responsibilities

1. Programme-Level Identity Architecture Leadership

  • •Serve as the lead architect for all identity capabilities: IGA, directories (AD/OT AD/Entra ID), RBAC/ABAC, Conditional Access, PKI, CIEM, machine identity, identity lifecycle automation.
  • •Own the architectural strategy and roadmap for the Identity Pillar across Year 1 (I&D) and influence Year 2 planning.
  • •Act as the single technical authority across all identity workstreams, ensuring coherence, interoperability, and alignment with Zero Trust Identity outcomes.
  • •Lead technical governance engagement: Information Security TAG, PESA approvals, Design Authority reviews, and cross pillar integration sessions.

2. Initiate & Discovery Responsibilities (Identity Specific)

  • •Lead comprehensive DAAS discovery for identity components:
    • oidentity stores and directories
    • oAD forests/domains and OT AD footprint
    • oapplication identity models
    • oentitlements, access patterns, privileged roles
    • oIGA process and connector readiness
    • onon human / service identities
  • •Conduct identity specific discovery across:
    • oJML processes, access request flows, attestation cycles
    • odirectory security posture (CIS benchmarks, Microsoft best practices)
  • •Evaluate and document:
    • oidentity risks
    • oidentity lifecycle issues
    • ounmanaged accounts
    • oaccess policy gaps
    • odiscovery logs
    • otechnical constraints
    • odiscovery outputs traceable to future designs

3. Identity Architecture Design Responsibilities

  • •Produce HL/ML/LLD for the IGA platform (SailPoint/Saviynt/etc.).
    • oaccess request & approval workflows
    • oentitlements management
    • orole mining & identity analytics
  • •Define integration patterns with:
    • oServiceNow
    • oSIEM for identity related detections
    • oPAM/PIM for privileged identities

Directory Services & Identity Core

  • •Produce architecture for AD, Entra ID, and OT AD identity capabilities:
    • osecure configuration baselines
    • onaming conventions, OU design, GPO strategy
    • oidentity lifecycle & sync patterns
    • odirectory-tiering strategy (Tier 0)
    • RBAC / ABAC

Conditional Access & Authentication

  • •Architect conditional access policies (CA rules, sign in risk, device trust, session controls).
  • •Define MFA strategy: Authenticator App, FIDO2, passwordless, biometrics.
  • •Define Zero Trust authentication patterns for:
    • oprivileged identities
    • othird parties
    • oOT identities where applicable

PKI & Certificate Lifecycle

  • •Produce architecture for PKI, certificate issuance, renewal, and lifecycle governance.
  • •Define trust anchors and certificate policies for:
    • odevice identities
    • oOT and cloud workloads
  • •Define cloud identity entitlement patterns (Azure/AWS).
  • •Establish least privilege, JIT/JEA patterns for cloud workloads.

4. Implementation Responsibilities (Identity-Focused)

  • •Provide hands on architectural oversight to ensure implementations follow approved designs.
  • •Oversee rollout and validation of:
    • oIGA connectors, workflows, lifecycle processes
    • oAD/Entra ID configuration updates and hardening
    • oConditional access/MFA/policy rollout
    • oRBAC role deployment and attestation setup
    • oPKI enhancements, CA templates, certificate workflows
    • oCIEM configuration and governance
  • •Guide identity engineers and application onboarding teams through technical sequencing, integration steps, and issue resolution.
  • •Validate end to end identity flows (authentication, provisioning, deprovisioning, attestation).

5. Identity Governance, Compliance & Risk

  • •Ensure all identity designs align with:
    • oZero Trust Identity requirements
    • oCAF/eCAF outcomes
    • oregulatory and compliance frameworks (GDPR, NIS R, PCI DSS)
    • oprivileged identity control
    • oaccess attestation
    • opolicy exceptions
  • •Support the audit and compliance teams with identity reporting, evidence, and control design.

6. Stakeholder & Technical Leadership

  • •Act as the single point of contact for all identity related technical matters across the programme.
  • •Lead communication with:
    • oHR, IT Ops, Security Operations
    • oApplication teams
    • oOT Identity & OT Engineering teams
  • •Conduct design walkthroughs, knowledge handovers, and training sessions for BAU teams.
  • •Resolve identity related escalations, engineering blockers, and architecture decision disputes.

Skills & Experience Requirements (Identity Scope)

Technical Expertise

  • •12+ years in Identity & Access Management architecture.
  • oIGA (SailPoint/Saviynt), RBAC/ABAC
  • oConditional Access & MFA
  • oPKI & Certificate Lifecycle
  • oCIEM, cloud identity & Zero Trust identity patterns
  • •Extensive experience designing and integrating identity capabilities across hybrid (IT/OT) landscapes.

Delivery & Architecture

  • •Proven experience delivering large-scale IAM transformations end to end.
  • •Strong architectural documentation and governance skills.
  • •Ability to lead multi vendor and multi platform identity delivery teams.

Behavioural

  • •Executive-level communication and architectural leadership.
  • •Operates confidently across strategic, detailed technical, and operational domains.
  • •Structured, methodical, collaborative, and outcome driven.

Requirements (Functional & Non Functional)

  • •High/Mid/Low-Level Identity Designs
  • •Directory Services Architecture Pack
  • •Conditional Access & MFA Design Pack
  • •Identity Implementation Playbooks
  • •Technical submissions for TAG/PESA/Design Authority

#J-18808-Ljbffr

Senior IDAM Architect – Identity Pillar in Coventry employer: Zohorecruit

Join Technical Resource Solutions Ltd, a leading engineering company located in the vibrant City of Westminster, where you will enjoy long-term job stability and a dynamic work environment. As a Commercial Administrator, you will be recognised for your contributions within a supportive team that values hard work and attention to detail, while also offering opportunities for professional growth in a bustling city known for its rich culture and connectivity.

Z

Contact Details:

Zohorecruit Recruitment Team