Salary: £38,000 - 68,000 per year
Requirements
- We need a senior technical leader with demonstrable success delivering large-scale IAM transformations across complex, federated environments.
- We need deep understanding of ISO 24760 and Zero Trust Architecture principles, including standard reference architectures and policy-driven, risk-based access decisions.
- We need proven design experience across IGA, AM, PAM, CIAM, and Non-Human Identity frameworks.
- We need hands-on architecture experience with Microsoft Entra ID, AWS Cognito, specialized IGA/PAM engines, and ideally HMG Gov.UK OneLogin.
- We need familiarity with modern authentication protocols and standards including OIDC, SAML, FIDO2, WebAuthn, and SCIM.
- We need understanding of identity assurance levels such as IALs and AALs.
- We need a track record in designing low-disruption transition architectures that retire legacy systems while maintaining security and business continuity.
- We need exceptional stakeholder management skills and the ability to bridge technical teams, security leads, and senior business executives.
Responsibilities
- We will define a coherent enterprise identity architecture aligned to ISO 24760 standards.
- We will ensure strict separation of Identity Authority, Relying Parties, and Verification Services.
- We will evaluate existing service integrations across Zero Trust frameworks, least-privilege principles, and security assurance requirements.
- We will design modern, scalable IAM architectures covering IGA and JML, authentication and access management, PAM, verification and CIAM, and machine and non-human identities.
- We will create end-to-end automated identity lifecycle processes, including policy-driven access, SCIM integration, and data quality assurance.
- We will design adaptive, risk-based access controls, phishing-resistant MFA, passwordless patterns, and session management.
- We will define just-in-time access, segregation of duties, and least-privilege administrative controls for privileged access.
- We will design customer and citizen identity management aligned with HMG verification platforms and GPG45 assurance standards.
- We will establish life cycle governance for service accounts, keys, and certificates.
- We will design secure, standards-based identity integration patterns for federation with associate bodies, suppliers, and third parties.
- We will map a phased migration strategy from legacy services, including replacement of ideiio.
- We will drive a Year 1 focus on core IGA and AM controls and a Year 2 expansion to PAM, CIAM, and full automation.
Technologies
- AWS
- Fabric
- IAM
- SAML
- Security
- Cloud
- Architect
More
We are a major, high-profile public sector and enterprise transformation organization partnering on a landmark identity transformation programme. This is a hybrid UK-based contract role inside IR35, initially for 6 to 9 months with a strategic two-year roadmap. We are building a future-fit, Zero Trust-aligned identity architecture that places identity at the centre of security for networks, devices, applications, and data. This is a high-visibility opportunity to lead the technical vision for greenfield enterprise-wide IAM transformation and help shape a passwordless, scalable identity fabric from the ground up.
last updated 33 week of 2026