Job Search and Career Advice Platform

Enable job alerts via email!

Security Architect - Zero Trust & Access Controls

Hargreaves Lansdown plc

United Kingdom

Hybrid

GBP 70,000 - 100,000

Full time

3 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services organization in the UK is seeking an experienced Security Architect to enhance IAM security and promote security-by-design principles. The successful candidate will lead IAM frameworks and mentor teams, ensuring the security of customer interactions. The role is full-time, offers a hybrid working pattern, and includes perks such as a discretionary bonus and flexible working options. Candidates must have a strong background in security architecture and IAM, especially in cloud environments.

Benefits

Discretionary annual bonus
25 days holiday plus bank holidays
Flexible working options
Enhanced parental leave
Private medical insurance
Health care cash plans
In-house barista and deli

Qualifications

  • Extensive experience in security architecture within Financial Services.
  • Proven experience implementing IAM solutions.
  • Strong knowledge of cloud security architecture.
  • Familiar with modern authentication protocols.

Responsibilities

  • Lead development of enterprise IAM frameworks.
  • Drive zero-trust architecture adoption.
  • Design IAM architectures for various environments.
  • Participate in security governance forums.

Skills

Security Architecture
Identity and Access Management (IAM)
Cloud Security
Stakeholder Management

Education

Bachelor's degree in computer science or related field

Tools

Ping Identity
AWS
Azure
Job description

Excited to grow your career?

Our purpose is to make it easy for people to save and invest for a better future. We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown.

We know that sometimes people can be put off applying for a job if they don't tick every box. If you're excited about working for us and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you!

About the role

We are seeking an experienced Security Architect - Zero Trust & Access Controls to join our rapidly evolving financial services organisation. This role will be instrumental in shaping and securing our digital future as we undergo significant transformation across our technology landscape. The position will focus primarily on securing customer interactions and fraud prevention while championing security-by-design principles across our product development lifecycle. You will be required to have a strategic input into enterprise IAM security architecture, with a direct influence on the security posture of our customer-facing services. Additionally, you will provide mentorship and guidance to our security architects, product security specialists and product development teams.

What you'll be doing
Strategic Leadership
  • Lead the development and evolution of enterprise IAM frameworks and patterns for customer-facing (Client) and workforce (Colleague) identity solutions across on-premises, colocation, SaaS, AWS, and Azure environments.
  • Drive zero-trust architecture adoption and security-by-design principles across all product development and engineering initiatives.
  • Provide thought leadership in cloud IAM, federated identity, privileged access management, and identity governance for hybrid multi-cloud environments.
Architecture & Design
  • Design and oversee robust IAM architectures spanning:
    • On-premises: Active Directory, AD FS, RADIUS/LDAP integrations.
    • Colocation: Hybrid identity sync, network-level authentication.
    • SaaS: Okta, Ping Identity, Auth0, Azure AD B2C.
    • AWS: IAM, Identity Center, Organizations, Cognito, Secrets Manager.
    • Azure: Entra ID, Conditional Access, PIM, Key Vault, Managed Identities.
  • Develop reference architectures for OAuth 2.0, OIDC, SAML 2.0, FIDO2/WebAuthn, and passwordless authentication flows.
  • Review and approve identity designs for critical systems including API security, service-to-service authentication, and customer authentication journeys.
  • Establish controls for identity lifecycle, access governance, JIT/JEA access, and privileged account management.
Digital Transformation
  • Align IAM architecture with agile delivery, DevSecOps practices, and infrastructure-as-code approaches.
  • Design identity controls enabling risk-based authentication, adaptive MFA, and continuous authorisation.
  • Develop migration strategies from legacy IAM systems to modern cloud-native platforms.
  • Governance & Risk Management.
  • Participate in security governance forums, design authority and architecture review boards.
  • Conduct IAM assessments, access reviews, segregation of duties analysis, and privilege escalation risk reviews.
  • Ensure regulatory compliance (GDPR, PSD2, DORA) through identity controls and access certification.
About you
  • Extensive experience in security architecture with deep IAM, preferably within the Financial Services Industry.
  • Proven experience in designing and implementing IAM solutions.
  • Deep understanding of cloud security architecture and control (AWS, Azure).
  • Experience with modern authentication protocols (OAuth 2.0, OIDC, SAML) and fraud prevention technologies.
  • Extensive knowledge and expertise on securing mobile apps, API transactions and system integrations with optimal combination of security capabilities.
  • Knowledge of application cryptography, PKI infrastructure and use of mobile TEE.
  • Strong communication and stakeholder management skills, with the ability to translate complex technical concepts for non-technical audiences.
  • Able to work under pressure in a fast paced, transformation-focused environment.
  • Bachelor's degree in computer science, Information Security, or related field.
Relevant certifications (highly desirable)
  • Certified Professional - Ping*.
  • CyberArk Sentry - Any.
  • Certified Identity and Access Manager (CIAM).
  • AWS Certified Security Specialty.
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900).
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300).
Interview process

This will be a 2-stage interview process, consisting of an intro call, competency and behavioural based interview with technical assessment.

Working Schedule

We are based in Bristol, BS1 5HL. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We have returned to the office, however for this role we offer a hybrid flexible working pattern to enable you the option of working from home.

Why us?

Here at HL, we're the UK's number 1 investment platform for private investors, based in Bristol. For more than 40 years we've helped investors save time, tax and money on their investments.

To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We're steered by core values that promote service, quality, innovation, and opportunity in everything we do.

What's on offer?
  • Discretionary annual bonus* and annual pay review
  • 25 days* holiday plus bank holidays and 1-day additional Christmas closure
  • Option to purchase an additional 5 days holiday**
  • Flexible working options available, including hybrid working
  • Enhanced parental leave
  • Pension scheme up to 11% employer contribution
  • Income Protection and Life insurance (4 x salary core level of cover)
  • Private medical insurance*
  • Health care cash plans - including optical, dental, and outpatient care
  • Health screening programme
  • Help@hand - confidential support including mental health counselling and remote GP
  • Wellhub - unlimited access to fitness providers and wellness coach sessions
  • Variety of travel to work schemes with bike storage and shower facilities
  • Inhouse barista and deli serving subsidised coffee and sandwiches
  • Two paid volunteering days per year

* dependant on role level

** only available to select during our annual benefits window, in November each year

Hargreaves Lansdown is an inclusive employer that values diversity in its workforce. We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age.

This role may also be available on a flexible working or part time basis - please ask the Recruitment & Onboarding team for more information.

Please note, we are unable to provide employment sponsorship to candidates.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.