Architect
Blip is a leading tech company focused on software engineering solutions for sports entertainment. We operate at scale as part of Flutter Entertainment, playing an essential role in the Group’s goal of becoming the global leader in online sports betting and iGaming, developing innovative products and platforms for over 14 million monthly customers worldwide. We are serious about tech, strive to deliver best technological products, and foster a people‑first mindset. We empower each individual’s strengths and unique perspectives, shaping a culture of belonging we are proud of.
Role
Flutter Global Cyber team is seeking an IAM Security Solutions Architect to contribute to the design, development, and implementation of IAM capabilities across the Flutter ecosystem. The role involves working with brand security and engineering teams, workplace technology, vendor technical account managers, and technical consultancies to support the delivery of the strategy.
What You’ll Be Doing
- Support the IAM architectural roadmap, working with security and enterprise architecture to maintain alignment with broader enterprise security and technology strategies.
- Design end‑to‑end IAM solutions covering identity governance and administration (IGA), privileged access management (PAM) and access management.
- Establish and maintain architecture patterns, standards, and reference designs for IAM across cloud, hybrid, and on‑premises environments.
- Architect and oversee implementation of authentication protocols including OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and FIDO2/WebAuthn.
- Drive adoption of multi‑factor authentication (MFA), single sign‑on (SSO), and password‑less authentication capabilities, extending conditional access implementation.
- Collaborate with peer functions such as Workplace Technology, Enterprise Architecture, and Security Architecture as required.
- Ensure IAM solutions comply with regulatory and control frameworks such as GDPR, SOX, PCI‑DSS, NIST, and ISO 27001.
- Support analysis and delivery of RBAC, ABAC, and entitlement management frameworks.
- Support audit and assurance activities, producing architectural documentation and evidence as required.
- Act as SME for IAM solutions, advising stakeholders and product teams on identity‑related risks, capabilities, and mitigations.
- Prioritise user experience in delivery of IAM services.
- Evaluate and support recommendations for IAM vendor solutions and tooling, contributing to procurement and commercial decisions.
- Coach or mentor junior colleagues to further IAM within Flutter.
What You’ll Bring
- Understanding of federation protocols: SAML 2.0, OAuth 2.0, OIDC, SCIM, LDAP, Kerberos.
- Strong understanding of zero‑trust network access (ZTNA) and its application to identity architectures.
- Experience designing IAM solutions across multi‑cloud environments (AWS, Azure, GCP).
- Understanding of API security patterns, including OAuth token management and API gateway integration.
- Familiarity with IaC tooling (e.g., Terraform, Ansible) as applied to identity configuration.
- Knowledge of PKI, certificate lifecycle management, and secrets management best practices.
- Architecture experience – ideally with a recognised framework such as TOGAF, SABSA, or Zachman.
- Demonstrable experience in large‑scale enterprise environments with diverse technology stacks.
- Strong understanding of cloud‑native architecture patterns, microservices, and containerisation (Kubernetes, Docker).
Essential
- Degree in Computer Science, Information Security, or a related discipline – or equivalent demonstrable experience.
- 7+ years in identity and access management or information security roles, with at least 3 years in an architectural or engineering capacity.
Desirable
- Relevant professional certifications such as CISSP, TOGAF.
- Experience in regulated industries (financial services, gaming, healthcare).
Behaviours & Competencies
- Strategic thinking – ability to connect IAM decisions to broader business and security outcomes.
- Communication – clear conveyance of complex technical concepts to technical and non‑technical audiences.
- Ownership – accountability for architectural decisions and their outcomes.
- Collaboration – effective working relationships across security, engineering, product, and compliance teams.
- Continuous learning – curiosity to remain current within the evolving identity governance and threat landscape.
Equal opportunities
At Blip, we are committed to creating a diverse and inclusive workplace. We strongly encourage people from all backgrounds, ways of thinking, and working styles to apply. We are committed to including everyone regardless of race, disability, age, gender identity, sexual orientation, religion, and more. You do not have to meet all the listed requirements to apply. If you need adjustments to apply or to ensure the role aligns with your needs, please contact accommodations@blip.pt. We will only respond to inquiries related to disabilities.