IT & Software

Solution Architect – Identity & Access Management (IAM)

Shivom Consultancy Ltd.

London · England · United Kingdom

LONDON (M-25), United Kingdom – £75k to £90k per annum, depending on experience

Permanent

Other Info

Start Date ASAP

Security Clearance Yes

Categories Executive | Public Sector

Telephone

Visa Requirement Applicants must be eligible to work in the specified location

Identity & Access Management (IAM) Solution Architect

Salary: £ 75,000 to £90,000 per annum, depending on experience

Security Clearance: Applicants must either hold current Security Check (SC) clearance or be eligible to obtain SC clearance. Candidates without existing clearance must be willing to complete the required security vetting process as a condition of appointment.

About the role

Shivom Consultancy is looking for an experienced Identity & Access Management (IAM) Solution Architect to join our growing architecture practice.

You will provide architecture leadership across enterprise identity, authentication, authorisation and access management services, helping organisations deliver secure and consistent identity capabilities for employees, external users, customers, partners, applications and services.

The role requires strong knowledge of modern identity architecture, particularly Microsoft Entra ID and ForgeRock, together with practical experience of federation, Single Sign On, Multi Factor Authentication, identity lifecycle management, privileged access, service identities and modern authentication protocols.

You will help organisations rationalise fragmented identity services, define target and transition architectures and establish reusable identity patterns that can be adopted consistently across multiple products and platforms.

You will work closely with enterprise architects, cyber security teams, cloud and platform teams, solution architects, application teams, engineers, service management and technology suppliers.

This role will support major UK public sector and enterprise transformation programmes within Shivom’s client portfolio.

What you will be doing

You will:

  • Lead solution architecture across enterprise Identity and Access Management capabilities.
  • Define current, target and transition architectures for authentication, authorisation and identity services.
  • Architect identity services supporting workforce, external users, customers, partners and machine identities.
  • Define architecture for Microsoft Entra ID and ForgeRock based identity services.
  • Develop reusable authentication and authorisation patterns for applications and digital services.
  • Design Single Sign On and federation solutions across cloud, SaaS, COTS and bespoke applications.
  • Define Multi Factor Authentication and Conditional Access architectures.
  • Architect identity lifecycle management covering joiners, movers and leavers.
  • Define Role Based Access Control and Attribute Based Access Control patterns.
  • Design identity governance and access review capabilities.
  • Define approaches for privileged access and administrative identities.
  • Architect application, workload and service identity patterns.
  • Design secure integration between identity platforms and enterprise applications.
  • Define authentication and authorisation patterns for APIs and distributed services.
  • Support consolidation and rationalisation of multiple identity platforms.
  • Assess Legacy identity services and define pragmatic migration approaches.
  • Develop solution visions, High Level Designs, options assessments and architecture roadmaps.
  • Define non functional requirements covering availability, resilience, security, performance, scalability, disaster recovery and supportability.
  • Work with cyber security teams to ensure identity architectures support Zero Trust and least privilege principles.
  • Work with engineering and delivery teams throughout discovery, design, implementation and transition into live service.
  • Review detailed technical designs and implementation approaches against agreed architecture.
  • Identify architecture risks, dependencies and technical debt.
  • Prepare and present architecture decisions through technical governance and design authority forums.
  • Support proofs of concept and technology evaluations where appropriate.
  • Define monitoring, audit and operational requirements for identity services.
  • Promote repeatable engineering through automation, CI/CD and Infrastructure as Code where appropriate.
  • Contribute to architecture peer reviews and continuous improvement across Shivom’s architecture practice.

Essential experience and skills

We are looking for strong experience across most of the following:

  • Significant experience working as an IAM Architect, Security Architect, Solution Architect or Technical Architect within complex enterprise environments.
  • Strong architecture experience with enterprise Identity and Access Management.
  • Strong practical knowledge of Microsoft Entra ID .
  • Experience architecting modern authentication and authorisation services.
  • Strong understanding of Single Sign On and identity federation.
  • Experience with OAuth 2.0, OpenID Connect and SAML.
  • Experience with Conditional Access and risk based access controls.
  • Strong understanding of identity lifecycle management.
  • Experience designing joiner, mover and leaver processes.
  • Experience with identity governance and access reviews.
  • Strong understanding of Role Based Access Control.
  • Understanding of Attribute Based Access Control and policy based authorisation.
  • Experience architecting privileged access controls.
  • Understanding of application, workload and service identities.
  • Experience integrating identity platforms with cloud, SaaS, COTS and bespoke applications.
  • Experience supporting both internal and external identity populations.
  • Experience defining secure authentication patterns for APIs and digital services.
  • Strong understanding of Zero Trust and least privilege principles.
  • Experience defining resilient, highly available identity services.
  • Experience producing architecture artefacts including HLDs, options assessments, roadmaps, identity flows and technical decisions.
  • Experience modernising or consolidating Legacy identity estates.
  • Experience working within technical governance, security assurance or design authority processes.
  • Experience working across multiple product teams and technology suppliers.
  • Strong stakeholder management and communication skills.
  • Ability to communicate complex security and identity concepts to technical and non technical audiences.
  • Ability to make pragmatic architecture decisions that balance security, user experience, operational needs and delivery constraints.

Strong Microsoft Entra ID experience is important for this role.

You should understand areas including:

  • Enterprise applications
  • App registrations
  • Managed identities
  • Single Sign On
  • Conditional Access
  • Identity Protection
  • External identities
  • Role Based Access Control
  • Privileged Identity Management
  • Access reviews
  • Entitlement management
  • Identity governance
  • Groups and administrative units
  • Passwordless authentication
  • Application consent
  • Workload identities
  • Audit and sign in logs
  • Hybrid identity

You should be able to treat identity as an enterprise platform capability, rather than configure individual applications in isolation.

ForgeRock and customer identityExperience with ForgeRock would be particularly valuable.

Relevant experience may include:

  • ForgeRock Access Management
  • ForgeRock Identity Management
  • ForgeRock Directory Services
  • ForgeRock Identity Gateway
  • Authentication journeys and trees
  • OAuth 2.0 and OpenID Connect
  • User registration
  • Account recovery
  • Credential management
  • Customer and citizen identity
  • External user identity
  • Identity lifecycle
  • Authentication policies
  • Session management
  • Identity integration

Candidates with comparable large scale Customer Identity and Access Management experience may also be considered where they can demonstrate strong transferable architecture knowledge.

Authentication and federationYou should have strong understanding across:

  • OAuth 2.0
  • OpenID Connect
  • SAML 2.0
  • JWT
  • Client credentials
  • PKCE
  • Token lifetime and refresh
  • Single Sign On
  • Passwordless authentication
  • Step up authentication
  • Risk based authentication
  • Session management

You should understand how to select appropriate identity patterns for web applications, APIs, mobile applications, SaaS services and machine to machine integration.

Identity governance and lifecycleIdentity architecture extends beyond login.You should be comfortable designing capabilities covering:

  • Joiners, movers and leavers
  • Identity provisioning
  • Role assignment
  • Group management
  • Entitlement management
  • Access requests
  • Approvals
  • Periodic access reviews
  • Segregation of duties
  • Orphaned account management
  • Privileged account lifecycle
  • Audit and evidence

You should understand how identity governance integrates with HR systems, directories, applications and operational processes.Privileged access and Zero TrustExperience or strong architectural knowledge across the following would be beneficial:

  • Privileged Identity Management
  • Privileged Access Management
  • Just in Time access
  • Just Enough Administration
  • Break glass accounts
  • Least privilege
  • Conditional Access
  • Device trust
  • Risk based access
  • Network and identity context
  • Zero Trust architecture

Identity should form a core control plane for enterprise security rather than being treated as a standalone authentication service.Application and workload identityModern platforms increasingly depend on non human identities.You should understand:

  • Managed identities
  • Workload identities
  • Application identities
  • Service accounts
  • Machine to machine authentication
  • Client credentials
  • Certificate based authentication
  • Secrets management
  • Credential rotation
  • Least privilege for workloads

Technology experienceCandidates do not need deep expertise in every technology listed below.We are looking for strong IAM architecture capability combined with sufficient breadth across Azure, security, application integration and engineering.Identity platforms and technologiesExperience with several of the following would be beneficial:

  • ForgeRock
  • Active Directory
  • Microsoft Entra External ID
  • Privileged Identity Management
  • Identity Governance
  • OAuth 2.0
  • OpenID Connect
  • SAML
  • LDAP
  • JWT
  • PKI and certificates

Microsoft AzureExperience across several of the following would be useful:

  • Azure applications and service principals
  • Managed identities
  • Application Insights

Engineering and automationExperience or architectural understanding of:

  • GitHub
  • CI/CD
  • Infrastructure as Code
  • Terraform
  • Bicep
  • Identity configuration as code
  • Automated deployment
  • Automated provisioning
  • API driven identity management
  • Source control

You do not need to be a DevOps engineer, but should understand how identity platform configuration can be deployed, controlled and audited through repeatable engineering practices.

Monitoring, audit and observabilityIdentity services are security critical and should be observable by design.Experience with areas such as the following would be advantageous:

  • Entra sign in and audit logs
  • Identity Protection
  • Application Insights
  • Dynatrace
  • Grafana
  • SIEM integration
  • Privileged access monitoring
  • Failed authentication monitoring
  • Audit trails
  • Correlation and investigation

You should understand the importance of identity telemetry for both operational support and cyber security monitoring.

Identity modernisationA key part of the role is being able to rationalise and modernise complex identity estates.You should be comfortable assessing:

  • Multiple identity providers
  • Legacy directories
  • Application specific identity stores
  • Local user accounts
  • Legacy federation
  • Workforce identity
  • Partner identity
  • Service and workload identities

You should be able to define transition architectures that progressively simplify identity services without creating unacceptable migration or operational risk.

At Shivom, we place strong emphasis on:

  • Identity as a strategic enterprise capability
  • Least privilege
  • Reusable authentication and authorisation patterns
  • Strong identity governance
  • Secure customer and external identity
  • Simplification and convergence
  • Modernisation of Legacy identity services
  • Secure by design architecture
  • Resilience and operational readiness
  • Automation and repeatability
  • Auditability and traceability
  • Engineering aligned architecture
  • Sustainable technology choices
  • Effective collaboration across multiple suppliers and delivery teams

Our architects remain close to delivery while maintaining the enterprise perspective needed to avoid fragmented and application specific identity solutions.

Desirable experienceIt would be advantageous to have:

  • Experience designing large scale Customer Identity and Access Management solutions.
  • Experience supporting multiple identity populations including employees, external users, partners and customers.
  • Experience consolidating multiple identity providers.
  • Experience migrating applications from Legacy authentication to modern federation.
  • Experience with Privileged Identity Management or Privileged Access Management.
  • Experience with passwordless authentication.
  • Experience with identity governance and entitlement management.
  • Experience with external identity and B2B collaboration.
  • Experience designing authentication for APIs and microservices.
  • Experience with Infrastructure as Code for identity or security configuration.
  • Experience integrating identity telemetry with SIEM and monitoring platforms.
  • Experience delivering architecture within UK central government, healthcare, financial services, defence, policing or another regulated environment.
  • Experience supporting large scale or business critical digital services.
  • Experience handling sensitive or regulated information.
  • Experience working within complex multi supplier environments.
  • Existing SC security clearance.
  • Microsoft Identity and Access Administrator or Cybersecurity Architect certification.
  • ForgeRock certification.
  • TOGAF or equivalent architecture certification.

Professional certifications are desirable rather than mandatory where equivalent practical experience can be demonstrated.

What success looks like

You will be successful when you can:

  • Understand a complex identity landscape quickly.
  • Define a clear enterprise IAM direction and realistic transition roadmap.
  • Create reusable identity patterns that application teams can adopt easily.
  • Simplify fragmented identity services.
  • Balance strong security with a practical user experience.
  • Design identity services for internal, external and machine identities.
  • Make effective use of Microsoft Entra ID and ForgeRock capabilities.
  • Reduce application specific authentication and access solutions.
  • Build Zero Trust and least privilege principles into architecture.
  • Ensure privileged access receives appropriate protection and governance.
  • Integrate identity cleanly and API, applications and cloud platforms.
  • Build monitoring, auditability and operational support into identity services.
  • Produce architecture that engineering teams can practically implement.
  • Influence multiple delivery teams while maintaining strong working relationships.
  • Make clear recommendations when faced with competing security and architecture options.
  • Build trusted relationships with cyber security teams, engineers, senior stakeholders and fellow architects.

Security requirements

Applicants must either hold current Security Check (SC) clearance or be eligible to obtain SC clearance .Candidates who do not currently hold SC clearance must be willing to complete the required security vetting process as a condition of appointment.The successful candidate will be expected to work in accordance with applicable client and government security policies when undertaking assignments involving sensitive information or systems.

Working arrangements

This is a UK based hybrid role.You should be comfortable working remotely while also attending Shivom offices, client locations and other UK sites where collaboration, delivery activities or security requirements make in person attendance appropriate.The frequency of on site attendance may vary depending on the nature and stage of individual assignments.

BenefitsAt Shivom, we want our people to build long term careers while working on meaningful and technically challenging programmes.

Our benefits package includes:

  • Private medical insurance
  • Critical illness cover
  • Employer pension contribution
  • Generous annual leave entitlement plus UK bank holidays
  • Hybrid and flexible working arrangements, subject to client requirements
  • Support for professional certifications and technical training
  • Continuous professional development opportunities
  • Access to architecture, cloud, security, identity, data and engineering learning opportunities
  • Support for maintaining and progressing professional and security clearances
  • Career progression within Shivom’s architecture and technology leadership practice
  • Opportunities to work on major UK public sector and enterprise transformation programmes
  • Regular knowledge sharing, technical forums and architecture communities of practice
  • Company sponsored social and team events
  • Employee referral opportunities
  • Recognition and performance related reward opportunities

Shivom Consultancy is a UK based technology consultancy specialising in architecture, cloud, data, security, software engineering and digital transformation.We work with organisations delivering complex and business critical technology services, helping them modernise Legacy estates, adopt cloud and digital platforms, strengthen cyber security and build secure, resilient and scalable technology capabilities.Our architecture practice focuses on practical architecture that connects strategy with engineering. We believe architects should remain close to delivery, understand the operational impact of their decisions and help teams make technology choices that remain sustainable beyond the immediate project.You will join a growing architecture community with opportunities to work across identity, cyber security, cloud, APIs, integration, data and digital services.

You will have the opportunity to shape enterprise identity services across complex organisations while developing your career within a growing architecture practice.You will work at the intersection of Microsoft Entra ID, ForgeRock, customer and workforce identity, Zero Trust, API security and cloud architecture, helping organisations move from fragmented identity services towards secure, reusable and sustainable enterprise capabilities.We combine the variety and technical challenge of consultancy with the opportunity to build long term relationships with clients and delivery teams, influence architecture direction and see solutions progress from early design through implementation and live service.

Equal opportunities

Shivom Consultancy is committed to creating an inclusive and supportive working environment.We welcome applications from suitably qualified candidates regardless of age, disability, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sex or sexual orientation.We will make reasonable adjustments throughout the recruitment process where required.

#J-18808-Ljbffr

Reference: WJ-766_22122757

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.