> Markdown version of [/jobs/ext/1431676-security-architect](https://www.wearedevelopers.com/jobs/ext/1431676-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** ISR Recruitment - **Location:** Manchester, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cloud Computing, Cyber Security, Data Security, Data Sharing, Distributed Systems, Federated Identity Management, Identity and Access Management, OAuth, Openid Connect, Zero Trust Network Access, Security Assertion Markup Language (SAML), Policy as Code, Legacy Systems - **Published:** July 25, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/41930388/ ## About the Role Skills and Experience:Proven security architecture experience on complex federated enterprise solutions.Strong knowledge of federated identity, trust frameworks (e.g. Zero Trust) and IAM.Strong understanding of cloud, API and distributed system security.Practical experience with OAuth2, OpenID Connect, SAML and SCIM.Practical experience designing ABAC and policy-based access control solutions.Practical experience with Open Policy Agent and policy-as-code solutions at scale.Practical experience HMG security assurance (e.g. NCSC Cyber Assessment Framework).Ability to produce high-quality architecture and security design documentation.Ability to translate complex security concepts for technical and non-technical audiences.Comfortable working with ambiguity and shaping emerging requirements. DesirableExperience with federated data-sharing platforms or data ecosystems.Ontologies, semantic data models or knowledge graphs.Public sector, regulated industry, critical infrastructure or federated ecosystem solutions. Role and Responsibilities:Design security Non-Functional Requirements.Lead on service wide threat modelling.Define and implement ABAC and policy-as-code approaches using Open Policy Agent.Define patterns for discovery, access requests, policy enforcement and auditability.Design integration with identity providers, IAM platforms and node-level services.Support testing, validation and pilot activities to ensure consistent policy enforcement. ## Description The Opportunity: We are seeking an experienced Security Architect (Identity and Access Management Specialist) to support the delivery of a secure, scalable and interoperable data-sharing infrastructure that allows organisations in different sectors to manage and exchange information securely while maintaining control over their own data. Working across multiple workstreams, you will be responsible for leading the design of security, identity and policy enforcement capabilities, focusing on federated identity, Attribute-Based Access Control (ABAC), policy-as-code and secure data discovery and access. You will be working closely with architects, governance leads, developers and stakeholders, that will see you translate business, risk and policy requirements into secure, scalable and practical technical solutions. This role is supporting a major public-sector organisation delivering a large-scale digital transformation programme - replacing legacy systems with a modern, integrated solution that will significantly enhance operational capability across critical services. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Smart City, Smart Mobility](https://www.wearedevelopers.com/videos/954-smart-city-smart-mobility) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)