Service Architect

Infinity Quest
UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£52,779.0
Working hours
Regular working hours

Tech stack

Microsoft Access Access Network Application Integration Architecture Cyber Security Databases Identity and Access Management Networking Hardware Key Management Metadata Service-Oriented Architecture Service Design Data Streaming

Job description

We are looking for a Senior or Lead Service Architect to design the enterprise service model for infrastructure access, including privileged access.

The role defines how users, identities, applications, servers, databases, cloud platforms, network devices, approval routes, risk controls, data sources, and support teams work together.

This is not a PAM tooling role. It is a service architecture role across identity, privileged access, infrastructure, cyber security, risk, audit, service management, and engineering.

The organisation needs to replace fragmented access processes, manual approvals, local exceptions, and tool-specific designs with one risk-based access service. That service must use identity, application, and infrastructure data to decide how access is requested, approved, granted, monitored, reviewed, and removed.

Role purpose

The Service Architect will design the target service for privileged access, server access, cloud administration, database administration, network access, emergency access, third-party access, break-glass access, and just-in-time access. The role defines the service blueprint, access patterns, process flows, approval paths, team responsibilities, metadata, control points, integrations, operating model, and transition roadmap.

Key responsibilities

Design the end-to-end service architecture for infrastructure access and privileged access.

Define the target service model, including processes, roles, controls, data flows, integrations, and operational hand-offs.

Create a risk-based access model that sets the access pattern, approval route, monitoring level, and review frequency.

Define patterns for standing access, time-bound access, just-in-time access, emergency access, third-party access, cloud access, and privileged administration.

Define how identity, application, infrastructure, entitlement, account, risk, and control data are used in access decisions.

Identify trusted data sources, data owners, data quality rules, and exception handling.

Design controls for least privilege, authorised access, traceability, monitoring, timely removal, access reviews, and audit evidence.

Define how evidence is produced through workflows, logs, approvals, access records, and session records.

Identify current-state gaps and define steps to move to the target service.

Work with IAM, PAM, infrastructure, cloud, application, cyber security, risk, audit, service management, and engineering teams.

Challenge access processes that are inconsistent, too manual, poorly owned, or designed around individual tools.

Key deliverables

The role will produce:

Service blueprint and privileged access service model

Access pattern catalogue and risk-based decision model

Process maps, RACI, and ownership model

Metadata, data, control, and evidence models

Integration architecture and operating model

Exception, break-glass, and onboarding designs

Reporting requirements and transition roadmap

Requirements

Candidates should have experience in several of the following areas:

Service architecture or service design in a large organisation.

IAM, PAM, infrastructure access, or security architecture.

Designing services across people, process, technology, data, and controls.

Risk-based access models and control design.

Infrastructure platforms, including servers, databases, cloud platforms, network devices, containers, and administrative tooling.

Using data from identity systems, application inventories, CMDBs, infrastructure inventories, entitlement stores, or control platforms.

Designing access request, approval, fulfilment, monitoring, review, revocation, and exception processes.

Working in regulated, audited, or control-heavy environments.

Experience with cloud IAM, secrets management, zero standing privilege, just-in-time access, attribute-based access control, service accounts, non-human identities, security monitoring, session recording, or financial services would be useful.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:13 min

Understanding engineering career opportunities within enterprise consulting structures

Thomas Hartenstein · LIVE

1:47 min

Comparing Egeria to alternative open metadata solutions

Ferd Scheepers · World Congress 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

9:33 min

Limiting script execution permissions in Node and package managers

Chris Heilmann +2 · LIVE

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

2:08 min

Creating standard APIs via the Egeria open metadata project

Ferd Scheepers · World Congress 2022

Videos

See all

Related articles

See all