Identity Security Architect

Circle Group Ltd
London, UK
17 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Compensation
£117,000.0 - £143,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Active Directory User Authentication Microsoft Azure Cyber Security Identity and Access Management Kerberos (Protocol) Microsoft Security Essentials OAuth Role-Based Access Control Openid Connect
+6 more
Azure Active Directory Phishing Zero Trust Network Access Security Assertion Markup Language (SAML) Enterprise Software Applications Microsoft InTune

Job description

  • Define and deliver enterprise Identity & Access Management (IAM) architecture, primarily leveraging Microsoft Entra ID across cloud, hybrid and on-premises environments.
  • Design secure authentication, authorisation and identity governance solutions for users, administrators, applications, workloads and external identities.
  • Develop identity roadmaps, architecture standards, security patterns and technical governance frameworks.
  • Architect and optimise Microsoft Entra capabilities including Conditional Access, ID Protection, PIM, Identity Governance, External ID, Access Reviews, Entitlement Management and Hybrid Identity solutions.
  • Design hybrid identity integrations between Active Directory and Microsoft Entra ID, including strategies for passwordless and phishing-resistant authentication (FIDO2, Windows Hello for Business, Microsoft Authenticator and certificate-based authentication).
  • Implement Zero Trust identity architectures, enforcing least privilege, risk-based access controls and secure administrative access models.
  • Define privileged access strategies using Entra PIM, RBAC/ABAC, Just-in-Time (JIT) access and privileged account governance.
  • Lead identity governance initiatives, including Joiner-Mover-Leaver (JML) processes, access certification, lifecycle automation and management of guest/external identities.
  • Provide architectural guidance for application and workload identities, including OAuth 2.0, OpenID Connect, SAML, Enterprise Applications, App Registrations, Managed Identities and Service Principals.
  • Establish governance for application permissions, secrets, certificates and workload credentials, reducing reliance on long-lived credentials.
  • Ensure identity services integrate effectively with the wider Microsoft security ecosystem, including Defender, Sentinel, Intune, Purview and Azure security services.
  • Conduct identity assessments, identify security and operational improvements, and mitigate risks related to privileged access, credential exposure and legacy authentication.
  • Lead stakeholder workshops, translate business and security requirements into technical solutions, and produce architecture documentation, standards and migration roadmaps.
  • Provide technical leadership, design assurance and governance support throughout project delivery, implementation and solution lifecycle.

Requirements

  • Significant experience designing enterprise Identity and Access Management solutions.
  • Strong architecture-level expertise with Microsoft Entra ID and Microsoft identity technologies.
  • Strong understanding of Active Directory and hybrid identity architectures.
  • Demonstrable experience designing Conditional Access strategies at enterprise scale.
  • Strong knowledge of privileged access management and Microsoft Entra PIM.
  • Experience with identity governance, lifecycle management and access certification.
  • Strong understanding of modern authentication and federation protocols including OAuth 2.0, OpenID Connect, SAML and Kerberos.
  • Experience designing passwordless and phishing-resistant authentication solutions.
  • Strong understanding of Microsoft 365 and Azure security architecture.
  • Experience designing identity controls as part of a Zero Trust security architecture.
  • Ability to assess identity security posture and translate findings into prioritised remediation programmes.
  • Experience operating in complex enterprise environments with multiple business units, applications and stakeholder groups.

Benefits & conditions

The role can be offered as either a day rate contract between c£450-£550 per day inside IR35 on an umbrella solution or as a fixed term contract with a salary of £80-90k.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all