Identity Architect - Hybrid London

Methods
London, UK
1 day ago
Apply on apply.workable.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Active Directory User Authentication Cloud Computing Domain Name System (DNS) Identity and Access Management Name Server OAuth Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Service Discovery Enterprise Application Integration
+1 more
Technical Debt

Job description

We are undertaking a significant transformation programme that will reshape the way technology, identity and services are delivered across one of our clients organisation. As part of this programme, we are looking for an experienced Identity & Directory Architect to design the identity and directory foundation that will underpin the transformation.

This is a key architecture role with responsibility for establishing a secure, resilient and pragmatic identity model that allows the organisation to operate across its existing technology environments while progressively introducing new target services.

You will lead the development of an Entra ID-led identity strategy, working across Microsoft Entra ID, Active Directory, authentication, identity lifecycle, directory services and DNS. You will need to balance the requirements of the existing estate with the ambition of the target architecture, ensuring that the organisation can transition safely without introducing unnecessary operational or security risk.

A major part of the role will be designing the coexistence and transition architecture. The organisation cannot simply move from the current environment to the target state overnight, so you will establish the patterns, controls and sequencing required to support a controlled transition.

You will also define the longer-term strategy for the Active Directory estate, creating a safe and evidence-based route towards eventual consolidation and simplification.

This is an opportunity to take ownership of a critical technology domain within a complex transformation and have a direct influence on the organisation’s future identity architecture.

What you will do

As the Identity & Directory Architect, you will own the technical architecture across the identity and directory domain and provide leadership from initial assessment and design through transition and implementation.

You will:

  • Define the current-state, coexistence, transition and target-state identity architectures, providing a clear roadmap from the existing environment to the future operating model.
  • Lead the Entra ID architecture, including tenant configuration, identity synchronisation, authentication, federation, domains, administrative boundaries and integration with existing directory services.
  • Define secure hybrid identity patterns that allow existing applications, infrastructure and services to continue operating while new cloud and target services are introduced.
  • Design the organisation’s identity lifecycle management approach, covering joiner, mover and leaver processes, provisioning, deprovisioning, synchronisation and access governance.
  • Establish appropriate patterns for authentication and access, including modern authentication, MFA, Conditional Access, federation and application authentication.
  • Define the approach for external identities, service accounts, non-human identities and other specialist identity requirements.
  • Design privileged-access controls, including break-glass accounts, delegated administration, administrative boundaries and separation of duties.
  • Define the future strategy for Active Directory Domain Services, including domains, forests, organisational units, trusts, Group Policy dependencies, legacy authentication and administrative models.
  • Assess the existing Active Directory estate, identifying technical debt, application dependencies, operational constraints and opportunities for simplification.
  • Develop a pragmatic and risk-managed roadmap towards future Active Directory consolidation, ensuring consolidation only occurs when the necessary prerequisites and target services are in place.
  • Own the DNS and namespace architecture, including name resolution, DNS forwarding, service discovery, namespace integration and dependencies between existing and target environments.
  • Ensure DNS and directory designs support secure and reliable operation across hybrid environments and do not create unnecessary future dependencies.
  • Define enterprise application integration patterns using technologies and standards

Requirements

  • Deep architecture experience with Microsoft Entra ID, Active Directory Domain Services and hybrid identity.

  • Strong knowledge of Entra Connect or Cloud Sync, authentication methods, federation, MFA and Conditional Access.

  • Experience of multi-tenant coexistence, tenant/domain migrations and Active Directory consolidation.

  • Strong DNS, namespace, trusts, GPO, privileged-access and directory-security knowledge.

  • Understanding of SAML, OpenID Connect, OAuth, SCIM and enterprise application integration.

  • Ability to produce HLD/LLD artefacts, transition designs, decision records and migration patterns.

  • Strong security judgement, troubleshooting ability and stakeholder communication.

Benefits & conditions

Methods is passionate about its people; we want our colleagues to develop the things they are good at and enjoy.

By joining us you can expect:

· Autonomy to develop and grow your skills and experience

· Be part of exciting project work that is making a difference in society

· Strong, inspiring, and thought-provoking leadership

· A supportive and collaborative environment

As well as this we offer:

Development - access to LinkedIn Learning, a management development programme, and training

Wellness - 24/7 confidential employee assistance programme

Flexible Working - including home working and part time

Social - office parties, breakfast Tuesdays, monthly pizza Thursdays, Thirsty Thursdays, and commitment to charitable causes

Time Off - 25 days of annual leave a year, plus bank holidays, with the option to buy 5 extra days each year

Volunteering - 2 paid days per year to volunteer in our local communities or within a charity organisation

About the company

Methods is a £100M+ IT Services Consultancy who has partnered with a range of central government departments and agencies to transform the way the public sector operates in the UK. Established over 30 years ago and UK-based, we apply our skills in transformation, delivery, and collaboration from across the Methods Group, to create end-to-end business and technical solutions that are people-centred, safe, and designed for the future.

Our human touch sets us apart from other consultancies, system integrators and software houses - with people, technology, and data at the heart of who we are, we believe in creating value and sustainability through everything we do for our clients, staff, communities, and the planet.

We support our clients in the success of their projects while working collaboratively to share skill sets and solve problems. At Methods we have fun while working hard; we are not afraid of making mistakes and learning from them.

Predominantly focused on the public-sector, Methods is now building a significant private sector client portfolio.

Methods was acquired by the Alten Group in early 2022.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply.workable.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

1:35 min

Translating domain names to server IP addresses

Shem Magnezi Shem Magnezi · World Congress 2025

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all