> Markdown version of [/jobs/ext/2667679-identity-architect-hybrid-london](https://www.wearedevelopers.com/jobs/ext/2667679-identity-architect-hybrid-london). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Architect - Hybrid London - **Company:** Methods - **Location:** London, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Active Directory, User Authentication, Cloud Computing, Domain Name System (DNS), Identity and Access Management, Name Server, OAuth, Openid Connect, Azure Active Directory, Security Assertion Markup Language (SAML), Service Discovery, Enterprise Application Integration, Technical Debt - **Published:** September 2, 2026 - **Apply:** https://apply.workable.com/methods/j/1AEB475895 ## About the Role * Deep architecture experience with Microsoft Entra ID, Active Directory Domain Services and hybrid identity. * Strong knowledge of Entra Connect or Cloud Sync, authentication methods, federation, MFA and Conditional Access. * Experience of multi-tenant coexistence, tenant/domain migrations and Active Directory consolidation. * Strong DNS, namespace, trusts, GPO, privileged-access and directory-security knowledge. * Understanding of SAML, OpenID Connect, OAuth, SCIM and enterprise application integration. * Ability to produce HLD/LLD artefacts, transition designs, decision records and migration patterns. * Strong security judgement, troubleshooting ability and stakeholder communication. ## Description We are undertaking a significant transformation programme that will reshape the way technology, identity and services are delivered across one of our clients organisation. As part of this programme, we are looking for an experienced Identity & Directory Architect to design the identity and directory foundation that will underpin the transformation. This is a key architecture role with responsibility for establishing a secure, resilient and pragmatic identity model that allows the organisation to operate across its existing technology environments while progressively introducing new target services. You will lead the development of an Entra ID-led identity strategy, working across Microsoft Entra ID, Active Directory, authentication, identity lifecycle, directory services and DNS. You will need to balance the requirements of the existing estate with the ambition of the target architecture, ensuring that the organisation can transition safely without introducing unnecessary operational or security risk. A major part of the role will be designing the coexistence and transition architecture. The organisation cannot simply move from the current environment to the target state overnight, so you will establish the patterns, controls and sequencing required to support a controlled transition. You will also define the longer-term strategy for the Active Directory estate, creating a safe and evidence-based route towards eventual consolidation and simplification. This is an opportunity to take ownership of a critical technology domain within a complex transformation and have a direct influence on the organisation's future identity architecture. What you will do As the Identity & Directory Architect, you will own the technical architecture across the identity and directory domain and provide leadership from initial assessment and design through transition and implementation. You will: * Define the current-state, coexistence, transition and target-state identity architectures, providing a clear roadmap from the existing environment to the future operating model. * Lead the Entra ID architecture, including tenant configuration, identity synchronisation, authentication, federation, domains, administrative boundaries and integration with existing directory services. * Define secure hybrid identity patterns that allow existing applications, infrastructure and services to continue operating while new cloud and target services are introduced. * Design the organisation's identity lifecycle management approach, covering joiner, mover and leaver processes, provisioning, deprovisioning, synchronisation and access governance. * Establish appropriate patterns for authentication and access, including modern authentication, MFA, Conditional Access, federation and application authentication. * Define the approach for external identities, service accounts, non-human identities and other specialist identity requirements. * Design privileged-access controls, including break-glass accounts, delegated administration, administrative boundaries and separation of duties. * Define the future strategy for Active Directory Domain Services, including domains, forests, organisational units, trusts, Group Policy dependencies, legacy authentication and administrative models. * Assess the existing Active Directory estate, identifying technical debt, application dependencies, operational constraints and opportunities for simplification. * Develop a pragmatic and risk-managed roadmap towards future Active Directory consolidation, ensuring consolidation only occurs when the necessary prerequisites and target services are in place. * Own the DNS and namespace architecture, including name resolution, DNS forwarding, service discovery, namespace integration and dependencies between existing and target environments. * Ensure DNS and directory designs support secure and reliable operation across hybrid environments and do not create unnecessary future dependencies. * Define enterprise application integration patterns using technologies and standards ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [The Journey of a Pixel in a React Application](https://www.wearedevelopers.com/videos/1667-the-journey-of-a-pixel-in-a-react-application) - [Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems](https://www.wearedevelopers.com/videos/928-break-the-chain-decentralized-solutions-for-today-s-web2-0-privacy-problems) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)