> Markdown version of [/jobs/ext/3082952-solution-architect-identity-access-management-iam](https://www.wearedevelopers.com/jobs/ext/3082952-solution-architect-identity-access-management-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Solution Architect - Identity & Access Management (IAM) - **Company:** gb Shivom Consultancy Limited - **Location:** London, UK (Remote available) - **Salary:** £75,000.0 - £90,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Application Programming Interfaces (APIs), Application Integration Architecture, Application Performance Management, Audit Trail, User Authentication, Authentication Protocols, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Disaster Recovery, Multi-Factor Authentication, Github, Identity and Access Management, Mobile Application Software, Key Management, Lightweight Directory Access Protocols (LDAP), Log Analysis, OAuth, Public Key Infrastructure, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Security Information and Event Management, Single Sign-On, Software Engineering, Systems Integration, User Provisioning Software, Web Applications, Web Platforms, Enterprise Software Applications, Grafana, Software Security, Technical Debt, Togaf, SC Clearance, HR Software, Infrastructure Automation Frameworks, Deployment Automation, Bicep, Enterprise Integration, Terraform, Software Version Control, Dynatrace, Api Management, User Accounts, Microservices - **Published:** September 26, 2026 - **Apply:** https://www.totaljobs.com/job/international-account-manager/shivom-consultancy-limited-job108043769 ## About the Role * Significant experience working as an IAM Architect, Security Architect, Solution Architect or Technical Architect within complex enterprise environments. * Strong architecture experience with enterprise Identity and Access Management. * Strong practical knowledge of Microsoft Entra ID . * Experience architecting modern authentication and authorisation services. * Strong understanding of Single Sign On and identity federation. * Experience with OAuth 2.0, OpenID Connect and SAML. * Experience designing Multi Factor Authentication. * Experience with Conditional Access and risk based access controls. * Strong understanding of identity lifecycle management. * Experience designing joiner, mover and leaver processes. * Experience with identity governance and access reviews. * Strong understanding of Role Based Access Control. * Understanding of Attribute Based Access Control and policy based authorisation. * Experience architecting privileged access controls. * Understanding of application, workload and service identities. * Experience integrating identity platforms with cloud, SaaS, COTS and bespoke applications. * Experience supporting both internal and external identity populations. * Experience defining secure authentication patterns for APIs and digital services. * Strong understanding of Zero Trust and least privilege principles. * Experience defining resilient, highly available identity services. * Experience producing architecture artefacts including HLDs, options assessments, roadmaps, identity flows and technical decisions. * Experience modernising or consolidating Legacy identity estates. * Experience working within technical governance, security assurance or design authority processes. * Experience working across multiple product teams and technology suppliers. * Strong stakeholder management and communication skills. * Ability to communicate complex security and identity concepts to technical and non technical audiences. * Ability to make pragmatic architecture decisions that balance security, user experience, operational needs and delivery constraints. Microsoft Entra ID Strong Microsoft Entra ID experience is important for this role., You should be able to treat identity as an enterprise platform capability, rather than configure individual applications in isolation. ForgeRock and customer identityExperience with ForgeRock would be particularly valuable. Relevant experience may include: * ForgeRock Access Management * ForgeRock Identity Management * ForgeRock Directory Services * ForgeRock Identity Gateway * Authentication journeys and trees * Federation * OAuth 2.0 and OpenID Connect * User registration * Account recovery * Credential management * Customer and citizen identity * External user identity * Identity lifecycle * Authentication policies * Session management * Identity integration Candidates with comparable large scale Customer Identity and Access Management experience may also be considered where they can demonstrate strong transferable architecture knowledge. Authentication and federationYou should have strong understanding across: * OAuth 2.0 * OpenID Connect * SAML 2.0 * JWT * Client credentials * Authorization Code flow * PKCE * Token validation * Token lifetime and refresh, Technology experienceCandidates do not need deep expertise in every technology listed below.We are looking for strong IAM architecture capability combined with sufficient breadth across Azure, security, application integration and engineering.Identity platforms and technologiesExperience with several of the following would be beneficial: * Microsoft Entra ID * ForgeRock * Active Directory * Entra Connect * Microsoft Entra External ID * Privileged Identity Management * Identity Governance * OAuth 2.0 * OpenID Connect * SAML * LDAP * JWT * PKI and certificates * Azure Key Vault, You should understand the importance of identity telemetry for both operational support and cyber security monitoring.Identity modernisationA key part of the role is being able to rationalise and modernise complex identity estates.You should be comfortable assessing: * Multiple identity providers * Legacy directories * Application specific identity stores * Bespoke authentication * Local user accounts * Legacy federation * Workforce identity * Customer or citizen identity * Partner identity * Service and workload identities You should be able to define transition architectures that progressively simplify identity services without creating unacceptable migration or operational risk. Our architecture approach, * Deep Microsoft Entra ID architecture experience. * Strong ForgeRock architecture experience. * Experience designing large scale Customer Identity and Access Management solutions. * Experience supporting multiple identity populations including employees, external users, partners and customers. * Experience consolidating multiple identity providers. * Experience migrating applications from Legacy authentication to modern federation. * Experience with Privileged Identity Management or Privileged Access Management. * Experience with passwordless authentication. * Experience with identity governance and entitlement management. * Experience with external identity and B2B collaboration. * Experience designing authentication for APIs and microservices. * Experience with Infrastructure as Code for identity or security configuration. * Experience integrating identity telemetry with SIEM and monitoring platforms. * Experience delivering architecture within UK central government, healthcare, financial services, defence, policing or another regulated environment. * Experience supporting large scale or business critical digital services. * Experience handling sensitive or regulated information. * Experience working within complex multi supplier environments. * Existing SC security clearance. * Microsoft Identity and Access Administrator or Cybersecurity Architect certification. * Microsoft Azure architecture certification. * ForgeRock certification. * TOGAF or equivalent architecture certification. Professional certifications are desirable rather than mandatory where equivalent practical experience can be demonstrated. ## Description Shivom Consultancy is looking for an experienced Identity & Access Management (IAM) Solution Architect to join our growing architecture practice. You will provide architecture leadership across enterprise identity, authentication, authorisation and access management services, helping organisations deliver secure and consistent identity capabilities for employees, external users, customers, partners, applications and services. The role requires strong knowledge of modern identity architecture, particularly Microsoft Entra ID and ForgeRock, together with practical experience of federation, Single Sign On, Multi Factor Authentication, identity lifecycle management, privileged access, service identities and modern authentication protocols. You will help organisations rationalise fragmented identity services, define target and transition architectures and establish reusable identity patterns that can be adopted consistently across multiple products and platforms. You will work closely with enterprise architects, cyber security teams, cloud and platform teams, solution architects, application teams, engineers, service management and technology suppliers. This role will support major UK public sector and enterprise transformation programmes within Shivom's client portfolio. What you will be doing You will: * Lead solution architecture across enterprise Identity and Access Management capabilities. * Define current, target and transition architectures for authentication, authorisation and identity services. * Architect identity services supporting workforce, external users, customers, partners and machine identities. * Define architecture for Microsoft Entra ID and ForgeRock based identity services. * Develop reusable authentication and authorisation patterns for applications and digital services. * Design Single Sign On and federation solutions across cloud, SaaS, COTS and bespoke applications. * Define Multi Factor Authentication and Conditional Access architectures. * Architect identity lifecycle management covering joiners, movers and leavers. * Define Role Based Access Control and Attribute Based Access Control patterns. * Design identity governance and access review capabilities. * Define approaches for privileged access and administrative identities. * Architect application, workload and service identity patterns. * Design secure integration between identity platforms and enterprise applications. * Define authentication and authorisation patterns for APIs and distributed services. * Support consolidation and rationalisation of multiple identity platforms. * Assess Legacy identity services and define pragmatic migration approaches. * Develop solution visions, High Level Designs, options assessments and architecture roadmaps. * Define non functional requirements covering availability, resilience, security, performance, scalability, disaster recovery and supportability. * Work with cyber security teams to ensure identity architectures support Zero Trust and least privilege principles. * Work with engineering and delivery teams throughout discovery, design, implementation and transition into live service. * Review detailed technical designs and implementation approaches against agreed architecture. * Identify architecture risks, dependencies and technical debt. * Prepare and present architecture decisions through technical governance and design authority forums. * Support proofs of concept and technology evaluations where appropriate. * Define monitoring, audit and operational requirements for identity services. * Promote repeatable engineering through automation, CI/CD and Infrastructure as Code where appropriate. * Contribute to architecture peer reviews and continuous improvement across Shivom's architecture practice., * Microsoft Entra ID * Enterprise applications * App registrations * Service principals * Managed identities * Single Sign On * Conditional Access * Multi Factor Authentication * Identity Protection * External identities * B2B collaboration * Role Based Access Control * Privileged Identity Management * Access reviews * Entitlement management * Identity governance * Groups and administrative units * Authentication methods * Passwordless authentication * Federation * Application consent * Workload identities * Audit and sign in logs * Hybrid identity, * Single Sign On * Multi Factor Authentication * Passwordless authentication * Step up authentication * Risk based authentication * Session management You should understand how to select appropriate identity patterns for web applications, APIs, mobile applications, SaaS services and machine to machine integration. Identity governance and lifecycleIdentity architecture extends beyond login.You should be comfortable designing capabilities covering: * Joiners, movers and leavers * Identity provisioning * Deprovisioning * Role assignment * Group management * Entitlement management * Access requests * Approvals * Periodic access reviews * Segregation of duties * Orphaned account management * Dormant account management * Privileged account lifecycle * External user lifecycle * Audit and evidence You should understand how identity governance integrates with HR systems, directories, applications and operational processes.Privileged access and Zero TrustExperience or strong architectural knowledge across the following would be beneficial: * Privileged Identity Management * Privileged Access Management * Just in Time access * Just Enough Administration * Administrative segregation * Break glass accounts * Strong authentication * Least privilege * Conditional Access * Device trust * Risk based access * Network and identity context * Zero Trust architecture Identity should form a core control plane for enterprise security rather than being treated as a standalone authentication service.Application and workload identityModern platforms increasingly depend on non human identities.You should understand: * Managed identities * Service principals * Workload identities * Application identities * Service accounts * Machine to machine authentication * Client credentials * Certificate based authentication * Secrets management * Credential rotation * Azure Key Vault * API authentication * Least privilege for workloads, * Microsoft Azure * Azure API Management * Azure applications and service principals * Managed identities * Azure Key Vault * Azure networking * Private Endpoints * Azure Monitor * Log Analytics * Application Insights Engineering and automationExperience or architectural understanding of: * Azure DevOps * GitHub * CI/CD * Infrastructure as Code * Terraform * Bicep * Identity configuration as code * Automated deployment * Automated provisioning * API driven identity management * Source control You do not need to be a DevOps engineer, but should understand how identity platform configuration can be deployed, controlled and audited through repeatable engineering practices.Monitoring, audit and observabilityIdentity services are security critical and should be observable by design.Experience with areas such as the following would be advantageous: * Entra sign in and audit logs * Identity Protection * Azure Monitor * Log Analytics * Application Insights * Dynatrace * Grafana * SIEM integration * Authentication monitoring * Privileged access monitoring * Failed authentication monitoring * Security alerts * Operational dashboards * Audit trails * Correlation and investigation, * Identity as a strategic enterprise capability * Zero Trust * Least privilege * Reusable authentication and authorisation patterns * Strong identity governance * Secure customer and external identity * Simplification and convergence * Modernisation of Legacy identity services * Secure by design architecture * Resilience and operational readiness * Automation and repeatability * Auditability and traceability * Open standards * Engineering aligned architecture * Sustainable technology choices * Effective collaboration across multiple suppliers and delivery teams Our architects remain close to delivery while maintaining the enterprise perspective needed to avoid fragmented and application specific identity solutions., You will be successful when you can: * Understand a complex identity landscape quickly. * Define a clear enterprise IAM direction and realistic transition roadmap. * Create reusable identity patterns that application teams can adopt easily. * Simplify fragmented identity services. * Balance strong security with a practical user experience. * Design identity services for internal, external and machine identities. * Make effective use of Microsoft Entra ID and ForgeRock capabilities. * Reduce application specific authentication and access solutions. * Build Zero Trust and least privilege principles into architecture. * Ensure privileged access receives appropriate protection and governance. * Integrate identity cleanly with APIs, applications and cloud platforms. * Build monitoring, auditability and operational support into identity services. * Produce architecture that engineering teams can practically implement. * Influence multiple delivery teams while maintaining strong working relationships. * Make clear recommendations when faced with competing security and architecture options. * Build trusted relationships with cyber security teams, engineers, senior stakeholders and fellow architects. Security requirements Applicants must either hold current Security Check (SC) clearance or be eligible to obtain SC clearance .Candidates who do not currently hold SC clearance must be willing to complete the required security vetting process as a condition of appointment.The successful candidate will be expected to work in accordance with applicable client and government security policies when undertaking assignments involving sensitive information or systems. Working arrangements This is a UK based hybrid role.You should be comfortable working remotely while also attending Shivom offices, client locations and other UK sites where collaboration, delivery activities or security requirements make in person attendance appropriate.The frequency of on site attendance may vary depending on the nature and stage of individual assignments. BenefitsAt Shivom, we want our people to build long term careers while working on meaningful and technically challenging programmes. Our benefits package includes: * Private medical insurance * Critical illness cover * Employer pension contribution * Generous annual leave entitlement plus UK bank holidays * Hybrid and flexible working arrangements, subject to client requirements * Support for professional certifications and technical training * Continuous professional development opportunities * Access to architecture, cloud, security, identity, data and engineering learning opportunities * Support for maintaining and progressing professional and security clearances * Career progression within Shivom's architecture and technology leadership practice * Opportunities to work on major UK public sector and enterprise transformation programmes * Regular knowledge sharing, technical forums and architecture communities of practice * Employee wellbeing support * Company sponsored social and team events * Employee referral opportunities * Recognition and performance related reward opportunities About Shivom Consultancy Shivom Consultancy is a UK based technology consultancy specialising in architecture, cloud, data, security, software engineering and digital transformation.We work with organisations delivering complex and business critical technology services, helping them modernise Legacy estates, adopt cloud and digital platforms, strengthen cyber security and build secure, resilient and scalable technology capabilities.Our architecture practice focuses on practical architecture that connects strategy with engineering. We believe architects should remain close to delivery, understand the operational impact of their decisions and help teams make technology choices that remain sustainable beyond the immediate project.You will join a growing architecture community with opportunities to work across identity, cyber security, cloud, APIs, integration, data and digital services. Why join Shivom? You will have the opportunity to shape enterprise identity services across complex organisations while developing your career within a growing architecture practice.You will work at the intersection of Microsoft Entra ID, ForgeRock, customer and workforce identity, Zero Trust, API security and cloud architecture, helping organisations move from fragmented identity services towards secure, reusable and sustainable enterprise capabilities.We combine the variety and technical challenge of consultancy with the opportunity to build longer term relationships with clients and delivery teams, influence architecture direction and see solutions progress from early design through implementation and live service. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Building Well-Architected applications](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)