Identity Security Architect
Key details
- Compensation
- $137,500 - $143,000
Job Description
Salary: £137,500 - 143,000 per year
Requirements
- Significant experience designing enterprise Identity and Access Management solutions.
- Strong architecture-level expertise with Microsoft Entra ID and Microsoft identity technologies.
- Strong understanding of Active Directory and hybrid identity architectures.
- Demonstrable experience designing Conditional Access strategies at enterprise scale.
- Strong knowledge of privileged access management and Microsoft Entra PIM.
- Experience with identity governance, lifecycle management and access certification.
- Strong understanding of modern authentication and federation protocols including OAuth 2.0, OpenID Connect, SAML and Kerberos.
- Experience designing passwordless and phishing-resistant authentication solutions.
- Strong understanding of Microsoft 365 and Azure security architecture.
- Experience designing identity controls as part of a Zero Trust security architecture.
- Ability to assess identity security posture and translate findings into prioritised remediation programmes.
- Experience operating in complex enterprise environments with multiple business units, applications and stakeholder groups.
Responsibilities
- Define and deliver enterprise Identity & Access Management architecture, primarily leveraging Microsoft Entra ID across cloud, hybrid and on-premises environments.
- Design secure authentication, authorisation and identity governance solutions for users, administrators, applications, workloads and external identities.
- Develop identity roadmaps, architecture standards, security patterns and technical governance frameworks.
- Architect and optimise Microsoft Entra capabilities including Conditional Access, ID Protection, PIM, Identity Governance, External ID, Access Reviews, Entitlement Management and Hybrid Identity solutions.
- Design hybrid identity integrations between Active Directory and Microsoft Entra ID, including strategies for passwordless and phishing-resistant authentication.
- Implement Zero Trust identity architectures, enforcing least privilege, risk-based access controls and secure administrative access models.
- Define privileged access strategies using Entra PIM, RBAC/ABAC, Just-in-Time access and privileged account governance.
- Lead identity governance initiatives, including Joiner-Mover-Leaver processes, access certification, lifecycle automation and management of guest/external identities.
- Provide architectural guidance for application and workload identities, including OAuth 2.0, OpenID Connect, SAML, Enterprise Applications, App Registrations, Managed Identities and Service Principals.
- Establish governance for application permissions, secrets, certificates and workload credentials, reducing reliance on long-lived credentials.
- Ensure identity services integrate effectively with the wider Microsoft security ecosystem, including Defender, Sentinel, Intune, Purview and Azure security services.
- Conduct identity assessments, identify security and operational improvements, and mitigate risks related to privileged access, credential exposure and legacy authentication.
- Lead stakeholder workshops, translate business and security requirements into technical solutions, and produce architecture documentation, standards and migration roadmaps.
- Provide technical leadership, design assurance and governance support throughout project delivery, implementation and solution lifecycle.
Technologies
- Active Directory
- Architect
- Azure
- Cloud
- Support
- Microsoft 365
- OAuth
- OpenID
- RBAC
- SAML
- Security
- Office 365
- IAM
- Windows
More
We are an IT consultancy client offering a mainly remote Identity Security Architect role, with approximately one day per week on site in either central London or Southampton and the remainder working remotely. The contract is available as a six-month day-rate engagement inside IR35 or as a fixed-term contract, with flexible remuneration. We also support reasonable adjustments during the recruitment process and offer referral incentives, including a bonus for successful referrals and an iPad for new client introductions.
last updated 34 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 43 indexed roles at this employer: $38,500 - $143,000(mid ~73820)
Context reflects data collected at crawl time.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs, or every remote job category.
Splunk SOAR Engineer - FTC
IT Security Manager
Clio Operate / ShareDo Developer & Configurator
Source: DevITJobs • Last updated 1w ago