Security Solution Architecture
Microsoft
- Location
- United Kingdom, Multiple Locations, Multiple Locations
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 2,066 approvals (FY2023)
- Posted
- 2h ago
About this role
Overview
Enterprise Identity Architect (Defence Sector)Location: UKClearance: Candidates who do not currently hold transferable UK DV clearance need not apply. Candidates must be willing to undergo additional customer specific vetting and adhere to personnel security obligations.Employment Type: Permanent / Long‑term Contract Travel: As required to UK sites in the South and West - averaging 3 days per week onsite Role Purpose We are seeking an Enterprise Identity Architect with proven deep, hands-on expertise in Identity & Access Management (IAM) across on-premises and cloud environments and, demonstrable experience shaping identity strategy for complex, multi-tenant, and multi-forest estates in regulated settings.This role is not a hands-on engineering-only role, a general architecture role, or an entry route into defence identity. We welcome candidates who meet the essential requirements and can evidence equivalent experience from regulated, national-security, critical infrastructure, or defence-adjacent environments.The role will lead and enable in a complex identity landscape, establish a single authoritative master identity model spanning classification domains, and shape and deliver a secure, standards aligned roadmap built on Zero Trust and defence policy frameworks (including ASP 240 and relevant JSPs). Candidates must be able to operate at enterprise architecture level while staying credible with engineering teams, security authorities, and operational stakeholders. Key Outcomes (12–18 months) Master Identity Model Delivered: A formalised, documented and implemented authoritative identity data model with clear source of truth, lifecycle, and attribute governance across classification domains. Consolidation & Simplification: Reduced identity duplication and drift across multiple AD forests/tenants, clear trust/segregation boundaries, and evidence based access models (RBAC/ABAC) aligned to business roles/missions. Control Maturity Improvement: Measured uplift in identity controls (MFA, PIM/PAM, passwordless, privileged isolation, just-in-time access) validated through defence audits and JSP/ASP control evidence.Assured Inter Domain Patterns: Approved cross domain identity patterns (e.g., credential brokerage, guard-mediated flows, offline enclave procedures) with formal risk acceptance and assurance artefacts. Legacy Decommission: Defined and executed migration/decommission plans for legacy IdPs, ADFS, and brittle sync pipelines with documented rollback and operational runbooks. Before applying, candidates must have current transferable UK DV clearance and, be able to evidence: enterprise-scale IAM architecture leadership; delivery across hybrid Active Directory and Microsoft Entra environments; experience in regulated, defence, national-security, or similarly controlled environments; and the ability to produce assurance-ready architecture artefacts for senior technical, security, and governance audiences. If you meet the essential clearance and architecture requirements but do not match every technology listed, we still encourage you to apply and show how your experience maps to the outcomes we need.
Responsibilities
Enterprise Identity Architecture Define and own end to end IAM reference architectures for OFFICIAL and SECRET domains, including enclave segregation, trust models, and boundary controls. Design authoritative identity sources and golden record schemas (HR, ERP, clearance systems), lifecycle policies (joiner/mover/leaver), and attribute governance . Specify RBAC/ABAC models , entitlement catalogues, role mining, separation of duties (SoD) and privileged access patterns (PAW tiers, admin forest, bastion models). Technical Strategy & Delivery Shape and enable consolidation/modernisation across on-premises Active Directory, Microsoft Entra ID, Microsoft Identity Manager/Entra ID Governance, and third-party IGA platforms including SailPoint and Saviynt. Architect MFA/password