Enterprise Identity Architecture Define and own end to end IAM reference architectures for OFFICIAL and SECRET domains, including enclave segregation, trust models, and boundary controls. Design authoritative identity sources and golden record schemas (HR, ERP, clearance systems), lifecycle policies (joiner/mover/leaver), and attribute governance. Specify RBAC/ABAC models, entitlement catalogues, role mining, separation of duties (SoD) and privileged access patterns (PAW tiers, admin forest, bastion models). Architect MFA/password less (FIDO2/YubiKey, smartcard/PIV equivalents), Conditional Access, risk based access, device trust, PIM and PAM (CyberArk/Beyond Trust). Map designs and evidence to ASP 240 and applicable JSP guidelines (e.g., JSP 440 Security, JSP 604 Information/IA policies or successors), NCSC guidance, ISO/IEC 27001, and Zero Trust principles. Produce and maintain HLD/LLD, Control Matrices, Risk/Threat Models (STRIDE/ATT&CK), Security Cases, Transition Plans, and Operational Runbooks. Support audits, Design Reviews, IAO/SIRO approvals, security testing, and accreditation evidence. Run workshops to untangle legacy identity estates, discover shadow entitlements, and align business/mission owners to a single operating model. Coach engineering and operations teams; establish guardrails, patterns, and reference implementations; guide devsecops integration for identity. Proven record of accomplishment leading large-scale Identity and Access Management transformations in complex regulated environments. Defence sector experience with mixed classification environments is preferred; candidates must demonstrate that their experience maps to defence assurance, governance, and accreditation expectations. Active Directory (multi‑forest consolidation, trusts, tiered admin, admin forests), DNS/PKI (enterprise and offline PKI, CRL/OCSP, HSMs FIPS 140‑2/3) .PIM , PAW and PAM. MFA/password less (FIDO2, smartcards, CAC/PIVstyle credentials), credential hygiene, Kerberos/NTLM deprecation strategies. Zero Trust identity controls, RBAC/ABAC, and policy as code approaches. Aligning all Zero Trust / Master identity to Enterprise Service Model. Demonstrable success unravelling complex identity estates (e.g., multiple AD forests, conflicting schemas, brittle sync, overlapping personas) and delivering a master identity model with clean source of truth and lifecycle automation. Experience defining cross domain identity patterns for air gapped or highside environments, including guardmediated flows, brokers, one way trust, and offline credential issuance. Strong documentation: HLD/LLD, architecture decision records, control mappings (JSP/ASP/NCSC), test plans, migration & decommission plans. Note: “ASP 240” nomenclature varies by organisation. Candidates must show experience aligning to ASP 240 (client/authority security policy 240) or equivalent Authority Security Policy requirements, plus: JSP 440 (security) and JSP 604 (information/IA) or successor policy frameworks. NCSC guidance (e.g., MFA, device identity, protective monitoring, cloud security), HMG SPF, ISO/IEC 27001, NIST SP 800‑63 (Digital Identity), NIST SP 800‑207 (Zero Trust). Experience migrating from ADFS and legacy IdPs to modern standards (OIDC/SAML).Familiarity with supply chain and partner access hardening (B2B, external identities).
Want jobs like this matched to you?
SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.