Rodeo
Get started

undisclosed

IAM Security Architect

London
£644/day
Posted about 22 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Role Title: IAM Security Architect

Duration: contract to run until 26/02/2027

Location: London/Brighton/Staines. Hybrid working 3 days per week onsite

Rate: up to £644 p/d Umbrella inside IR35

Role purpose / summary

The Identity & Access Architect is responsible for defining, designing, and governing enterprise-wide Identity and Access Management (IAM) solutions across Microsoft Azure, Microsoft Entra ID, Google Cloud Platform (GCP) and SaaS platforms such as Salesforce, Oracle Health Insurance, and PeopleSoft.

The role provides technical leadership for identity architecture, authentication, authorization, privileged access management, federation, secrets management, token lifecycle governance, and DevSecOps identity controls. The architect will establish secure, scalable, and compliant identity patterns for users, applications, workloads, APIs, automation platforms, and CI/CD pipelines while supporting a Zero Trust security model.

The successful candidate will serve as the subject matter expert for cloud identity, access governance, workload authentication, and token management across hybrid and multi-cloud environments for human and also agentic access requirements.

Key Responsibilities

Identity Architecture & Strategy

  • Define and maintain the enterprise IAM strategy and roadmap.
  • Design secure identity architectures across Azure, Entra ID, GCP, SaaS platforms.
  • Design user access management for human, agentic applications, and APIs.
  • Develop identity governance standards, patterns, and reference architectures.
  • Ensure alignment with Zero Trust principles and cloud security best practices.
  • Lead the design of hybrid identity and cloud-native authentication solutions.
  • Provide architecture guidance for new applications, platforms, and services.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Authentication & Federation

Design and implement enterprise authentication and federation services including:

  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • Passwordless Authentication
  • Federation Services
  • Identity Trust Relationships

Protocols and technologies:

  • SAML 2.0
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • SCIM
  • WS-Federation
  • Kerberos
  • LDAP

Responsibilities include:

  • Federation between Microsoft Entra ID and GCP.
  • Integration with SaaS and third-party identity providers.
  • B2B and B2C identity solutions.
  • Cross-cloud trust establishment.
  • API authentication architecture.

Token Management & Governance

Act as the enterprise authority for token lifecycle management.

Token Types:

  • OAuth Access Tokens
  • Refresh Tokens
  • ID Tokens
  • JWT Tokens
  • Service Account Tokens
  • OIDC Tokens
  • PAT (Personal Access Tokens)
  • API Access Tokens

Responsibilities:

  • Define token issuance standards.
  • Establish token lifespan and expiry policies.
  • Design token validation mechanisms.
  • Define token revocation processes.
  • Implement token monitoring and auditing.
  • Govern token signing and certificate management.
  • Design secure token storage patterns.
  • Prevent token leakage and abuse.
  • Establish short-lived token standards across cloud platforms.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Security Principles:

  • Least privilege access
  • Just-In-Time (JIT) authentication
  • Zero Trust verification
  • Secure token handling
  • Continuous validation of identity

Secrets, Certificates & Key Management

Design and govern enterprise secret management capabilities.

Microsoft Azure:

  • Azure Key Vault
  • Managed Identities
  • Entra Workload Identities
  • Service Principals
  • Certificate Management

Google Cloud Platform:

  • Secret Manager
  • Cloud KMS
  • Customer Managed Encryption Keys (CMEK)
  • Workload Identity Federation
  • Service Accounts

Responsibilities include:

  • Credential lifecycle management.
  • Automated secret rotation.
  • Certificate lifecycle governance.
  • Encryption key management.
  • Elimination of hard-coded credentials.
  • Secure storage and retrieval controls.
  • Auditable access to sensitive credentials.
  • Secrets management standards across cloud platforms.

Privileged Access Management (PAM)

Design and govern privileged access solutions including:

  • Microsoft Entra Privileged Identity Management (PIM)
  • Just-In-Time Access
  • Just Enough Administration (JEA)
  • Google Cloud IAM Controls

Responsibilities include:

  • Privileged role governance.
  • Privileged access reviews.
  • Break-glass account management.
  • Segregation of duties controls.

All profiles will be reviewed against the required skills and experience. Due to the high number of applications, we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Identity & Access Management
Microsoft Azure
Microsoft Entra ID
Google Cloud Platform
Zero Trust
SAML 2.0
OAuth 2.0
OpenID Connect
Privileged Access Management
Token Lifecycle Management
Secrets Management
DevSecOps
Federation Services
API Authentication
Cloud Security Architecture
Identity Governance

Location

London, England, United Kingdom

Sign up to applySee more jobs like this