eTeam
Security Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Title: IAM Security Architect
Location:
Staines TW18 3DZ / Brighton BN1 4FY / London EC2R 7HJ (3 days office)
Duration:
26/02/2027
Pay Rate:
£581 to 608 per day all inc. (PAYE through Umbrella)
Clearance:
SC Eligible
Role Description:
Job Purpose
The Identity & Access Architect is responsible for defining, designing, and governing enterprise-wide Identity and Access Management (IAM) solutions across Microsoft Azure, Microsoft Entra ID, Google Cloud Platform (GCP), and SaaS Platform such as Salesforce, Oracle Health Insurance, and PeopleSoft. The role provides technical leadership for identity architecture, authentication, authorization, privileged access management, federation, secrets management, token lifecycle governance, and DevSecOps identity controls.
The architect will establish secure, scalable, and compliant identity patterns for users, applications, workloads, APIs, automation platforms, and CI/CD pipelines while supporting a Zero Trust security model.
The successful candidate will serve as the subject matter expert for cloud identity, access governance, workload authentication, and token management across hybrid and multi-cloud environments for human and also agentic access requirements.
Key Responsibilities
Identity Architecture & Strategy
- Define and maintain the enterprise IAM strategy and roadmap.
- Design secure identity architectures across Azure, Entra ID, GCP, SaaS platform.
- Design User access management for human, Agentic applications, and APIs.
- Develop identity governance standards, patterns, and reference architectures.
- Ensure alignment with Zero Trust principles and cloud security best practices.
- Lead the design of hybrid identity and cloud-native authentication solutions.
- Provide architecture guidance for new applications, platforms, and services.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Authentication & Federation
- Design and implement enterprise authentication and federation services including:
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Passwordless Authentication
- Federation Services
- Identity Trust Relationships
Protocols and technologies:
- SAML 2.0
- OAuth 2.0
- OpenID Connect (OIDC)
- SCIM
- WS-Federation
- Kerberos
- LDAP
Responsibilities include:
- Federation between Microsoft Entra ID and GCP.
- Integration with SaaS and third-party identity providers.
- B2B and B2C identity solutions.
- Cross-cloud trust establishment.
- API authentication architecture.
Token Management & Governance
- Act as the enterprise authority for token lifecycle management.
- Privileged role governance.
- Privileged access reviews.
- Break-glass account management.
- Segregation of duties controls.
Token Types:
- OAuth Access Tokens
- Refresh Tokens
- ID Tokens
- JWT Tokens
- Service Account Tokens
- OIDC Tokens
- PAT (Personal Access Tokens)
- API Access Tokens
Responsibilities
- Define token issuance standards.
- Establish token lifespan and expiry policies.
- Design token validation mechanisms.
- Define token revocation processes.
- Implement token monitoring and auditing.
- Govern token signing and certificate management.
- Design secure token storage patterns.
- Prevent token leakage and abuse.
- Establish short-lived token standards across cloud platforms.
- Credential lifecycle management.
- Automated secret rotation.
- Certificate lifecycle governance.
- Encryption key management.
- Elimination of hard-coded credentials.
- Secure storage and retrieval controls
- Auditable access to sensitive credentials.
- Secrets management standards across cloud platforms.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Privileged Access Management (PAM)
Security Principles:
- Least privilege access
- Just-In-Time (JIT) authentication
- Zero Trust verification
- Secure token handling
- Continuous validation of identity
Secrets, Certificates & Key Management
- Design and govern enterprise secret management capabilities.
- Microsoft Azure
- Azure Key Vault
- Managed Identities
- Entra Workload Identities
- Service Principals
- Certificate Management
- Google Cloud Platform
- Secret Manager
- Cloud KMS
- Customer Managed Encryption Keys (CMEK)
- Workload Identity Federation
- Service Accounts
- Microsoft Azure
Design and govern privileged access solutions including:
- Microsoft Entra Privileged Identity Management (PIM)
- Just-In-Time Access
- Just Enough Administration (JEA)
- Google Cloud IAM Controls
If you are interested in this position and would like to learn more, please send through your CV and we will get in touch with you as soon as possible. Please note, candidates are often shortlisted within 48 hours.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location