Data Architect Senior at LanceSoft Inc
London, New South Wales, United Kingdom -
Full Time


Start Date

Immediate

Expiry Date

16 Nov, 26

Salary

0.0

Posted On

18 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services;Software Development & Publishing

Description

Description:

  • Target IAM architecture design: Define a coherent enterprise identity architecture aligned to the ISO24760 standard reference architecture principles (stakeholders, actors, lifecycle services and governance), ensuring separation of identity authority, relying parties, and verification services.
  • Current-state architecture assessment against target IAM architecture design including risk analysis: Evaluate existing IAM services integration (EntraID, ideiio, AWS Cognito) against all IAM pillars, Zero Trust Architecture frameworks, good practice least privilege principles and assurance requirements.
  • IAM pillars should include verification using HMG verification platforms, identity governance and administration (IGA), customer/citizen identity (CIAM), access management (AM), privileged access management (PAM), non-human/machine identity management (NHI/MIM)
  • The architecture assessment shall include the identification of risks in the UKRI identity lifecycle governance, policies and processes, access controls, monitoring and auditing gaps, and data quality management for each of the following pillars:
  • Identity governance and administration lifecycle model (IGA): Design end-to-end identity lifecycle controls (joiner mover leaver, provisioning, review, deprovisioning), including policy-driven access, auditability, and data quality assurance. Establish identity governance structures to ensure secure, scalable identity controls.
  • Authentication and access management (AM): Define modern authentication patterns aligned to assurance levels (eg, phishing-resistant MFA, passwordless), adaptive risk-based access (aka Conditional Access Controls (CAC)), and session controls for all IAM pillars including users, devices and agents.
  • Privileged access and control (PAM): Establish privileged identity controls, segregation of duties, and just-in-time access, aligned to the principle of least privilege and audit requirements.Integration and identity fabric: Design adaptive, secure identity integration patterns across enterprise systems enabling federated identity, interoperability, and secure identity information exchange between services.
  • Transition architecture: Design the migration from existing IAM services to the new IAM target architecture. Define how the new IAM architecture will transition into existing systems and will support the migration from existing services.
  • Phased implementation roadmap: Deliver a structured roadmap covering discovery, Alpha capability delivery, and phased rollout of IAM services with measurable outcomes (for identity verification, IGA and lifecycle automation, CIAM, AM, PAM, identity trusts and federation) to support the project management planning delivery.

Project Descriptor:

  • Strategic two-year project to establish identity as the primary control plane for secure access management to UKRI services, aligned to Zero Trust Architecture frameworks and enterprise architecture principles.
  • Design and deliver a future-fit identity capability blueprint structured around the core IAM pillars of identity verification, governance (IGA & JML), authentication and access controls (AM), citizen and customer identity (CIAM), non-human identity including machine identity management (NHI/MIM), privileged access (PAM), as well as identity trust and federation with associate organsations, trusted 3rd parties and suppliers.
  • Transform current identity services with a scalable, policy-driven and standards-aligned IAM platform, improving security, resilience and operational efficiency that addresses current services support and operational challenges.Establish identity as the core security control for access management to UKRI services, laying foundations for broader Zero Trust Architecture initiatives across networks, devices, applications, and data.
  • Ensure IAM services are designed with clear roles, stakeholders, and trust relationships, supporting enterprise and federated deployment scenarios.
  • Deliver Year 1 outcomes focused on foundational IAM controls that include identity lifecycle management (JML/IGA), strong authentication and access management, identity data quality, identity monitoring, auditing and governance.
  • Conduct extended discovery and design activities (Year 1) that define UKRI identity requirements across all IAM pillars, improve identity standards, policies and processes, and support the development of a full identity business case, with potential early (Alpha) implementation.
  • Deliver priority IAM capabilities (Year 1) including replacement of existing identity governance and administration (IGA) services, improved authentication with phishing resistant MFA and passwordless controls, and credential management.
  • Deliver Year 2 outcomes expanding to privileged access, external /customer / citizen identity platforms that are aligned with UK Government initiatives, identity lifecycle automation, and full integration across UKRI services.
  • Embed audit, compliance and regulatory alignment including assurance levels, consent management, logging and reporting
  • Enterprise IAM architecture expertise: Strong design capability across identity verification assurance levels (IALs), IGA, CIAM, AM, PAM, and trust models aligned to enterprise and federated deployment scenarios.
  • Identity lifecycle and governance design: Experience defining identity lifecycle policies and processes, identity data quality controls, and audit mechanisms.
  • Evidence of IAM industry architecture expertise: Deep knowledge of identity platforms (e.g. Entra ID, AWS Cognito, IGA, PAM, HMG Gov.OneLogin desirable) and demonstrable ability to design scalable, future-fit architectures.Zero Trust architecture (ZTA): Strong understanding of Zero Trust Architecture principles and design, and how identity good practice underpins secure authentication, authorisation and risk-based access controls.
  • Zero Trust architecture and access control design: Ability to translate Zero Trust principles into identity-driven access management, that includes the implementation of the principle of least privilege, separation and segregation of duties and risk-based decisioning.
  • Strong evidence of authentication and authorisation assurance expertise: Knowledge of modern authentication standards and protocols, assurance levels, and credential lifecycle controls.Identity governance and lifecycle management: Expertise in designing role-based access, identity lifecycle processes and automated applications provisioning, and governance models across complex organisations.
  • Integration and migration architecture: Proven capability designing integration, federation and transition from existing identity platforms. Demonstrable ability to design integrations with legacy and modern systems, and plan transitions from existing IAM services with minimal disruption.
  • Stakeholder engagement and governance: Ability to work across business, security and suppliers, aligning stakeholders, policies and regulatory expectations.
  • Stakeholder engagement and technical leadership: Capability to work with senior Enable Skills-Based Hiring NoRegion try { var fgTooltip = new FG.Tooltip({ element: $('#cf_descz18051517413973032789902'), text: "Geographical\x20Region" }).initialize(); } catch(err) {}Additional DetailsSenior Interim Hire : No
  • Region : South West
  • Requisition Type : 1. New Requirement
  • Name of Nominated Worker : (No Value)
  • Please provide any additional information specific to this role : (No Value)
  • If any professional qualifications are required for the role, please list certificates here: : (No Value)
  • Desired Skill 1 : TECH & DIGITAL|Architecture
  • Desired Skill 2 : (No Value)
  • Desired Skill 3 : (No Value)
  • Desired Skill 4 : (No Value)
  • Desired Skill 5 : (No Value)
  • Are there any Health and Safety requirements or hazards associated to this role? : No
  • If yes, please specify the Health and Safety Considerations : (No Value)
  • Is the role in or out of scope of IR35? : In Scope
  • Level of screening : BPSS (Basic Disclosure)
  • Internal Job Title : Lead IAM Technical Architect
  • Grade : G
  • AMS Job Category : Technology|Solutions Architect
  • Equivalent Permanent Grade : UK Research and Innovation (UKRI) (BEIS UKRI)|G
  • Armed Forces Covenant Signatory : Unknown
  • Disability Confident Level : Yes - Employer (L2)
  • Business Unit Name Hierarchy : Department for Business Energy and Industrial Strategy|UK Research and Innovation (UKRI)
  • Business Unit Code Hierarchy : BEIS|BEIS UKRI

LanceSoft

Responsibilities
Loading...