Identity and Access Management Architect (IDAM)
Job Description
Location: Farnborough (onsite 5 days per week)
IDAM Architecture & Strategy
- Design enterprise-scale identity and access management architectures supporting defence operations.
- Architect secure authentication, multi-factor authentication (MFA) and authorisation frameworks.
- Design role-based access control (RBAC), attribute-based access control (ABAC) and privilege access management (PAM) solutions.
- Develop identity governance, access lifecycle management and entitlement management strategies.
- Lead IDAM technology evaluation and vendor selection processes.
Security & Compliance
- Ensure IDAM architectures comply with Classification Guides, Defence Security Policy and ITAR regulations.
- Design identity solutions supporting defence contractor personnel vetting (PRF) requirements.
- Architect data protection and encryption strategies aligned with defence security standards.
- Lead security risk assessments for IDAM systems and vulnerabilities.
- Design audit and logging capabilities supporting compliance and forensic requirements.
IDAM Modernisation & Implementation
- Lead design and implementation of modern IDAM platforms (AD/Azure AD, Okta, Ping, ForgeRock).
- Design cloud-ready and hybrid identity solutions supporting multi-cloud environments.
- Guide API-driven identity architecture and microservices-based identity solutions.
- Lead IDAM system migrations and technology modernisation programmes.
Technical Leadership & Governance
- Lead IDAM technical teams and provide architectural mentoring.
- Establish IDAM design standards, architecture patterns and operational governance.
- Drive technical decision-making through IDAM design reviews.
- Document IDAM architecture decisions and design specifications.
Integration & Operations
- Design IDAM integration with enterprise applications, systems and cloud platforms.
- Architect identity federation, single sign-on (SSO) and cross-domain authentication.
- Support IDAM operational readiness, performance monitoring and incident response.
- Establish IDAM lifecycle management and continuous improvement processes.
Customer & Stakeholder Engagement
- Serve as technical authority for IDAM architecture discussions with customer leadership.
- Present identity and access management recommendations to defence programme teams.
- Lead IDAM design workshops and customer validation activities.
What You’ll Bring
- Previous experience in identity and access management within a architecture role.
- Proven experience designing enterprise-scale IDAM solutions.
- Strong background in defence, aerospace or government IDAM programmes.
- Demonstrated expertise with modern identity platforms (Azure AD, Okta, Ping, ForgeRock).
- Track record of leading IDAM modernisation and technology transformation programmes.
- Deep expertise in IDAM architecture patterns, methodologies and best practices.
- Expert-level knowledge of identity technologies including LDAP, Active Directory, OAuth, SAML and OpenID Connect.
- Strong understanding of Azure AD, Office 365 identity, hybrid identity and cloud-native identity solutions.
- Proficiency in privilege access management (PAM), role/attribute-based access control (RBAC/ABAC).
- Knowledge of identity governance, access certification and entitlement management.
- Expertise in API security, service-to-service authentication and microservices identity.
- Understanding of cryptography, encryption and security protocols.
- Exceptional strategic thinking with strong technical depth.
- Outstanding communication and stakeholder engagement skills.
- Strong problem-solving and analytical capabilities.
- Proven ability to lead technical teams and influence senior stakeholders.
- Commitment to security and compliance excellence.
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here
Not included in the source posting: about the role, what you'll do, qualifications, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.