NextPath Jobs

Security Solution Architecture

Microsoft · United Kingdom, Multiple Locations, Multiple Locations

Clearance-flagged

Posted 2026-09-15 · Verified live 2026-09-16

See how your real experience scores against this role — our AI drafts an honest, verifiable resume tailor. Nothing invented, ever. You approve everything.

Get matched — join the waitlist Apply on company site ↗

About this role

<b>Overview</b><br><p>We are seeking an <strong>Enterprise Identity Architect</strong> with deep, hands-on expertise in <strong>Identity &amp; Access Management (IAM)</strong> across complex, multitenant, and multiforest estates in the <strong>UK defence sector</strong>. The role will lead the <strong>unravelling of a complex identity landscape</strong>, establish a <strong>single authoritative master identity model</strong> spanning <strong>OFFICIAL to SECRET</strong> domains, and drive a secure, standards aligned roadmap built on <strong>Zero Trust</strong> and <strong>defence policy frameworks</strong> (including <strong>ASP 240</strong> and <strong>relevant JSPs</strong>).</p><p><strong>Key Outcomes (12–18 months)</strong><strong>Master Identity Model Delivered:</strong> A formalised, documented and implemented <strong>authoritative identity data model</strong> with clear <strong>source of truth</strong>, lifecycle, and attribute governance across OFFICIAL and SECRET domains.<strong>Consolidation &amp; Simplification:</strong> Reduced identity duplication and drift across <strong>multiple AD forests/tenants</strong>, clear trust/segregation boundaries, and <strong>evidence based access models</strong> (RBAC/ABAC) aligned to business roles/missions.<strong>Control Maturity Increase:</strong> Measured uplift in identity controls (MFA, PIM/PAM, password less, privileged isolation, just in time access) validated through <strong>defence audits and JSP/ASP control evidence</strong>.<strong>Assured Inter Domain Patterns:</strong> Approved <strong>cross domain identity patterns</strong> (e.g., credential brokerage, guardmediated flows, offline enclave procedures) with formal <strong>risk acceptance</strong> and <strong>assurance artefacts</strong>.<strong>Legacy Decommission:</strong> Defined and executed migration/decommission plans for legacy IdPs, ADFS, and brittle sync pipelines with <strong>documented rollback and operational runbooks</strong>.</p><br><br><b>Responsibilities</b><br><p><strong>Enterprise Identity Architecture</strong></p><ul><li>Define and own&nbsp;<strong>end to end IAM reference architectures</strong> for <strong>OFFICIAL and SECRET</strong> domains, including enclave segregation, trust models, and boundary controls.</li><li>Design&nbsp;<strong>authoritative identity sources</strong> and <strong>golden record schemas</strong> (HR, ERP, clearance systems), lifecycle policies (joiner/mover/leaver), and <strong>attribute governance</strong>.</li><li>Specify&nbsp;<strong>RBAC/ABAC models</strong>, entitlement catalogues, role mining, separation of duties (SoD) and <strong>privileged access patterns</strong> (PAW tiers, admin forest, bastion models).</li></ul><p><strong>Technical Strategy &amp; Delivery</strong></p><ul><li>Lead consolidation/modernisation across&nbsp;<strong>Microsoft Entra ID (Azure AD)</strong>, <strong>on Prem AD</strong>, <strong>MIM/Entra ID Governance</strong>, and third-party IGA (<strong>SailPoint/Saviynt</strong>).</li><li>Architect&nbsp;<strong>MFA/password less</strong> (FIDO2/YubiKey, smartcard/PIV equivalents), <strong>Conditional Access</strong>, <strong>risk based access</strong>, device trust, <strong>PIM</strong> and <strong>PAM</strong> (CyberArk/Beyond Trust).</li><li>Own identity integration for&nbsp;<strong>critical apps</strong> (cloud, on Prem, legacy, air gapped) and <strong>cross domain</strong> access patterns via controlled brokers/guards.</li></ul><p><strong>Security, Compliance &amp; Defence Governance</strong></p><ul><li>Map designs and evidence to&nbsp;<strong>ASP 240</strong> and applicable <strong>JSP guidelines</strong> (e.g., <strong>JSP 440</strong> Security, <strong>JSP 604</strong> Information/IA policies or successors), <strong>NCSC guidance</strong>, <strong>ISO/IEC 27001</strong>, and <strong>Zero Trust</strong> principles.</li><li>Produce and maintain&nbsp;<strong>HLD/LLD</strong>, <strong>Control Matrices</strong>, <strong>Risk/Threat Models (STRIDE/ATT&amp;CK)</strong>, <strong>Security Cases</strong>, <strong>Transition Plans</strong>, and <strong>Operational Runbooks</strong>.</li><li>Support audits, Design Reviews,&nbsp;<strong>IAO/SIRO</strong> approvals, security testing, and <strong>accreditation</strong> evidence.</li></ul><p><strong>Change &amp; Stakeholder Leadership</strong></p><ul><li>Run&nbsp;<strong>workshops</strong> to untangle legacy identity estates, discover shadow entitlements, and align business/mission owners to a <strong>single operating model</strong>.</li><li>Coach engineering and operations teams; establish&nbsp;<strong>guardrails</strong>, <strong>patterns</strong>, and <strong>reference implementations</strong>; guide <strong>devsecops</strong> integration for identity.<br><br></li></ul><br><br><b>Qualifications</b><br><p><strong>Proven record of accomplishment</strong> leading <strong>largescale IAM transformations</strong> in the <strong>Defence Sector</strong> with mixed classification environments (<strong>OFFICIAL, OFFICIALSENSITIVE, SECRET</strong>).</p><p>Deep expertise with:</p><ul><li><strong>Microsoft Entra ID</strong> (Azure AD), <strong>Entra Connect/Cloud Sync</strong>, <strong>MIM/Entra ID Governance</strong>, <strong>Conditional Access</strong>, <strong>PIM</strong>, tenant to tenant and hybrid patterns.</li><li><strong>Active Directory</strong> (multi‑forest consolidation, trusts, tiered admin, admin forests), <strong>DNS/PKI</strong> (enterprise and offline PKI, CRL/OCSP, HSMs FIPS 140‑2/3)</li><li>.<strong>PIM</strong> , <strong>PAW </strong>and <strong>PAM</strong>.</li><li><strong>MFA/password less</strong> (FIDO2, smartcards, CAC/PIVstyle credentials), <strong>credential hygiene</strong>, <strong>Kerberos/NTLM deprecation strategies</strong>.</li><li><strong>Zero Trust</strong> identity controls, <strong>RBAC/ABAC</strong>, and <strong>policy as code</strong> approaches.</li></ul><p><strong>Aligning all Zero Trust / Master identity to Enterprise Service Model.</strong></p><p>Demonstrable success&nbsp;<strong>unravelling complex identity estates</strong> (e.g., multiple AD forests, conflicting schemas, brittle sync, overlapping personas) and delivering a <strong>master identity model</strong> with clean source of truth and lifecycle automation.</p><p>Experience defining&nbsp;<strong>cross domain identity</strong> patterns for <strong>air gapped or highside</strong> environments, including <strong>guardmediated flows</strong>, <strong>brokers</strong>, <strong>one way trust</strong>, and <strong>offline credential issuance</strong>.</p><p>Strong documentation:&nbsp;<strong>HLD/LLD</strong>, architecture decision records, control mappings (JSP/ASP/NCSC), test plans, <strong>migration &amp; decommission</strong> plans.</p><p>&nbsp;</p><p><strong>Defence Policy &amp; Standards (Experience Expected)</strong></p><p><strong>Note:</strong>&nbsp;“ASP 240” nomenclature varies by organisation. Candidates must show experience aligning to&nbsp;<strong>ASP 240 (client/authority security policy 240)</strong> or equivalent <strong>Authority Security Policy</strong> requirements, plus:</p><ul><li><strong>JSP 440</strong> (security) and <strong>JSP 604</strong> (information/IA) or successor policy frameworks.</li><li><strong>NCSC</strong> guidance (e.g., MFA, device identity, protective monitoring, cloud security), <strong>HMG SPF</strong>, <strong>ISO/IEC 27001</strong>, <strong>NIST SP 800</strong>‑<strong>63 (Digital Identity)</strong>, <strong>NIST SP 800</strong>‑<strong>207 (Zero Trust)</strong>.</li><li>Evidence generation for&nbsp;<strong>assurance/accreditation</strong>, including control narratives, test evidence, residual risk statements, and operational handover.</li></ul><p><strong>Clearance Requirements</strong></p><ul><li><strong>Baseline:</strong> Active <strong>DV</strong> clearance required at starts</li><li>Ability to work in&nbsp;<strong>secure facilities</strong> (up to SECRET), follow <strong>need to know</strong>, and comply with <strong>JSP/ASP</strong> handling procedures.</li><li>Willingness to undergo&nbsp;<strong>additional customer specific vetting</strong> and adhere to <strong>personnel security</strong> obligations.</li></ul><p><strong>Nice to Have</strong></p><ul><li><strong>Cross domain solutions (CDS)</strong> exposure, data diodes/guards integration with identity.</li><li><strong>Logging &amp; Threat Detection</strong> integration&nbsp;Experience migrating from <strong>ADFS</strong> and legacy IdPs to modern standards (OIDC/SAML)</li><li>.Familiarity with&nbsp;<strong>supply chain and partner access</strong> hardening (B2B, external identities).</li><li>Prior work with&nbsp;<strong>highside enclaves</strong>, <strong>break glass</strong> and <strong>operational segregation</strong> (PAW, tiering, jump hosts).</li></ul><p><strong>Ways of Working</strong></p><ul><li>Pragmatic architect who can&nbsp;<strong>dive hands on</strong> to prove patterns, build <strong>reference implementations</strong>, and <strong>mentor engineers</strong>.</li><li>Strong communicator with the ability to&nbsp;<strong>translate policy (ASP/JSP/NCSC)</strong> into actionable designs and <strong>audit ready evidence</strong>.</li><li>Comfortable in&nbsp;<strong>multi</strong>‑<strong>supplier</strong> and <strong>secure programme</strong> environments with formal change, test, and release controls.<br><br></li></ul><p><strong>Example Deliverables</strong></p><ul><li><strong>Identity</strong><strong>&nbsp;Target Operating Model</strong> (policy, process, RACI, service catalogue).</li><li><strong>Master Identity Data Model</strong> (attributes, schemas, authoritative sources, lifecycle).</li><li><strong>Reference Architectures &amp; Patterns</strong> (OFFICIAL ↔ SECRET, cross domain access).</li><li><strong>Control Matrix &amp; Evidence Pack</strong> mapped to <strong>ASP 240, JSPs, NCSC</strong>.</li><li><strong>Migration &amp; Decommission Plan</strong> with success metrics and rollback.</li><li><strong>Operational Runbooks</strong> (privileged workflows, emergency access, DR/BCP for identity).&nbsp;<br></li></ul> <br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html" rel="noopener noreferrer"><b><u>requesting accommodations.</u></b></a></p>

One of thousands of fresh listings refreshed nightly, built for cleared & defense careers.

Browse all jobs