Dev Sec Ops Solutions Architect
Job Title: Dev Sec Ops Solutions Architect
3 days on site - Sheffield
Job Description
This role sits within a global Identity and Access Management (IAM) function that is redefining how identity is managed at enterprise scale. You will act as a Solution Architect and Design Engineer for a multi-year IAM transformation, delivering secure, scalable and supportable identity services across a complex international technology estate. Working closely with IAM architects, business stakeholders and technology partners, you will define the target architecture for IDAM 2.0 and provide end-to-end technical design that bridges modern IAM technology with large-scale banking environments.
Responsibilities
- Provide end-to-end solution architecture and technical design for the IDAM 2.0 programme across business, application, data and infrastructure domains.
- Produce high-quality High Level Designs (HLDs) and Low Level Designs (LLDs) that clearly describe identity and access management solutions.
- Translate business, security and regulatory requirements into secure, scalable and supportable technical solutions.
- Develop reference architectures, patterns and design standards to guide delivery across the IAM transformation programme.
- Define integration patterns between identity platforms, applications, infrastructure and wider enterprise services.
- Design cloud-native identity and security solutions for Google Cloud Platform (GCP) and Kubernetes environments.
- Define authentication, authorisation and federation architectures to support human and non-human identities.
- Design Agent Identity, Human Identity and Workload Identity solutions within a Zero Trust security architecture and clearly defined trust boundaries.
- Design API security architectures, including service-to-service authentication and workload authentication patterns.
- Develop event-driven integration architectures using messaging and asynchronous processing to support scalable IAM services.
- Design Policy Decision Point (PDP) and Policy Enforcement Point (PEP) architectures using Policy-as-Code approaches.
- Define patterns for secrets management, certificate life cycle management and PKI integration.
- Design resilience, disaster recovery and high-availability architectures for IAM platforms and services.
- Ensure all solutions meet non-functional requirements for security, scalability, resilience and performance.
- Produce architecture decision records (ADRs) and comprehensive design documentation for governance and delivery teams.
- Support architectural governance through participation in Architecture Review Boards and Design Authorities.
- Perform solution assurance and technical design reviews for internal and supplier-delivered solutions.
- Identify and manage technical risks, assumptions, constraints and dependencies across multiple workstreams.
- Collaborate with Enterprise Architecture to ensure alignment with the strategic architecture and target state.
- Work closely with Product Owners to refine technical requirements, clarify scope and prioritise delivery.
- Support engineering teams throughout implementation, testing and production readiness, providing ongoing technical guidance.
- Mentor engineers and promote engineering and DevSecOps best practices across the IAM function.
- Evaluate new technologies and vendor products against programme requirements and recommend adoption where appropriate.
- Contribute to roadmap planning and the definition of future-state architecture for identity and access management.
Essential Skills
- Proven experience in enterprise solution architecture, ideally within large and complex global organisations.
- Strong expertise in Identity and Access Management (IAM), covering human and non-human identities.
- Deep knowledge of authentication and authorisation mechanisms and standards.
- Hands-on experience designing and implementing Zero Trust architectures.
- experience with Agent Identity and Workload Identity solutions.
- Strong understanding of identity federation standards such as OIDC, OAuth2, SAML and SCIM.
- Cloud architecture experience with Google Cloud Platform (GCP).
- Practical experience with Kubernetes and service mesh technologies.
- Expertise in API architecture and API security design.
- experience designing and implementing event-driven architectures.
- Knowledge and practical use of Policy-as-Code tools and frameworks (for example OPA or Cedar).
- Strong understanding of PKI, digital certificates and secrets management.
- experience working in DevSecOps environments with CI/CD pipelines.
- Demonstrable experience designing for high availability, resilience and disaster recovery.
- Background in security architecture, particularly in the context of IAM.
- experience operating within formal architecture governance frameworks.
- Strong stakeholder management skills, with the ability to influence and align diverse technical and business stakeholders.
- Proven technical leadership experience across multiple workstreams or programmes.
Additional Skills & Qualifications
- experience working on large-scale, multi-year transformation programmes in regulated industries.
- Background in banking or financial services technology environments.
- Familiarity with core banking systems and large-scale technology estates.
- experience collaborating with external vendors and reviewing supplier-provided solution designs.
- experience documenting architecture decision records (ADRs) and maintaining architectural artefacts.
- Exposure to event-driven and messaging-based integration patterns within security-sensitive environments.
- experience mentoring engineers and contributing to the development of engineering standards and best practices.
Sheffield, UK
Trading as TEKsystems. Allegis Group Limited, Bracknell, RG12 1RT, United Kingdom. No Allegis Group Limited operates as an Employment Business and Employment Agency as set out in the Conduct of Employment Agencies and Employment Businesses Regulations 2003. TEKsystems is a company within the Allegis Group network of companies (collectively referred to as "Allegis Group"). Aerotek, Aston Carter, EASi, Talentis Solutions, TEKsystems, Stamford Consultants and The Stamford Group are Allegis Group brands. If you apply, your personal data will be processed as described in the Allegis Group Online Privacy Notice available at our website.
To access our Online Privacy Notice, which explains what information we may collect, use, share, and store about you, and describes your rights and choices about this, please go our website.
We are part of a global network of companies and as a result, the personal data you provide will be shared within Allegis Group and transferred and processed outside the UK, Switzerland and European Economic Area subject to the protections described in the Allegis Group Online Privacy Notice. We store personal data in the UK, EEA, Switzerland and the USA. If you would like to exercise your privacy rights, please visit the "Contacting Us" section of our Online Privacy Notice on our website for details on how to contact us. To protect your privacy and security, we may take steps to verify your identity, such as a password and user ID if there is an account associated with your request, or identifying information such as your address or date of birth, before proceeding with your request. commitments under the UK Data Protection Act, EU-U.S. Privacy Shield or the Swiss-U.S. Privacy Shield.