Security & Identity Architect
Job Description
π Role Details
β’ πΌ Title: Security & Identity Architect
β’ π Location: On-site in Dartford (TuesdayβThursday) | Remote (Monday & Friday by agreement)
β’ π Contract: 6 week contract (potential for extension)
β’ Rate: Β£800 / Per Day (Outside IR35)
π― Role Purpose
We are looking for an experienced Security & Identity Architect to drive the security design, governance, and assurance for a large-scale digital manufacturing capability on one of the UKβs most critical infrastructure programmes.
Working alongside Enterprise, Solution, Data, and Manufacturing Architects, you will ensure Cyber Security, Identity & Access Management (IAM), and Secure-by-Design principles are deeply integrated across both Enterprise IT and Operational Technology (OT) environments.
π Key Responsibilities
π‘οΈ Security Architecture & IAM Strategy
β’ Ecosystem Protection: Implement and embed robust security architecture across the entire Digital Manufacturing ecosystem.
β’ IAM Strategy: Lead the IAM approach across Enterprise IT, Operational Technology (OT), and shop-floor manufacturing systems.
β’ Secure HLD: Ensure Cyber Security and IAM principles are embedded throughout all High Level Design activities.
β’ Access Control & Lifecycle: Define RBAC, Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and user lifecycle models across all platforms.
β’ Federation & SSO: Support Single Sign-On (SSO) and identity federation across enterprise platforms and third-party partner environments.
π IT / OT Integration & Cloud Security
β’ Secure Integration: Secure APIs, machine identities, Industrial IoT (IIoT) devices, and data threads connecting SAP, PLM, MES, QMS, and Microsoft platforms.
β’ Network Segmentation: Enforce strict network zoning and IT/OT security principles (e.g., Purdue Model).
β’ Cloud & Zero Trust: Apply Zero Trust principles, least-privilege access, cloud security (Azure), and data encryption/classification standards.
ποΈ Governance, Risk & Assurance
β’ Architecture Assurance: Review and assure designs from internal teams, primary delivery partners and tech vendors.
β’ Governance Boards: Represent security and identity architecture at the Architecture Review Board (ARB).
β’ Compliance: Ensure all solutions comply with Enterprise IT security policies, nuclear requirements, and industry standards.
β’ Risk Management: Proactively identify programme security risks and define pragmatic mitigation strategies.
π¦ Key Deliverables
β’ π Security Architecture Input for the High Level Design (HLD)
β’ π Identity & Access Management (IAM) Recommendations & Artefacts
β’ π Security Architecture Assurance Reviews
β’ π‘οΈ Security Requirements Catalogue
β’ π¨ Programme Security Risk & Mitigation Log
β’ ποΈ Architecture Governance & ARB Submissions
π οΈ Required Experience & Technical Knowledge
πΌ Experience
β’ Enterprise & Solution Security Architecture within major digital transformation programmes
β’ Identity & Access Management (IAM) & Privileged Access Management (PAM)
β’ Operational Technology (OT) & Industrial Control Systems (ICS) security
β’ Cloud Security Architecture (Microsoft Azure preferred)
β’ Digital Manufacturing ecosystems (MES, PLM, Quality Systems, IIoT)
β’ Delivery Partner Management (assessing Tier-1 system integrators)
π Frameworks & Technologies
β’ Frameworks & Standards: ISA-95, Purdue Model, IEC 62443, NIST Cyber Security Framework, ISO 27001, CIS Controls, Zero Trust
β’ Technologies & Tools: Microsoft Entra ID, Microsoft Defender Suite, SAP Security, PLM Platforms, SAML / OAuth2 / OpenID Connect, Industrial IoT (IIoT)
π Personal Attributes
β’ Collaborative & Pragmatic: Balances strict cyber mandates with real-world project delivery deadlines.
β’ Clear Communicator: Explains complex technical risks effortlessly to both technical and executive stakeholders.
β’ Thrives in Ambiguity: Comfortable operating within fast-paced, multi-supplier transformation programmes.
β’ Constructive Challenge: Able to push back constructively on vendor designs while keeping delivery on track.
π Success Measures
β’ π― Design Integrity: Secure-by-Design and Identity-by-Design principles embedded across all workstreams by the end of the HLD phase.
β’ π« Risk Mitigation: Security flaws identified early to prevent expensive redesigns during full Digital Delivery.
β’ π Gap Identification: Clear documentation of programme-specific IAM and security gaps with defined mitigation paths.
β’ π Seamless Transition: A clear security assurance playbook ready to transition smoothly into implementation.
