Haystack
← Back to Jobs
Full time
Other
IT

Lead IAM Architect

Infoplus Technologies UK LtdScotland🇬🇧United KingdomPosted 22 Sept 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Scotland, United Kingdom
MFASAMLActive DirectoryAzureOnboarding

Job Description

Client: MASTEK

Role: Permanent

Salary: 80K GBP Per Annum (incl 10% variable)

Location: Scotland (once or twice a month)

Key expectations

  • Lead MFA and SailPoint discovery and design.
  • Create one joined-up IAM architecture across Microsoft Entra, MFA, Microsoft Authenticator, FIDO2 tokens, Active Directory, F5/Legacy access routes, SailPoint ISC and Application A.
  • Define the MFA target design, including policy, authentication methods, exceptions, privileged users, recovery and operational controls.
  • Define the SailPoint target design for Application onboarding, including AD groups, RBAC, Access Profiles, roles, workflows and approvals.
  • Ensure the MFA and SailPoint designs work together and do not create conflicting AD-group, access-governance or privileged-access models.
  • Model and implement risk based authentication policies in Azure Entra.
  • Lead technical workshops and document architecture decisions.
  • Produce technical design documentation and maintain the design-decision log.
  • Support Design Authority approval.
  • Provide targeted technical assurance during implementation, resolving complex decisions and reviewing significant deviations from design.
  • Support RFC, CAB, security assurance, implementation planning, rollback planning and technical handover where required.
  • Be hands on in implementing MFA entra, policies, application onboarding and others.

Minimum experience

  • 10+ years in IAM, identity architecture, cyber security or enterprise security architecture.
  • 5+ years designing and delivering Microsoft Entra ID/Azure AD identity, MFA and Conditional Access solutions in enterprise or public-sector-scale environments.
  • Proven experience of Microsoft Authenticator, FIDO2 security keys/passkeys, authentication-method policy, privileged access and emergency-access design.
  • 3+ years of hands-on SailPoint Identity Security Cloud architecture or implementation experience, including access profiles, roles, workflows, life cycle controls and access governance.
  • Demonstrable Active Directory and hybrid identity experience, including AD groups, group-based authorisation, provisioning and Legacy/on-premise integration.
  • Experience of Legacy/hybrid application patterns, including Kerberos, SAML/OIDC, F5/reverse Proxy or application Proxy, Windows-integrated applications and on-premise estates.
  • Experience preparing and defending technical designs through formal Design Authority, cyber-security assurance or CAB governance.

Similar jobs