About the Role
The Lead Identity Architect plays a pivotal role within the Enterprise Security Architecture team, responsible for positioning identity as a foundational security capability and business enabler across UNSW. This role is a thought leader in the identity domain and champions identity as a key differentiator for UNSW transformation.
Responsibilities
- Shape and guide holistic IAM strategy, roadmap and framework, covering Users, Applications, Systems, Services (eg on-premise, hybrid, cloud), Enterprise Integrations and AI Identity.
- Translate business and security requirements into scalable, secure and reusable identity architectures/standards/patterns. Ensure the IAM Standards, Guidelines are modified to meet changing requirements, including uplifting maturity.
- Proactively collaborate with Programs, Projects and operational teams on proposed solution architecture (including HLD, DSD), to ensure alignment with identity architectures/standards/patterns.
- Define, maintain and govern enterprise identity architecture including a target state, guiding principles, reference architectures/standards/patterns across the breadth of Identity and Access Management (IAM).
- Develop and maintain IAM architectures/patterns covering capabilities such as identity lifecycle management, authentication, authorisation, federation, privileged access management, identity verification, and access re-certification.
- Provide identity expertise in architecture review boards, design authorities and governance forums.
- Be a strategic adviser to the Head of Enterprise Identity, CISO and internal/external forums on identity capability evolution, investment priorities.
- Ensure IAM architectures/standards/patterns meet regulatory, privacy, and security requirements (including NIST, ISO 27001/31000/42001, PSPF/DISP, SOCI, PPIP, Privacy Act, GDPR).
- Partner with the security team in delivering threat modelling, risk, and compliance audits.
- Take ownership of advancing Enterprise Security Architecture maturity and associated artefacts.
- Design and govern enterprise identity lifecycle patterns, including the joiner-mover-leaver (JML) processes for the different cohorts, as well as non-human identity. This includes cohorts such as staff, student, alumni, affiliates, partners, suppliers, third-party, customer and agentic identity.
- Define and guide access control models (RBAC, ABAC, PBAC), segregation-of-duties (SoD) principals, and access re-certification policies.
- Collaborate with Enterprise Identity, to ensure that all Identity Services are designed to be scalable, secure, and available.
- Act as the Lead IAM technical authority in enterprise and application architecture reviews.
Requirements
- Significant experience (10+ years) working in identity, security or enterprise architecture roles within complex environments.
- Demonstrated experience designing and governing enterprise-scale identity architectures within complex, federated or decentralised organisations.
- Deep understanding of Security Principles: least privilege, defence-in-depth, zero trust etc including Agentic / Agent Identity security
- Ability to embed identity as foundational controls aligned to the NIST Cybersecurity Framework, as well as ISO27001.
- Extensive experience across core IAM domains, including Directory Services, Identity Governance and Administration (IGA), Authentication and Federation (SSO, MFA), Authorisation and Access Control Models (RBAC, ABAC, PBAC), Access Re-certification/Reviews, Privileged Access Management (Vaulting, JIT, JEA) and Identity Verification (IDV)
- Practical experience with modern Identity-as-a-service (IDaaS) platforms such as Microsoft Entra ID, Entra External ID and Saviynt. As well as legacy technology such as Active Directory. Practical experience with cloud-identity/security (eg Azure, AWS, cross-cloud federation).
- Strong AI exposure with understanding of Agentic Identity, including Model Context Procol (MCP), Agent-to-Agent (A2A), etc.
- Strong understanding of passwords, multi-factor authentication (push, otp, passkeys, tap), federation, trusts, cryptography/certificates (public/PKI).
- Familiarity with automation, DevSecOps approaches as applied to identity (eg IaC, CI/DC pipelines)
- Strong communication skills with ability to present to executives and technical teams.
- Strategic thinker with ability to translate business needs into technical architecture.
- Comprehensive written, verbal, analytical and problem-solving skills and proven capacity to exercise initiative, flexibility and to be proactive in development of robust solutions to problems.
- Excellent time management skills, with a demonstrated ability to respond to changing priorities, manage multiple tasks and meet competing deadlines by using judgement and initiative.
Skills
- Identity Governance and Administration (IGA)
- Authentication and Federation (SSO, MFA)
- Authorisation and Access Control Models (RBAC, ABAC, PBAC)
- Access Re-certification/Reviews
- Privileged Access Management (Vaulting, JIT, JEA)
- Identity Verification (IDV)
- Microsoft Entra ID
- Entra External ID
- Saviynt
- Active Directory
- Azure
- AWS
- Agentic Identity
- Model Context Procol (MCP)
- Agent-to-Agent (A2A)
- NIST Cybersecurity Framework
- ISO27001
- TOGAF
- CISSP
- CISA
- SABSA
- Automation
- DevSecOps
- IaC
- CI/DC pipelines
Location
- Kensington, Sydney
Work Type
- Full time
- Hybrid
Experience Level
- 10+ years
Education Level
- Relevant tertiary qualification in computer science, information security, information technology or related field. Or equivalent industry experience.
Salary/Compensations
- Excellent salary package available
Benefits
- Flexible Working Options (work from home, flexible hours etc)
- Career development opportunities
- 17% Superannuation contributions and additional leave loading payments
- Additional 3 days of leave over Christmas period
- Discounts and entitlements (retail, education, fitness)
About the Company
- UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It’s the reason we’re one of the top 20 universities in the world (QS top 20) and a member of Australia’s prestigious Group of Eight. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.
Equal Opportunity
- UNSW is committed to equity diversity and inclusion. Applications from women, people of culturally and linguistically diverse backgrounds, those living with disabilities, members of the LGBTIQ+ community; and people of Aboriginal and Torres Strait Islander descent, are encouraged. UNSW provides workplace adjustments for people with disability, and access to flexible work options for eligible staff. The University reserves the right not to proceed with any appointment.
