Job Search

Applicant Login

Lead Identity Architect

Apply now Job no: 541788
Work type: Full Time
Location: Sydney, NSW
Categories: Information Technology, Cyber

  • Full time continuing role as a Lead Identity Architect within our Cyber Security directorate
  • Excellent salary package available
  • Kensington, Sydney location, 2-3 days in the office, Hybrid working

About UNSW:

UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It’s the reason we’re one of the top 20 universities in the world (QS top 20) and a member of Australia’s prestigious Group of Eight. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.

Lead Identity Architect

The Lead Identity Architect plays a pivotal role within the Enterprise Security Architecture team, responsible for positioning identity as a foundational security capability and business enabler across UNSW. This role is a thought leader in identity domain and champions identity as key differentiator for UNSW transformation.

This role works in close collaboration with the Enterprise Identity function to develop Identity Governance and Administration (IGA) framework establishing a strong identity foundation, enabling seamless onboarding, lifecycle management, access governance, and modern identity services including AI adoption across the organisation. The role translates enterprise security and identity strategy into practical, implementable identity architectures and patterns, ensuring consistent adoption of identity capabilities across programs, platforms, and applications.

Operating across architecture and delivery, the Lead Identity Architect partners with enterprise architects, solution architects, and the Enterprise Identity function to embed identity controls early in solution design, strengthen integration across systems, and uplift identity maturity aligned to Zero Trust principles and regulatory obligations. The role reports to the Principal Security Architect and has no direct reports.

Accountabilities

  • Shape and guide holistic IAM strategy, roadmap and framework, covering Users, Applications, Systems, Services (eg on-premise, hybrid, cloud), Enterprise Integrations and AI Identity.
  • Translate business and security requirements into scalable, secure and reusable identity architectures/standards/patterns. Ensure the IAM Standards, Guidelines are modified to meet changing requirements, including uplifting maturity.
  • Proactively collaborate with Programs, Projects and operational teams on proposed solution architecture (including HLD, architectures/standards/patterns. DSD), to ensure alignment with identity
  • Define, maintain and govern enterprise identity architecture including a target state, guiding principles, reference architectures/standards/patterns across the breadth of Identity and Access Management (IAM).
  • Develop and maintain IAM architectures/patterns covering capabilities such as identity lifecycle management, authentication, authorisation, federation, privileged access management, identity verification, and access re-certification.
  • Provide identity expertise in architecture review boards, design authorities and governance forums.
  • Be a strategic adviser to the Head of Enterprise Identity, CISO and internal/external forums on identity capability evolution, investment priorities.
  • Ensure IAM architectures/standards/patterns meet regulatory, privacy, and security requirements (including NIST, ISO 27001/31000/42001, PSPF/DISP, SOCI, PPIP, Privacy Act, GDPR).
  • Partner with the security team in delivering threat modelling, risk, and compliance audits.
  • Take ownership of advancing Enterprise Security Architecture maturity and associated artefacts.
  • Design and govern enterprise identity lifecycle patterns, including the joiner-mover-leaver (JML) processes for the different cohorts, as well as non-human identity. This includes cohorts such as staff, student, alumni, affiliates, partners, suppliers, third-party, customer and agentic identity.
  • Define and guide access control models (RBAC, ABAC, PBAC), segregation-of-duties (SoD) principals, and access re-certification policies.
  • Collaborate with Enterprise Identity, to ensure that all Identity Services are designed to be scalable, secure, and available.
  • Act as the Lead IAM technical authority in enterprise and application architecture reviews.

Who you are:

  • Significant experience (10+ years) working in identity, security or enterprise architecture roles within complex environments.
  • Relevant tertiary qualification in computer science, information security, information technology or related field. Or equivalent industry experience.
  • Demonstrated experience designing and governing enterprise-scale identity architectures within complex, federated or decentralised organisations.
  • Deep understanding of Security Principles: least privilege, defence-in-depth, zero trust etc including Agentic / Agent Identity security
  • Ability to embed identity as foundational controls aligned to the NIST Cybersecurity Framework, as well as ISO27001.
  • Extensive experience across core IAM domains, including Directory Services, Identity Governance and Administration (IGA), Authentication and Federation (SSO, MFA), Authorisation and Access Control Models (RBAC, ABAC, PBAC), Access Re-certification/Reviews, Privileged Access Management (Vaulting, JIT, JEA) and Identity Verification (IDV)
  • Practical experience with modern Identity-as-a-service (IDaaS) platforms such as Microsoft Entra ID, Entra External ID and Saviynt. As well as legacy technology such as Active Directory. Practical experience with cloud-identity/security (eg Azure, AWS, cross-cloud federation).
  • Strong AI exposure with understanding of Agentic Identity, including Model Context Procol (MCP), Agent-to-Agent (A2A), etc.
  • Strong understanding of passwords, multi-factor authentication (push, otp, passkeys, tap), federation, trusts, cryptography/certificates (public/PKI).
  • Familiarity with automation, DevSecOps approaches as applied to identity (eg IaC, CI/DC pipelines)
  • Any Industry certifications such as TOGAF, CISSP, CISA, SABSA and IAM Product Specific certifications relating to Saviynt IGA, Entra ID, or PAM.
  • Strong communication skills with ability to present to executives and technical teams.
  • Strategic thinker with ability to translate business needs into technical architecture.
  • Comprehensive written, verbal, analytical and problem-solving skills and proven capacity to exercise initiative, flexibility and to be proactive in development of robust solutions to problems.
  • Excellent time management skills, with a demonstrated ability to respond to changing priorities, manage multiple tasks and meet competing deadlines by using judgement and initiative.

Benefits and Culture

  • Flexible Working Options (work from home, flexible hours etc) 
  • Career development opportunities
  • 17% Superannuation contributions and additional leave loading payments 
  • Additional 3 days of leave over Christmas period
  • Discounts and entitlements (retail, education, fitness)

For further details on the benefits, please visit https://www.jobs.unsw.edu.au/lifestyle-benefits

How to Apply: please apply through the portal, we would like you to submit a full application including resume and addressing the who you are section.

Applications close:  Sunday 16th of August at 11.30pm

Pre-Employment Checks
Aligned with UNSW’s focus on cultivating a workplace defined by safety, ethical conduct, and strong integrity preferred candidates will be required to participate in a combination of pre-employment checks relevant to the role they have applied for.

These pre-employment checks may include a combination of some of the following checks:- 

  • National and International Criminal history checks
  • Entitlement to work and ID checks
  • Working With Children Checks
  • Completion of a Gender-Based Violence Prevention Declaration
  • Verification of relevant qualifications
  • Verification of relevant professional membership
  • Employment history and reference checks
  • Financial responsibility assessments/checks.
  • Medical Checks and Assessments

Compliance with the necessary combination of these checks is a condition of employment at UNSW.

Get in Touch:

Jen MacLachlan

j.maclachlan@unsw.edu.au

Talent Acquisition Partner – UNSW IT

Please apply through the application portal and not via the contact above.

UNSW is committed to equity diversity and inclusion. Applications from women, people of culturally and linguistically diverse backgrounds, those living with disabilities, members of the LGBTIQ+ community; and people of Aboriginal and Torres Strait Islander descent, are encouraged. UNSW provides workplace adjustments for people with disability, and access to flexible work options for eligible staff. The University reserves the right not to proceed with any appointment.

Position Description

Advertised: AUS Eastern Standard Time
Applications close: AUS Eastern Standard Time

Back to search results Apply now Refer a friend

Job Search

Refine Search

Careers at UNSW for Indigenous Australians

Apply now for a career at UNSW to grow in an environment that values and uplifts you.