Lead Service Architect
- Posted 20 July 2026
- LocationSheffield
- Job type Contract
- Discipline Technology
Job description
Key responsibilities
Design the end-to-end service architecture for infrastructure access and privileged access.
Define the target service model, including processes, roles, controls, data flows, integrations, and operational hand-offs.
Create a risk-based access model that sets the access pattern, approval route, monitoring level, and review frequency.
Define patterns for standing access, time-bound access, just-in-time access, emergency access, third-party access, cloud access, and privileged administration.
Define how identity, application, infrastructure, entitlement, account, risk, and control data are used in access decisions.
Identify trusted data sources, data owners, data quality rules, and exception handling.
Design controls for least privilege, authorised access, traceability, monitoring, timely removal, access reviews, and audit evidence.
Define how evidence is produced through workflows, logs, approvals, access records, and session records.
Identify current-state gaps and define steps to move to the target service.
Work with IAM, PAM, infrastructure, cloud, application, cyber security, risk, audit, service management, and engineering teams.
Challenge access processes that are inconsistent, too manual, poorly owned, or designed around individual tools.
Key deliverables
The role will produce:
Service blueprint and privileged access service model
Access pattern catalogue and risk-based decision model
Process maps, RACI, and ownership model
Metadata, data, control, and evidence models
Integration architecture and operating model
Exception, break-glass, and onboarding designs
Reporting requirements and transition roadmap
Experience and capability
Candidates should have experience in several of the following areas:
Service architecture or service design in a large organisation.
IAM, PAM, infrastructure access, or security architecture.
Designing services across people, process, technology, data, and controls.
Risk-based access models and control design.
Infrastructure platforms, including servers, databases, cloud platforms, network devices, containers, and administrative tooling.
Using data from identity systems, application inventories, CMDBs, infrastructure inventories, entitlement stores, or control platforms.
Designing access request, approval, fulfilment, monitoring, review, revocation, and exception processes.
Working in regulated, audited, or control-heavy environments.
