Now hiring

Security Architect (Agentic Identity & Access) @ Intellias

GBOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £46,000 - 50,000 per year

Requirements: 8+ years in security architecture and/or platform engineering, with a track record of shipping production codePrincipal-level depth, ideally in a high-velocity or quant / financial-services engineering cultureDeep command of modern identity and authorisation: OIDC / OAuth2 / JWT, including token issuance flows, claims design, and delegation / impersonation patternsHands-on HashiCorp Vault experience, including dynamic / short-lived secrets and migrating away from long-lived tokens across a large application estateKeycloak policy modelling experience, ideally with Terraform-driven configurationStrong Terraform / IaC fluency to design repeatable, self-service patternsWorking knowledge of Active Directory + Entra legacy environments, including nested groups, LDAP-backed role mapping, and distribution-list-as-permission-group issuesExperience leading engineers, including near-shore or distributed teams, with responsibility for technical direction, reviews, and unblocking deliveryCredible in front of clients, able to run working sessions and explain security trade-offs to non-specialist audiencesSelf-starter mentality, able to take vague problems, find answers, and turn them into actionable plansNice to have: exposure to agentic / LLM systems and the associated threat modelNice to have: familiarity with MCP as an integration / onboarding standard and at least one agent harnessNice to have: experience with just-in-time, task-scoped delegation and risk-gated credential issuanceNice to have: behavioural baselining / anomaly detection for workloadsNice to have: SIEM integration and action attribution for agentic workflowsNice to have: financial-services audit literacyNice to have: pre-sales or bid-support experience Responsibilities: Design and ship IaC-driven, self-service identity patterns that can roll out firm-wide without requiring a full Active Directory cleanup firstDefine the agentic runtime security model, including containerised code execution, permission delegation to agents, and MCP-based tool accessLead the transition from long-lived secrets to ephemeral, time-based, risk-scored credentials scoped to task duration and issued via JWT / OIDCLayer LLM and software guardrails on top of feasible hard guardrails across the estateEstablish opinionated onboarding standards, such as mandatory MCP interfaces, and drive adoption through better defaults and developer experienceDesign SIEM integration, behavioural baselining, and anomaly detection for agentic workflows, and centralise audit logs for security and regulatory needsTake bounded beachheads from vague ideas to delivered solutions, including scoped access delegation from authenticated users to internal systemsLead the near-shore engineering team, setting technical direction, reviewing designs and code, and building depth in identity and agentic securityAct as the senior technical voice with the client, running design sessions, presenting options and trade-offs, and translating ambiguous requests into delivered work Technologies: AIActive DirectoryIAMSupportJWTLDAPLLMMachine LearningMCPQuantSecurityTerraformAgentic AIArchitect More:

We are a leading global investment management company headquartered in London, managing over $228 billion in assets and serving institutional investors, pension funds, wealth managers, and other sophisticated clients worldwide. We specialise in quantitative investing, alternative investments, systematic trading strategies, and technology-driven asset management, with data science, machine learning, and AI at the core of our investment and research processes. This role focuses on building the foundational capabilities needed for safe and scalable AI adoption across the enterprise, especially Agentic Security and AI-Ready Data Foundations. It is a hands-on principal-level position at the intersection of enterprise IAM, platform engineering, and agentic-AI security, with real technical ownership in a heavily regulated financial environment.

last updated 33 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores