Senior API

5 days ago

Brentford, ENG, United Kingdom Shivom Consultancy Ltd Remote Full-time
Senior API & Integration Architect – Azure API Management

Location:
UK-based – Hybrid working with occasional travel to Shivom offices and client locations Employment Type: Permanent, Full-Time

Salary:
£75,000–£90,000 per annum, depending on experience Security Clearance: Current SC clearance or eligibility to obtain SC clearance

About the Role
Shivom Consultancy Ltd is looking for an experienced Senior API & Integration Architect – Azure API Management & API Marketplace to join our growing Architecture Practice. You will provide architecture leadership for enterprise API platforms, API marketplaces and modern integration services, with a strong focus on Microsoft Azure API Management (APIM), API lifecycle management, API governance, secure API exposure and reusable integration patterns. The role focuses on how organisations publish, discover, govern and consume APIs across multiple products, platforms and delivery teams while enabling secure integration with internal systems, external partners and third-party services. You will help shape and evolve enterprise API capabilities, establish standards and reusable patterns, improve developer and consumer experience, and reduce reliance on brittle point-to-point, email and file-based integrations where APIs, messaging or event-driven approaches are more appropriate. You will work closely with Enterprise Architects, Solution Architects, Product teams, Engineers, Security Specialists, Identity teams, Platform teams, Data teams and technology suppliers. The role will support major UK public sector and enterprise transformation programmes within Shivom's client portfolio.

Key Responsibilities
You will:
- Lead solution architecture for enterprise API platforms and API marketplace capabilities.
- Define current, target and transition architectures for API management and enterprise integration.
- Architect and evolve Azure API Management as a secure, scalable and reusable enterprise capability.
- Define architecture for API publishing, discovery, onboarding, consumption and lifecycle management.
- Shape enterprise API marketplace and catalogue capabilities.
- Establish API governance standards covering design, versioning, security, documentation, ownership and deprecation.
- Define reusable API patterns and standards across multiple delivery teams.
- Design internal, external and partner-facing APIs.
- Define developer portal and API consumer onboarding approaches.
- Define secure API exposure patterns for internal and external consumers.
- Architect authentication and authorisation using OAuth 2.0, OpenID Connect, JWT, Client Credentials and Microsoft Entra ID.
- Define API gateway policies including throttling, rate limiting, quotas, request validation, transformation and security controls.
- Design API gateway and routing patterns.
- Define API versioning and backward compatibility approaches.
- Architect synchronous and asynchronous integration patterns.
- Design messaging and event-driven integrations using Azure integration services.
- Define secure and reusable connectivity patterns across enterprise integration platforms.
- Assess point-to-point, file-based and batch integrations and identify opportunities for modernisation.
- Define transition strategies from legacy integration towards APIs, messaging and event-driven services.
- Develop High-Level Designs, solution visions, options assessments and architecture roadmaps.
- Define non-functional requirements covering availability, resilience, performance, scalability, security, observability and supportability.
- Define monitoring, logging, tracing and analytics requirements.
- Work with engineering teams to translate architecture into implementable solutions.
- Review detailed technical designs and implementation approaches.
- Identify architectural risks, dependencies and technical debt.
- Present architecture decisions through technical governance and design authority forums.
- Support proofs of concept, platform evaluations and technical feasibility exercises.
- Promote repeatable engineering through CI/CD, Infrastructure as Code and automated configuration.
- Contribute to architecture peer reviews and continuous improvement. Essential Experience & Skills We are looking for strong experience across most of the following:
- Significant experience as an API Architect, Integration Architect, Solution Architect or Technical Architect within complex enterprise environments.
- Strong architecture experience with Microsoft Azure API Management.
- Experience designing and governing enterprise API platforms.
- Experience designing or evolving an API Marketplace, API Catalogue or Developer Portal.
- Strong understanding of API lifecycle management.
- Strong understanding of REST API design principles.
- Experience defining and enforcing API standards across multiple delivery teams.
- Experience with OpenAPI specifications and API documentation.
- Strong understanding of API security.
- Experience with OAuth 2.0, OpenID Connect, JWT and Client Credentials.
- Experience integrating API platforms with Microsoft Entra ID.
- Experience defining API gateway policies including throttling, quotas, rate limiting and request validation.
- Experience with internal, external and partner-facing APIs.
- Experience onboarding API producers and consumers.
- Strong understanding of synchronous and asynchronous integration patterns.
- Experience architecting Azure-based messaging and integration services.
- Experience with Azure Service Bus or similar enterprise messaging technologies.
- Understanding of event-driven architecture.
- Experience integrating cloud, SaaS, COTS and legacy platforms.
- Experience modernising legacy integration estates.
- Experience designing integration across multiple product teams, applications or organisational boundaries.
- Strong understanding of resilience, retries, idempotency, failure handling and recovery patterns.
- Experience designing monitoring and observability for APIs and distributed integrations.
- Experience producing HLDs, options assessments, roadmaps, sequence diagrams, integration diagrams and technical decisions.
- Experience working within architecture governance, technical review or design authority processes.
- Experience working across multiple delivery teams and technology suppliers.
- Good understanding of Agile and product-based delivery.
- Strong stakeholder management and communication skills.
- Ability to make pragmatic architecture decisions balancing strategic direction, delivery requirements, legacy constraints and operational considerations. Azure API Management Azure API Management is a key part of this role. You should have strong practical architecture knowledge across:
- Azure API Management
- API gateways
- API products and subscriptions
- Developer portals
- API policies
- Named values
- Authentication and authorisation
- OAuth 2.0
- OpenID Connect
- JWT validation
- Client Credentials
- Certificates and Managed Identities
- Rate limiting, throttling and quotas
- Request and response transformation
- IP filtering
- Backend routing
- API versioning and revisions
- Internal and external API exposure
- Private connectivity and network integration
- Monitoring and analytics
- Operational resilience
- High availability and scaling You should be able to define APIM as an enterprise platform capability, rather than simply configuring individual APIs. API Marketplace & Developer Experience An important part of the role is making APIs easy to discover, understand and reuse. You should understand how to design and evolve enterprise API marketplaces or catalogues covering:
- API discovery and search
- API ownership and classification
- API documentation
- OpenAPI specifications
- Developer onboarding
- Consumer registration
- Access requests
- Subscription management
- API usage guidance
- Reusable examples and patterns
- API lifecycle status
- Versioning and deprecation
- Support and ownership models
- Internal and external developer experience
- Governance and assurance You should be able to balance effective enterprise governance with a developer experience that enables product teams to publish and consume APIs efficiently. API Governance & Lifecycle Management You should be comfortable defining standards across:
- API design
- Naming conventions
- Resource modelling
- Versioning
- Error handling
- Security
- Documentation
- Ownership and reuse
- Lifecycle states
- Deprecation and retirement
- Backward compatibility
- Consumer impact
- Governance checkpoints
- Architecture assurance
- API quality The objective is to create consistent, secure and reusable APIs without introducing unnecessary governance overhead. Messaging & Event-Driven Integration Although API architecture is the primary focus, you should understand when asynchronous integration is more appropriate. Relevant experience includes:
- Azure Service Bus
- Queues and Topics
- Publish/Subscribe
- Event-driven architecture
- Dead-letter queues
- Retry and backoff
- Message ordering
- Duplicate handling
- Idempotency
- Correlation
- Message schemas
- Eventual consistency
- Failure recovery
- Azure Event Grid
- Azure Event Hubs
- Azure Functions You should be able to determine when a REST API, message, event or batch process is the appropriate integration pattern. Legacy & Transitional Integration You should understand transitional integration technologies and patterns including:
- Managed File Transfer
- SFTP
- Secure file exchange
- Batch integration
- Scheduled transfers
- Point-to-point interfaces
- File-based exchange
- Reconciliation
- Failure and retry handling Deep Managed File Transfer expertise is not required. You should, however, be capable of defining realistic migration paths towards governed APIs, messaging and event-driven integration where these provide greater resilience, maintainability and reuse. Technology Experience Candidates do not need deep expertise in every technology listed below. We are looking for strong depth in Azure API Management and enterprise API architecture, combined with broader Azure integration, security, engineering and operational knowledge. Microsoft Azure Relevant experience may include:
- Microsoft Azure
- Azure API Management
- Azure Service Bus
- Azure Event Grid
- Azure Event Hubs
- Azure Functions
- Azure Logic Apps
- Azure Storage
- Azure Key Vault
- Microsoft Entra ID
- Managed Identities
- Azure Virtual Networks
- Private Endpoints
- Azure Monitor
- Application Insights
- Log Analytics API Technologies & Standards
- REST
- JSON and XML
- OpenAPI/Swagger
- OAuth 2.0
- OpenID Connect
- JWT
- Webhooks
- API gateways
- API catalogues
- Developer portals
- API security
- API testing
- API analytics Engineering & Deployment Modern API platforms should be delivered and operated using repeatable engineering practices. Relevant knowledge includes:
- Azure DevOps
- GitHub
- CI/CD
- Source control
- API definition as code
- Infrastructure as Code
- Terraform
- Bicep
- Automated APIM deployment
- Automated policy deployment
- Environment promotion
- API and contract testing
- Release management
- Configuration management You do not need to operate as a DevOps Engineer but should understand how to define architecture and delivery patterns that enable API and integration platforms to be deployed consistently and safely. Monitoring & Observability APIs and integration services should be observable by design. Relevant experience includes:
- Azure Monitor
- Application Insights
- Log Analytics
- Dynatrace
- Grafana
- API analytics
- Distributed tracing
- Correlation IDs
- Centralised logging
- API performance monitoring
- Dependency monitoring
- Message and queue monitoring
- Operational dashboards
- Alerting
- Failure monitoring
- Capacity monitoring Security Architecture You should have a good understanding of:
- Microsoft Entra ID
- OAuth 2.0 and OpenID Connect
- JWT
- Client Credentials
- Managed Identities
- Certificate-based authentication
- Secrets management
- Azure Key Vault
- API gateway security
- Private connectivity
- Network segmentation
- Encryption
- Least privilege
- Zero Trust principles
- Audit and traceability
- Data protection
- External consumer security Security should be built into API and integration architecture from the outset. Desirable Experience It would be advantageous to have:
- Deep Azure API Management architecture experience.
- Experience establishing or evolving large enterprise API platforms.
- Experience designing or implementing enterprise API Marketplaces or catalogues.
- Experience governing APIs across multiple product or engineering teams.
- Experience managing internal and external API consumers.
- Developer portal and API onboarding experience.
- Strong Azure Service Bus architecture experience.
- Event-driven integration experience.
- Experience modernising file-based or point-to-point integrations.
- Experience integrating commercial SaaS or COTS platforms.
- Experience integrating services across organisational boundaries.
- GitHub or Azure DevOps-based API delivery experience.
- Terraform or Bicep experience.
- Azure Monitor, Application Insights, Log Analytics, Dynatrace or Grafana experience.
- Experience within UK central government, healthcare, financial services, defence, policing or another regulated environment.
- Experience delivering large-scale or business-critical digital services.
- Experience handling sensitive or regulated information.
- Experience within complex multi-supplier environments.
- Existing SC security clearance. Relevant Microsoft Azure architecture/developer or TOGAF certifications are desirable but not mandatory where equivalent practical experience can be demonstrated. What Success Looks Like You will be successful when you can:
- Understand complex API and integration landscapes quickly.
- Define clear API architecture direction and realistic transition roadmaps.
- Establish Azure API Management as a reusable enterprise capability.
- Improve API discoverability and reuse through marketplace and catalogue capabilities.
- Establish standards that improve consistency without unnecessary bureaucracy.
- Enable engineering teams to publish secure, high-quality APIs.
- Enable consumers to easily discover, understand and access existing APIs.
- Determine when APIs, messaging, events or transitional integration approaches are most appropriate.
- Reduce unnecessary point-to-point and file-based integration.
- Design secure APIs for internal and external consumers.
- Build monitoring, traceability and failure handling into solutions from the outset.
- Produce architecture that engineering teams can practically implement.
- Influence multiple delivery teams and build strong relationships with product teams, engineers, security specialists, suppliers and senior stakeholders. Security Clearance Applicants must either hold current Security Check (SC) clearance or be eligible to obtain SC clearance. Candidates without existing clearance must be willing to complete the required security vetting process as a condition of appointment. Successful candidates will be expected to comply with applicable client and government security policies when working with sensitive information or systems. Working Arrangements This is a UK-based hybrid role. You should be comfortable working remotely while also attending Shivom offices, client locations and other UK sites where collaboration, delivery activities or security requirements make in-person attendance appropriate. On-site attendance may vary depending on the nature and stage of individual assignments. Benefits Our benefits package includes:
- Private medical insurance
- Critical illness cover
- Employer pension contribution
- Generous annual leave plus UK bank holidays
- Hybrid and flexible working arrangements, subject to client requirements
- Support for professional certifications and technical training
- Continuous professional development opportunities
- Access to architecture, cloud, integration, security, data and engineering learning opportunities
- Support for maintaining and progressing professional and security clearances
- Career progression within Shivom's Architecture and Technology Leadership Practice
- Opportunities to work on major UK public sector and enterprise transformation programmes
- Regular knowledge-sharing sessions, technical forums and architecture communities of practice
- Employee wellbeing support
- Company-sponsored social and team events
- Employee referral opportunities
- Recognition and performance-related reward opportunities About Shivom Consultancy Ltd Shivom Consultancy Ltd is a UK-based technology consultancy specialising in architecture, cloud, data, security, software engineering and digital transformation. We work with organisations delivering complex and business-critical technology services, helping them modernise legacy estates, adopt cloud and digital platforms, strengthen cyber security and build secure, resilient and scalable technology capabilities. Our Architecture Practice focuses on practical architecture that connects strategy with engineering. Our architects remain close to delivery, understand the operational impact of their decisions and help teams make sustainable technology choices. You will join a growing architecture community with opportunities to work across APIs, integration, cloud, data, identity, security, automation and digital services. Why Join Shivom? You will have the opportunity to shape enterprise API capabilities across complex organisations while developing your career within a growing Architecture Practice. You will work at the intersection of Azure API Management, API marketplaces, enterprise integration, API governance, security and modern engineering, helping organisations move from fragmented interfaces towards reusable, discoverable and well-governed enterprise capabilities. Equal Opportunities Shivom Consultancy Ltd is committed to creating an inclusive and supportive working environment. We welcome applications from suitably qualified candidates regardless of age, disability, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sex or sexual orientation. Reasonable adjustments can be provided throughout the recruitment process where required. Pay: £75,000.00-£90,000.00 per year

Benefits:
- Health & wellbeing programme
- Private medical insurance Work

Location:
Hybrid remote in Brentford TW8 9ES