IAM Architect - Infrastructure & Access Management
Job Description
Architect: Infrastructure & Access Management
\nThe Opportunity
\nOur client is a leading international law firm, recognised for representing the world's major corporations, funds, and financial institutions in their most complex transactions and disputes. We are looking for a talented and experienced Architect: Infrastructure & Access Management to join the firms IT department in London.
\nThis is a high-impact role at the heart of our global security and identity strategy, offering the chance to shape architecture at enterprise scale while collaborating with top-tier colleagues across regions.
\nWhat You'll Do
\nYou will lead the design and evolution of our Identity and Access Management (IAM) architecture across a complex, global environment. Key responsibilities include:
\n- \n
- Developing and maintaining IAM architecture covering identity lifecycle, access governance, and privileged access controls \n
- Designing secure authentication and authorisation patterns (OpenID Connect, SAML, OAuth, Kerberos, LDAP) and Conditional Access policies aligned with Microsoft best practices \n
- Embedding zero trust and least privilege principles across all privileged roles and enterprise applications \n
- Owning global firewall design and architecture \n
- Architecting and enhancing Privileged Access Management (PAM) capabilities, including approval workflows and continuous monitoring \n
- Championing Identity Threat Detection and Response (ITDR) solutions to proactively mitigate identity-based attacks \n
- Guiding the hardening of multi-site Active Directory domains/forests and cloud identity components (Entra/Azure AD) \n
- Collaborating with Security to design Azure Policies and guardrails supporting audit readiness (ISO 27001, ISO 22301) \n
- Integrating IAM with HR, IT, and engineering systems throughout the user lifecycle \n
- Staying ahead of emerging technologies including passwordless authentication, decentralised identity frameworks, and adaptive access controls \n
What We're Looking For
\nQualifications & Experience
\n- \n
- Proven background in IAM/identity engineering or architecture within large enterprise environments \n
- Prior global or large-scale enterprise experience preferred \n
- Microsoft Certified: Identity and Access Administrator Associate \n
- CISSP or equivalent \n
- Azure Cybersecurity Expert or Certified Identity and Access Manager (CIAM) \n
Technical Skills
\n- \n
- Deep expertise in Microsoft identity and security across SaaS/PaaS, IAM, and Privileged Access domains \n
- Advanced knowledge of Entra ID/Azure AD and on-premises Active Directory \n
- Strong command of SSO and authentication protocols: OpenID Connect, SAML, OAuth, Kerberos, LDAP \n
- Hands-on experience with RBAC design, entitlement management, and automated provisioning pipelines \n
- Proficiency with PowerShell and RESTful integrations for identity automation \n
- Familiarity with NDR, Micro-Segmentation, and network topology as they relate to IAM \n
- Experience with Azure Policy, landing zone guardrails, and Conditional Access at scale \n
