> Markdown version of [/jobs/ext/2107566-infrastructure-access-management-architect](https://www.wearedevelopers.com/jobs/ext/2107566-infrastructure-access-management-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure & Access Management Architect - **Company:** Mayer Brown LLP - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Systems Engineering, Authentication Protocols, Microsoft Azure, Biometrics, Software as a Service, Cyber Security, Multi-Factor Authentication, Network Topologies, Identity and Access Management, Intrusion Detection and Prevention, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Machine Learning, Network Segmentation, OAuth, Platform as a Service (PAAS), Windows PowerShell, Role-Based Access Control, Remote Access Technology, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), SSL Certificate Management, Enterprise Software Applications, Firewalls (Computer Science), Customer Identity Access Management, Information Technology, Restful APIs - **Published:** August 19, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/44482975/ ## About the Role IAM-related vulnerabilities and design timely mitigations. Establish and maintain reference architectures, design standards, runbooks, and documentation. Participate in vendor governance, roadmap reviews, and security notifications. Communicate architecture decisions to senior business and IT leaders; foster cross-regional collaboration. Track industry trends and recommend innovations to improve security and reduce complexity. Perform other duties as assigned or required to meet Firm goals and objectives. Qualifications, Experience and Personal Attributes Bachelor's degree in Computer Science, Information Technology, or related field; equivalent experience considered. Approx. 7-10 years in IAM/identity engineering/architecture within large or enterprise environments; 3+ years leading complex IAM design initiatives. Prior global/large-scale enterprise experience preferred. Relevant industry certifications such as CISSP. Microsoft Certified: Identity and Access Administrator Associate required. Azure Cybersecurity Expert preferred. Certified Identity and Access Manager (CIAM) are highly desirable. Technical Skills Deep expertise in Microsoft identity and security across SaaS/PaaS, IAM, and Privileged Access domains; advanced Entra ID/Azure AD and on-prem AD. Strong command of SSO and authentication protocols: OpenID Connect, SAML, OAuth, Kerberos, LDAP. Hands-on RBAC design, entitlement management, and automated provisioning/de-provisioning pipelines. Proficiency with PowerShell and RESTful integrations for identity automation and compliance checks. Familiarity with NDR and Micro-Segmentation patterns; understanding of network topologies and their interplay with IAM. Experience hardening infrastructure and monitoring for malware/unauthorized access in hybrid environments. Exposure to Azure Policy and landing zone guardrails; Conditional Access at scale. Performance Traits Excellent written and verbal communication; able to explain complex identity concepts to diverse audiences. Strong customer focus, initiative, and ability to operate under pressure with shifting priorities. Collaborative across business analysts, developers, data teams, and security; resilient, agile mindset; commitment to process improvement and structured operational practices. High discretion in handling sensitive information; willingness to challenge the status quo constructively. Willingness to challenge the status quo. #J-18808-Ljbffr ## Description the person we are seeking to join our IT department in our London office as an Architect: Infrastructure & Access Management. Responsibilities Stay current with emerging IAM technologies such as passwordless authentication, decentralized identity frameworks, and adaptive access controls. Collaborate with the Senior Architect Information Security and lead the implementation of identity governance automation, leveraging machine learning for anomaly detection and remediation. Ensure seamless integration of multi-factor authentication (MFA) with biometric and mobile device capabilities to improve both security and user experience. Champion the adoption of identity threat detection and response (ITDR) solutions to proactively identify and mitigate identity-based attacks. Develop and maintain the firm's IAM architecture, including identity lifecycle, access governance, and privileged access controls. Design secure authentication and authorization patterns (OpenID Connect, SAML, OAuth, Kerberos, LDAP) and in conjunction with the Platform Engineering team, Conditional Access policies aligned with Microsoft best practices. Embed zero trust and least privilege principles across all privileged roles and enterprise applications. Responsible for global firewall design and architecture. Architect and enhance privileged access management (PAM) capabilities, including approval workflows and continuous monitoring. Collaborate with Security to design Azure Policies and guardrails, supporting audit readiness and remediation (e.g., ISO 27001, ISO 22301). Integrate IAM with HR, IT, and engineering systems to ensure policy-driven access throughout the user lifecycle. Oversee Conditional Access deployment, risk-based authentication, and device/state signals. Guide the operation and hardening of multi-site Active Directory domains/forests and cloud identity components (Entra/Azure AD). Align IAM with Firewall, Micro-Segmentation, NDR, Remote Access, and Certificate Management strategies. Assess ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)