IAM Architect - Infrastructure & Access Management

Precise Placements
London, UK
6 days ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£106,000.0 - £116,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Active Directory Systems Engineering Authentication Protocols Microsoft Azure Software as a Service Encodings Cyber Security Network Topologies Identity and Access Management Intrusion Detection and Prevention Kerberos (Protocol)
+13 more
Lightweight Directory Access Protocols (LDAP) Network Segmentation OAuth Platform as a Service (PAAS) Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Systems Integration Enterprise Software Applications Customer Identity Access Management Restful APIs

Job description

  • Developing and maintaining IAM architecture covering identity lifecycle, access governance, and privileged access controls
  • Designing secure authentication and authorisation patterns (OpenID Connect, SAML, OAuth, Kerberos, LDAP) and Conditional Access policies aligned with Microsoft best practices
  • Embedding zero trust and least privilege principles across all privileged roles and enterprise applications
  • Owning global firewall design and architecture
  • Architecting and enhancing Privileged Access Management (PAM) capabilities, including approval workflows and continuous monitoring
  • Championing Identity Threat Detection and Response (ITDR) solutions to proactively mitigate identity-based attacks
  • Guiding the hardening of multi-site Active Directory domains/forests and cloud identity components (Entra/Azure AD)
  • Collaborating with Security to design Azure Policies and guardrails supporting audit readiness (ISO 27001, ISO 22301)
  • Integrating IAM with HR, IT, and engineering systems throughout the user lifecycle
  • Staying ahead of emerging technologies including passwordless authentication, decentralised identity frameworks, and adaptive access controls

Requirements

  • Proven background in IAM/identity engineering or architecture within large enterprise environments
  • Prior global or large-scale enterprise experience preferred
  • Microsoft Certified: Identity and Access Administrator Associate
  • CISSP or equivalent
  • Azure Cybersecurity Expert or Certified Identity and Access Manager (CIAM)

Technical Skills

  • Deep expertise in Microsoft identity and security across SaaS/PaaS, IAM, and Privileged Access domains
  • Advanced knowledge of Entra ID/Azure AD and on-premises Active Directory
  • Strong command of SSO and authentication protocols: OpenID Connect, SAML, OAuth, Kerberos, LDAP
  • Hands-on experience with RBAC design, entitlement management, and automated provisioning pipelines
  • Proficiency with PowerShell and RESTful integrations for identity automation
  • Familiarity with NDR, Micro-Segmentation, and network topology as they relate to IAM
  • Experience with Azure Policy, landing zone guardrails, and Conditional Access at scale

About the company

Our client is a leading international law firm, recognised for representing the world’s major corporations, funds, and financial institutions in their most complex transactions and disputes. We are looking for a talented and experienced Architect: Infrastructure & Access Management to join the firms IT department in London.

This is a high-impact role at the heart of our global security and identity strategy, offering the chance to shape architecture at enterprise scale while collaborating with top-tier colleagues across regions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · World Congress 2021

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all