> Markdown version of [/jobs/ext/3089546-senior-identity-security-architect](https://www.wearedevelopers.com/jobs/ext/3089546-senior-identity-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Identity Security Architect - **Company:** Jones Lang Lasalle ("jll") - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cloud Engineering, Cyber Security, Software Design Patterns, Identity and Access Management, Intrusion Detection and Prevention, Kerberos (Protocol), Network Security, OAuth, OpenID, Open Web Application Security, Zero Trust Network Access, Secure Coding, Okta, Cyberark, Large Language Models, Multi-Agent Systems, Software Security, Mitre Att&ck, Customer Identity Access Management, Hardware Infrastructure, CIS Benchmarks - **Published:** September 26, 2026 - **Apply:** https://www.recruit.net/job/identity-security-architect-jobs/083856EDFC74BB5F ## About the Role If you're a strategic thinker with deep identity expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you., * Hands-on architectural experience with enterprise IdP platforms (Okta strongly preferred) and Privileged Access Management solutions (CyberArk strongly preferred). * Experience securing identity across M365, AWS/Azure, SaaS applications, and on-premises infrastructure. * Experience implementing Active Directory governance models that enforce security policy and compliance requirements, including hybrid AD/Entra ID sync architecture, delegation and privilege-escalation attack paths (e.g., resource-based constrained delegation, Kerberos delegation), and tiered administrative models. * Track record of partnering with threat management, insider threat, and incident response teams to design identity-aware detection capabilities. * Experience architecting identity for non-person and machine-to-machine access such as service accounts, workload identity, and OAuth delegation patterns (client credentials, on-behalf-of/token exchange) for service integrations and automation. Skills & Abilities * Comprehensive knowledge of zero trust architecture principles and enterprise identity design patterns, including federation, SSO, OAuth 2.0/OIDC, and PAM. * Strong command of security frameworks including NIST CSF, NIST 800-63, ISO 27001, and MITRE ATT&CK and CIS Controls v8, along with emerging OWASP guidance for AI/LLM and agentic systems (GenAI Security, LLM Top 10, AI Exchange) - and the ability to apply them practically, not just reference them. * Proven ability to develop sophisticated security architectures that address complex business requirements, regulatory obligations, and enterprise risk across multiple technology domains. * Exceptional communication and influencing skills - able to build alignment across engineering, product, and business stakeholders on complex architectural decisions. * Comfortable operating in ambiguity; able to define structure, set priorities, and drive progress in a fast-moving, high-change global environment. Education & Experience * 10+ years of technical cybersecurity experience, with at least 7 years focused on identity security architecture in large, complex enterprise environments. * Demonstrated success designing and maturing enterprise identity security programs - not just operating tools, but shaping strategy and standards at scale. ## Description Gain full access to exclusive job listings from leading companies worldwide. * Verified, High-Quality Jobs Only No ads, scams, or junk-just genuine opportunities. * Focus on Real Opportunities Explore thousands of open positions tailored to your lifestyle, including flexible remote jobs. * Exclusive Resume Review Receive expert feedback with personalized suggestions to enhance your resume., Identity Strategy & Architecture * Define and own JLL's enterprise identity security architecture spanning IdP services (Okta or Entra preferred), Active Directory, M365, cloud platforms (AWS/Azure), and third-party SaaS. * Ensuring a coherent, scalable, and secure design across the global technology estate. * Establish and maintain identity security policy and standards across users, non-person accounts, and on-premises, cloud, and SaaS platforms, in partnership with key identity stakeholders. * Partner with Identity Security, Engineering, and operations teams to develop to translate standards and patterns into actionable engineering and operational direction. * Lead JLL's zero trust strategy for user and third-party access in close partnership with the network security organization, driving architectural decisions that eliminate implicit trust across the environment. * Shape the architectural vision for Customer Identity and Access Management (CIAM) within JLL's externally-facing digital products, ensuring secure and seamless experiences for clients and partners. * Extend identity security architecture beyond the human user scope and into NHI landscapes for machine identity and service accounts including creation of AI, API, and other modern auth patterns and standards. Identity Governance & Administration * Architecture coverage for JLL's identity governance and administration strategy across different identity platforms, assisting in defining entitlement models, access certification and review cadence, and joiner/mover/leaver lifecycle standards and management. * Assist in defining segregation-of-duties and least-privilege policy for toxic-combination detection, and partner with application and platform owners to translate that policy into enforceable entitlement structures and operating models. Privileged Access Governance * Architect JLL's Privileged Access Management strategy, defining controls for privileged accounts that minimize abuse potential and enable robust detection of insider and external threats. * Provide strategic direction to engineering teams operating JLL's PAM tooling (CyberArk preferred), ensuring the platform evolves to meet emerging threat and business requirements. * Collaborate with cyber threat management and insider threat teams to embed identity-aware detection and response capabilities across the enterprise. Cross-Functional Leadership & Influence * Partner with Active Directory, authentication, and cloud engineering teams to translate security architecture into enforceable controls and compliant implementations. * Serve as the identity security subject matter expert on major programs, technology transformations, and acquisitions. Bring architectural clarity to complex, multi-stakeholder initiatives. * Lead security architecture reviews and design governance processes; mentor junior architects and security professionals across the team. * Communicate advanced security architecture strategies and design rationale clearly to diverse audiences from engineering teams to senior business stakeholders. Mentorship & Team Leadership * Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards. * Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams. * Support secure development training and awareness programs to build security competency across engineering organizations. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems](https://www.wearedevelopers.com/videos/928-break-the-chain-decentralized-solutions-for-today-s-web2-0-privacy-problems) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)