IT & Software

Infrastructure & Access Management Architect

Mayer Brown

London · Greater London · United Kingdom

Overview

As Architect: Infrastructure & Access Management, you will lead IAM strategy and implementation to secure Mayer Brown’s global operations. You’ll work with cross-functional teams to design and automate identity governance, integrate MFA with biometrics, and apply zero-trust principles. The role supports the Firm’s security posture while enabling seamless user experiences across platforms. You will collaborate with regional teams and senior leaders to drive innovative, compliant identity solutions in a demanding legal environment. This is a hybrid, globally scoped role with potential off-hours collaboration.

Responsibilities
  • Stay current with IAM technologies and lead the implementation of identity governance automation with ML-based anomaly detection.
  • Integrate MFA with biometric and mobile device capabilities to balance security and user experience.
  • Champion ITDR solutions to proactively identify and mitigate identity-based threats.
  • Develop and maintain IAM architecture, including identity lifecycle, access governance, and privileged access controls.
  • Design secure authentication/authorization patterns and implement Conditional Access policies with Microsoft best practices.
  • Embed zero-trust and least privilege across privileged roles and enterprise applications.
  • Oversee global firewall design and architecture; enhance PAM capabilities with workflows and monitoring.
  • Collaborate on Azure Policy and guardrails; support audit readiness (ISO 27001, ISO 22301).
  • Integrate IAM with HR, IT, and engineering systems for policy-driven access throughout the user lifecycle.
  • Oversee Conditional Access deployment, risk-based authentication, and device/state signals.
  • Guide operation of multi-site AD domains/forests and cloud identity components (Entra/Azure AD).
  • Align IAM with Firewall, Micro-Segmentation, NDR, Remote Access, and Certificate Management.
  • Assess IAM vulnerabilities and implement timely mitigations.
  • Create and maintain reference architectures, runbooks, and documentation; participate in vendor governance and roadmap reviews.
  • Communicate architecture decisions to senior business and IT leaders; foster cross-regional collaboration.
  • Track industry trends and propose innovations to improve security and reduce complexity.
  • Perform other duties as assigned to meet Firm goals.
Key requirements
  • Significant IAM/identity engineering/architecture experience in large or enterprise environments; 3+ years leading IAM design initiatives.
  • CISSP and Microsoft Certified: Identity and Access Administrator Associate required.
  • Azure Cybersecurity Expert preferred; CIAM highly desirable.
  • Deep expertise in Microsoft identity/security across SaaS/PaaS, IAM, and Privileged Access; advanced Entra ID/Azure AD and on-prem AD.
  • Strong command of SSO and authentication protocols: OpenID Connect, SAML, OAuth, Kerberos, LDAP.
  • Hands-on RBAC design, entitlement management, and automated provisioning/de-provisioning pipelines.
  • PowerShell and RESTful integrations for identity automation and compliance checks.
  • Experience with NDR and Micro-Segmentation patterns; knowledge of network topologies and IAM interplay.
  • Ability to harden infrastructure and monitor for malware/unauthorized access in hybrid environments.
  • Exposure to Azure Policy and landing zone guardrails; scale of Conditional Access.
  • Excellent written and verbal communication
  • Customer focus and initiative
  • Ability to operate under pressure with shifting priorities
  • Identity and access management architecture
  • OpenID Connect, SAML, OAuth, Kerberos, LDAP
  • Entra/Azure AD and on-prem AD

Reference: WJ-747_30201562

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.