
Senior Identity Security Architect
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Spain.
• Define and take ownership of JLL's enterprise identity security architecture encompassing IdP services, Active Directory, M365, cloud platforms, and third-party SaaS.
• Establish and uphold identity security policies and standards applicable to user, non-person, on-premises, cloud, and SaaS identities.
• Collaborate with identity security, engineering, and operations teams to convert standards into actionable engineering and operational guidelines.
• Spearhead JLL's zero trust strategy pertaining to user and third-party access.
• Shape the architecture for Customer Identity and Access Management for externally facing digital products.
• Expand the identity security architecture to include machine identities, service accounts, AI, APIs, and contemporary authentication patterns.
• Define strategies for identity governance and administration, entitlement models, access certification cadence, and standards for joiners, movers, and leavers.
• Establish segregation-of-duties and least-privilege policies, converting them into enforceable entitlement structures.
• Architect JLL's Privileged Access Management strategy and provide guidance for PAM tools.
• Collaborate with threat management and insider threat teams to enhance identity-aware detection and response.
• Partner with Active Directory, authentication, and cloud engineering teams to implement robust security controls.
• Act as the identity security subject matter expert for significant programs, transformations, and acquisitions.
• Lead security architecture reviews and design governance processes.
• Mentor junior architects, engineers, developers, and security professionals.
• Direct cross-functional security initiatives and support secure development training and awareness programs.
• Over 10 years of technical cybersecurity experience.
• At least 7 years dedicated to identity security architecture within large, complex enterprise environments.
• Practical architectural experience with enterprise IdP platforms, particularly Okta.
• Proficient in Privileged Access Management solutions, especially CyberArk.
• Experience in securing identity across M365, AWS/Azure, SaaS applications, and on-premises infrastructure.
• Familiarity with implementing Active Directory governance models, including hybrid AD/Entra ID sync architecture, delegation, privilege-escalation attack paths, and tiered administrative models.
• Expertise in designing identity-aware detection capabilities in collaboration with threat management, insider threat, and incident response teams.
• Experience in architecting non-person and machine-to-machine access, including service accounts, workload identity, and OAuth delegation patterns.
• In-depth knowledge of zero trust architecture, federation, SSO, OAuth 2.0/OIDC, and PAM.
• Strong understanding of NIST CSF, NIST 800-63, ISO 27001, MITRE ATT&CK, CIS Controls v8, and OWASP AI/LLM guidance.
• Ability to develop sophisticated security architectures that meet business requirements, regulatory obligations, and enterprise risk.
• Excellent communication and influencing capabilities.
• Capacity to operate in ambiguity and propel progress in a dynamic global environment.
• Equal opportunity employment.
• Reasonable accommodations for individuals with disabilities.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.