About this role
JLL empowers you to shape a brighter way .
Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong. Whether you’ve got deep experience in commercial real estate, skilled trades or technology, or you’re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward.
JLL es una empresa comprometida con la igualdad de oportunidades entre hombres y mujeres / JLL as a company is committed to equal opportunities for men and women.
Senior Identity Security Architect
Level: P4 | Job Discipline: Security Architecture
Overview
At JLL, we're reimagining how the world's most complex real estate environments are secured, operated, and experienced. As our Senior Identity Security Architect, you'll be shaping the strategy that defines how 100,000+ employees, clients, and partners authenticate, access, and interact with JLL's global technology ecosystem. This is a high-impact architecture role. You will be responsible for setting direction, establishing standards, and partnering with engineering and product teams to ensure that identity security is designed correctly from the ground up. From zero trust frameworks to privileged access governance to customer identity in JLL’s digital products, your architectural decisions will directly shape JLL’s security posture at enterprise scale.
If you’re a strategic thinker with deep identity expertise who thrives in a large, dynamic environment and wants their work to have real, visible impact, we want to hear from you.
Essential Duties and Responsibilities
Identity Strategy & Architecture
- Define and own JLL's enterprise identity security architecture spanning IdP services (Okta or Entra preferred), Active Directory, M365, cloud platforms (AWS/Azure), and third-party SaaS.
- Ensuring a coherent, scalable, and secure design across the global technology estate.
- Establish and maintain identity security policy and standards across users, non-person accounts, and on-premises, cloud, and SaaS platforms, in partnership with key identity stakeholders.
- Partner with Identity Security, Engineering, and operations teams to develop to translate standards and patterns into actionable engineering and operational direction.
- Lead JLL's zero trust strategy for user and third-party access in close partnership with the network security organization, driving architectural decisions that eliminate implicit trust across the environment.
- Shape the architectural vision for Customer Identity and Access Management (CIAM) within JLL's externally-facing digital products, ensuring secure and seamless experiences for clients and partners.
- Extend identity security architecture beyond the human user scope and into NHI landscapes for machine identity and service accounts including creation of AI, API, and other modern auth patterns and standards.
Identity Governance & Administration
- Architecture coverage for JLL's identity governance and administration strategy across different identity platforms, assisting in defining entitlement models, access certification and review cadence, and joiner/mover/leaver lifecycle standards and management.
- Assist in defining segregation-of-duties and least-privilege policy for toxic-combination detection, and partner with application and platform owners to translate that policy into enforceable entitlement structures and operating models.
Privileged Access Governance
- Architect JLL's Privileged Access Management strategy, defining controls for privileged accounts that minimize abuse potential and enable robust detection of insider and external threats.
- Provide strategic direction to engineering teams operating JLL's PAM tooling (CyberArk preferred), ensuring the platform evolves to meet emerging threat and business requirements.
- Collaborate with cyber threat management and insider threat teams to embed identity-aware detection and response capabilities across the enterprise.
Cross-Functional Leadership & Influence
- Partner with Active Directory, authentication, and cloud engineering teams to translate security architecture into enforceable controls and compliant implementations.
- Serve as the identity security subject matter expert on major programs, technology transformations, and acquisitions. Bring architectural clarity to complex, multi-stakeholder initiatives.
- Lead security architecture reviews and design governance processes; mentor junior architects and security professionals across the team.
- Communicate advanced security architecture strategies and design rationale clearly to diverse audiences from engineering teams to senior business stakeholders.
Mentorship & Team Leadership
- Provide technical guidance and mentoring to junior security engineers, developers, and architects on application security principles, secure coding practices, and architectural standards.
- Lead cross-functional security initiatives, driving collaborative approaches to security integration across development and architecture teams.
- Support secure development training and awareness programs to build security competency across engineering organizations.
Required Knowledge, Skills, and Abilities
Technical Knowledge
- Hands-on architectural experience with enterprise IdP platforms (Okta strongly preferred) and Privileged Access Management solutions (CyberArk strongly preferred).
- Experience securing identity across M365, AWS/Azure, SaaS applications, and on-premises infrastructure.
- Experience implementing Active Directory governance models that enforce security policy and compliance requirements, including hybrid AD/Entra ID sync architecture, delegation and privilege-escalation attack paths (e.g., resource-based constrained delegation, Kerberos delegation), and tiered administrative models.
- Track record of partnering with threat management, insider threat, and incident response teams to design identity-aware detection capabilities.
- Experience architecting identity for non-person and machine-to-machine access such as service accounts, workload identity, and OAuth delegation patterns (client credentials, on-behalf-of/token exchange) for service integrations and automation.
Skills & Abilities
- Comprehensive knowledge of zero trust architecture principles and enterprise identity design patterns, including federation, SSO, OAuth 2.0/OIDC, and PAM.
- Strong command of security frameworks including NIST CSF, NIST 800-63, ISO 27001, and MITRE ATT&CK and CIS Controls v8, along with emerging OWASP guidance for AI/LLM and agentic systems (GenAI Security, LLM Top 10, AI Exchange) — and the ability to apply them practically, not just reference them.
- Proven ability to develop sophisticated security architectures that address complex business requirements, regulatory obligations, and enterprise risk across multiple technology domains.
- Exceptional communication and influencing skills — able to build alignment across engineering, product, and business stakeholders on complex architectural decisions.
- Comfortable operating in ambiguity; able to define structure, set priorities, and drive progress in a fast-moving, high-change global environment.
Education & Experience
- 10+ years of technical cybersecurity experience, with at least 7 years focused on identity security architecture in large, complex enterprise environments.
- Demonstrated success designing and maturing enterprise identity security programs — not just operating tools, but shaping strategy and standards at scale.
Location:
Remote –Madrid, ESP
If this job description resonates with you, we encourage you to apply even if you don’t meet all of the requirements. We’re interested in getting to know you and what you bring to the table!
At JLL, we harness the power of artificial intelligence (AI) to efficiently accelerate meaningful connections between candidates and opportunities. Using AI capabilities, we analyze your application for relevant skills, experiences, and qualifications to generate valuable insights about how your unique profile aligns with the specific requirements of the role you're pursuing.
JLL Privacy Notice
Jones Lang LaSalle (JLL), together with its subsidiaries and affiliates, is a leading global provider of real estate and investment management services. We take our responsibility to protect the personal information provided to us seriously. Generally the personal information we collect from you are for the purposes of processing in connection with JLL’s recruitment process. We endeavour to keep your personal information secure with appropriate level of security and keep for as long as we need it for legitimate business or legal reasons. We will then delete it safely and securely.
For more information about how JLL processes your personal data, please view our Candidate Privacy Statement .
For additional details please see our career site pages for each country.
Jones Lang LaSalle (“JLL”) is an Equal Opportunity Employer and is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process – including the online application and/or overall selection process – you may email us at [email protected] . This email is only to request an accommodation. Please direct any other general recruiting inquiries to our Contact Us page > I want to work for JLL.
