Senior APIM Architect
.png)
Role overview
JLL runs a multi-cloud estate and needs an architect to set the direction for how APIs are exposed, secured and governed across it. Azure API Management is the centre of gravity, but the person in this seat is also expected to understand AWS and GCP well enough to bridge gateways, define standards that work on any cloud, and keep security and governance consistent wherever an API happens to live.
Day to day this means designing APIM topologies (multi-region, VNet-integrated, private endpoints), writing policy for transformation, auth and traffic control, building the identity layer around Okta, coordinating gateway policy with Akamai WAF, and automating everything through GitHub Actions, Terraform and Artifactory. The architect also acts as the internal authority on API platform choices, mentors developers, and leads proofs of concept on new integration approaches.
What you will do
- Own the architecture of Azure API Management at JLL: multi-region topologies, VNet-connected deployments, private endpoints and hybrid links, plus the developer-portal customisation and self-service onboarding experience.
- Write Azure APIM policy that reshapes requests and responses, authenticates callers, caches results and throttles traffic, and design integration patterns with App Services, Function Apps, Logic Apps, AKS and Service Bus.
- Extend API management beyond Azure by bridging APIM with AWS API Gateway, Lambda, ECS, SQS/SNS and GCP services, and by defining cloud-neutral API standards, cross-cloud routing and multi-provider failover and DR.
- Build the identity and security layer: OAuth 2.0 and OpenID Connect flows with Okta as the enterprise IdP, validating JWTs and introspecting tokens across Azure, AWS and GCP gateways, certificate and API-key access, and defence in depth that pairs APIM policy with Akamai WAF rules.
- Deliver observability and delivery automation by wiring APIM into Application Insights, Log Analytics and Datadog, shipping APIs, policies and infrastructure via GitHub Actions with ARM/Bicep/Terraform, storing artifacts in Artifactory and adding automated tests and security scans to pipelines.
- Assess alternative API platforms (AWS API Gateway, GCP API Gateway, Apigee, MuleSoft, Kong) and design migration or coexistence patterns, advising leadership on trade-offs between them.
- Define and enforce a governance framework covering security, lifecycle, performance and compliance that applies across every cloud and gateway, including standards for OpenAPI documentation, portal content, API testing and dev/test/prod promotion workflows.
- Run the platform operationally: scaling across regions, backup/restore and DR, capacity planning, SKU and cost decisions, and SLA tuning through caching and traffic policies coordinated with Akamai.
- Establish GitOps practices for API lifecycle changes, including branching, pull-request review, rollback procedures and deployments synchronised with WAF configuration changes.
- Partner with enterprise and solution architects, security and compliance teams and cloud vendor account teams; mentor developers on APIM policy and API design; lead proofs of concept on event-driven, serverless and container-based patterns and on consolidating legacy integration platforms.
What the employer is looking for
- Bachelor's degree in Computer Science, IT or a related field (Master's preferred) and 8+ years in roles spanning software engineering, cloud integration work or enterprise architecture.
- 5+ years of hands-on Azure API Management in production, with expert-level policy authoring, multi-region deployments and VNet, private endpoint, VPN and ExpressRoute networking.
- Deep familiarity with the APIM object model (products, subscriptions, versions, revisions, backends, named values) and with customising the developer portal and publishing APIs through it.
- Experience in at least two of Azure, AWS and GCP, including working knowledge of AWS API Gateway, Lambda, EKS, VPC, IAM and CloudWatch, GCP services, and cross-cloud connectivity (VPN, ExpressRoute, Direct Connect, Cloud Interconnect).
- A strong record of integrating API platforms with Okta: OAuth 2.0, OIDC and SAML implementations, validating JWTs, introspecting tokens and authorising on claims.
- Experience with Akamai WAF or a comparable web application firewall, and with handling secrets in Azure Key Vault, AWS Secrets Manager and GCP Secret Manager.
- Proficiency with GitHub and GitHub Actions for CI/CD, Artifactory or a similar artifact repository, and infrastructure as code using Terraform or cloud-native tools (ARM/Bicep, CloudFormation, Deployment Manager), plus an understanding of GitOps.
- Substantial hands-on time with Azure Integration Services (Logic Apps, Service Bus, Event Grid, Event Hubs, Function Apps), Azure monitoring (Application Insights, Log Analytics, Azure Monitor) and Azure networking and security (VNets, NSGs, Front Door, Key Vault, Azure Policy).
- Exposure to other API management products such as AWS API Gateway, GCP API Gateway, Apigee, MuleSoft, Kong or Gravitee, and the ability to translate patterns between them and Azure APIM.
- Solid grounding in REST and microservices design, API security standards, .NET/Python/JavaScript, Docker and Kubernetes (AKS/EKS/GKE) and YAML/JSON configuration, combined with clear communication, leadership and the judgement to weigh trade-offs in an Agile environment.
Good to have
- Microsoft Azure certifications (Solutions Architect Expert, Administrator Associate or Developer Associate) or AWS certifications (Solutions Architect, Developer Associate or Security Specialty).
- Experience with the Azure APIM self-hosted gateway in hybrid or multi-cloud setups.
- Familiarity with Akamai's own API Gateway or its API Security capabilities.
- Exposure to monetizing APIs and growing a developer ecosystem.
- Working knowledge of GraphQL, gRPC or similar newer protocols, and a history of leading cross-cloud API platform migrations or consolidation efforts.
- FinOps and cloud cost optimisation knowledge, or prior work in the commercial property or professional services sectors.
About JLL
JLL (NYSE: JLL) is a worldwide commercial property and investment management firm with a history stretching back more than 200 years. It supports clients through the purchase, construction, occupation, management and investment stages across office, industrial, hospitality, residential and retail assets. A Fortune 500 company operating in over 80 countries, JLL combines a global platform with local market expertise and is increasingly pairing its services and advisory work with technology.
Quick answers
Is the Senior APIM Architect role at JLL remote?
Yes. The posting lists the position as remote within Jalisco, Mexico, tied to JLL's Guadalajara corporate office.
How much Azure API Management experience does JLL require?
At least 5 years of hands-on Azure APIM in production, within a broader 8+ years spent in software engineering, cloud integration work or enterprise architecture roles. Experience in at least two of Azure, AWS and GCP is also required.
Which API platforms and security tools does this role work with?
Azure API Management is the primary platform, alongside AWS API Gateway and GCP API Gateway/Apigee. Exposure to MuleSoft, Kong or Gravitee is welcome. Identity runs through Okta (OAuth 2.0, OIDC, SAML) and edge security through Akamai WAF, with GitHub Actions, Terraform and Artifactory for delivery.

DigitalAPI's read on this role
Why JLL's multi-cloud APIM Architect role reflects where enterprise API management is heading
DigitalAPI's leadership team has run API programmes for Fortune 100 companies and now builds the platform behind them. Here is their take on what this opening really asks for.
What this role says about the market
This posting is a textbook example of gateway sprawl in a large enterprise. Azure APIM is the anchor, yet the job description repeatedly asks for AWS API Gateway, GCP API Gateway, Apigee, MuleSoft and Kong knowledge, cloud-agnostic standards and migration or coexistence patterns. JLL is not hiring someone to master one console; it is hiring someone to govern APIs consistently across several. The emphasis on Okta-backed identity, Akamai WAF coordination, GitHub Actions pipelines with automated policy validation and security scanning, and a shared OpenAPI/portal standard shows governance moving into the pipeline rather than a review board. The passing mention of API monetization and developer ecosystems as a nice-to-have hints at where the programme could go next.
What to emphasise in your application
- Production Azure APIM depth: policy expressions for transformation, auth, caching and rate limiting, multi-region deployments, VNet and private endpoint networking, and the products/subscriptions/versions/revisions model.
- Concrete cross-cloud work: linking Azure APIM to AWS API Gateway or Apigee, JWT validation and token introspection that spans gateways, and any vendor-neutral API standards you have authored.
- Identity and edge security integration: OAuth 2.0/OIDC flows with Okta as IdP, claims-based authorisation, and layering gateway policy with a WAF such as Akamai.
- Delivery automation: GitHub Actions pipelines that deploy APIM configuration via Terraform, Bicep or ARM, artifact management in Artifactory, GitOps branching and rollback.
- Governance and mentoring: examples of API lifecycle standards, OpenAPI documentation and portal conventions you defined and got adopted across teams.
For hiring managers
DigitalAPI's leadership team would advise screening for candidates who can explain how they kept policy, identity and observability consistent when APIs lived on more than one gateway, not only how deep they went on Azure APIM. Ask for a worked example of a cross-cloud migration or coexistence design, and probe whether their governance shows up as automated pipeline checks or as documents. Candidates who treat the developer portal as a product, not an afterthought, will also raise adoption of the platform you are building.
In our view this is exactly the profile modern API programmes need: someone who governs across gateways, treats the portal as the place APIs become products, and automates policy rather than reviewing it. As agents and MCP clients join the consumer mix, that cross-gateway discipline becomes even more valuable.
About DigitalAPI
DigitalAPI is the gateway-agnostic command centre for APIs and AI agents. It connects to the gateways an enterprise already runs, Apigee, Kong, AWS API Gateway and Azure API Management, and turns everything behind them into one governed, self-serve catalogue for developers, partners and AI agents. API Gateway, API Portal, API Catalog, API Marketplace, MCP Gateway and MCP Portal ship as one platform.
The company grew out of an API consultancy founded in Bangalore in 2015 that became an Apigee-Google partner in 2017, then built its own cloud-agnostic, AI-powered platform in 2020 after seeing how fragmented gateways and duplicate APIs blocked its clients. More than 240 API teams now use it, with customers such as Zurich, Canara Bank, HSBC, Fiserv and Mahindra Finance. DigitalAPI has offices in the USA, UK and India, 130+ people, and recognition from Gartner and Deloitte.









.avif)
