That's quite a bit of group memberships, to increase the allowed header size (which this is most likley violating) this can be done under Proxies > HTTP Proxy > Settings > Maximum header length.
The reason this could be occurring is if he is apart of soooo many groups, the proxy will pass a large request to the ICAP server for filtering, and if it is larger than the 'Maximum header length' then it will result in an ICAP error.
If you did ICAP traces for the user this would show how large the X-Authenticated-Group header is.
Yes, it look like that. We have a team that is streamlining all group membership and structure. I will know tomorrow what is the story for this account.