AI Agentic Identity Engineer
Job Summary
-
Looking for a senior-level Security Engineer to support a strategic initiative to establish an identity and access management (IAM) program for AI agents.
-
They will treat each agent as a governed non-human identity (NHI) with a tracked owner a pre-approved permission set (persona) and strong workload identity.
-
This includes both consumer-facing and internal agentic services.
-
-
Design and operationalize runtime guardrails identity-aware authorization and policy enforcement across both guest-facing and internal systems.
-
Design and implement security control planes for agentic AI systems.
-
Support human-in-the-loop workflows for sensitive or high-risk AI-initiated actions.
-
Ensure end-to-end attribution across user agent tool execution chains.
-
Implement SPIFFE/SPIRE (or equivalent) for cryptographic agent identity.
-
Implement OAuth 2.0/2.1 OIDC On-Behalf-Of (RFC 8693) token exchange and audience-bound tokens (RFC 8707); enforce least privilege and temporal/just-in-time constraints.
-
8 years of experience in security engineering application security or platform security.
-
Proven experience delivering enterprise IAM / non-human identity solutions.
-
Experience designing fine-grained least-privilege access models for distributed systems.
-
Experience working with AI-enabled or automation-heavy systems.
-
Familiarity with risks unique to agentic or autonomous systems.
-
Deep working knowledge of OAuth 2.0/2.1 OIDC token exchange (OBO) and modern token security (PKCE audience binding short-lived tokens).
-
Experience with workload identity: SPIFFE/SPIRE mTLS and PKI/certificate-based authentication.
-
Experience with secrets management and eliminating static/long-lived credentials.
-
Solid grasp of Zero Trust least privilege and identity lifecycle/recertification.
-
Experience with AI/LLM security risks (e.g. OWASP Top 10 for LLM Applications agentic threat models).