Enter a job title or keyword

Security Engineer Architect — Identity, Authorization &amp Platform Security

Cyber Resource


Job Location:

Denver, CO - USA

Monthly Salary: Not provided by the employer
Posted: 24 September 2026 (9 hours ago)
Application Deadline: 22 December 2026
Vacancies: 1 Vacancy

Job Summary

Security Engineer / Architect Identity Authorization & Platform Security

Location: Denver CO 100% Onsite
Job Type: Contract
Duration: Contract / Long-Term Engagement

Position Overview

We are seeking a hands-on Security Engineer / Architect to design build and implement a unified policy-driven security layer across the platform.

The primary focus will be on Identity & Access Management (IAM) RBAC authorization cloud security secrets management vulnerability management security telemetry SIEM integration and platform security.

This is a builders role requiring strong hands-on engineering experience. The selected candidate will own the architecture deliver reference implementations establish security standards and work closely with engineering teams to implement production-ready security solutions.

Key Responsibilities
Identity & Access Management / RBAC
  • Design a canonical identity entitlement and role model across infrastructure cloud IAM applications containers and other downstream systems.
  • Implement identity federation using OIDC SAML OAuth2 and standards-based provisioning.
  • Build automated user/group/role provisioning and lifecycle management.
  • Implement access recertification and governance processes.
  • Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
  • Establish SSO and API authentication across services.
  • Implement consistent organization and tenant isolation across identity and downstream platforms.
Authorization & Policy Engineering
  • Design and implement centralized authorization using RBAC ABAC and/or ReBAC models.
  • Implement an externalized policy-decision engine and manage policies as code.
  • Define fine-grained authorization boundaries for users applications agents services and tools.
  • Implement OAuth2/OIDC concepts including scopes audiences token exchange JWTs and audience restriction.
  • Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.
AI Agent & Tool Security
  • Design authorization models for AI agents and automated tool invocation.
  • Establish agent workload identities and delegated authorization.
  • Implement per-agent cryptographic identities and on-behalf-of authorization.
  • Define tool-level permissions based on users agents tenants resources and actions.
  • Implement human-in-the-loop approval workflows for sensitive operations.
  • Maintain complete tamper-evident audit trails for agent and tool activity.
  • Apply security controls against prompt injection and unauthorized tool execution.
Secrets & Cloud Security
  • Implement centralized secrets management and automated credential rotation.
  • Design secure cloud IAM architectures and least-privilege access.
  • Implement secure credential management for applications workloads agents and infrastructure.
  • Support secure execution environments and sandboxing for sensitive tool calls.
Vulnerability Management
  • Implement continuous vulnerability scanning across:
    • Edge compute nodes
    • Containers and container images
    • Operating systems
    • Application dependencies
    • Container-orchestration platforms
    • Third-party libraries
    • Device firmware where applicable
  • Implement SBOM generation tracking and vulnerability correlation.
  • Correlate CVEs with asset exposure and exploitability.
  • Develop risk-based vulnerability prioritization and remediation workflows.
  • Build operational and executive vulnerability dashboards.
  • Integrate vulnerability findings with event platforms and ticketing workflows.
Security Telemetry & SIEM
  • Deploy security telemetry capabilities across edge environments.
  • Capture authentication authorization process execution network connections file integrity configuration changes secret access and agent/tool activity.
  • Normalize security events into a common schema.
  • Integrate security telemetry with centralized SIEM platforms.
  • Implement store-and-forward capabilities for intermittently connected edge environments.
  • Design bandwidth-aware event batching and reliable event delivery.
  • Implement tamper-evident and mutually authenticated telemetry pipelines.
  • Maintain tenant isolation throughout the telemetry pipeline.
  • Develop SIEM detection and correlation rules that associate security events with verified identities.
  • Route actionable security alerts into event buses and on-call workflows.
Platform Security Integration
  • Establish security standards for event-platform authentication and authorization.
  • Implement message signing and secure service-to-service communication.
  • Support edge-device identity mTLS PKI and certificate lifecycle management.
  • Integrate security controls into CI/CD pipelines.
  • Implement security gates including artifact signing IaC scanning and automated security validation.
  • Partner with engineering teams to establish reusable security primitives and standards.
Required Qualifications
  • 8 years of experience in security engineering.
  • 3 years of experience architecting and implementing Identity & Access Management at scale.
  • Strong hands-on experience with enterprise Identity Providers and identity federation.
  • Deep knowledge of OAuth2 OIDC SAML JWT SSO and standards-based provisioning.
  • Experience mapping federated identities to downstream authorization models.
  • Strong understanding of OAuth2/OIDC scopes audiences token exchange and audience restrictions.
  • Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
  • Experience with externalized authorization/policy engines.
  • Strong cloud IAM experience.
  • Hands-on experience with centralized secrets management and automated credential rotation.
  • Experience with containers and container orchestration.
  • Ability to develop production-quality code and implement security solutions hands-on.
  • Demonstrated experience implementing least-privilege and Just-in-Time access.
  • Experience building fully auditable access-control systems.
Preferred Qualifications
  • Experience securing AI agents LLM applications and automated tool-invocation interfaces.
  • Knowledge of prompt-injection and AI tool-boundary security.
  • Experience with workload identity and machine-to-machine authentication.
  • Experience building security telemetry pipelines and SIEM integrations.
  • Experience with vulnerability-management programs SBOM tools CVE correlation and risk prioritization.
  • Experience securing edge IoT or intermittently connected environments.
  • Experience with lightweight host-based security telemetry agents.
  • Knowledge of Zero Trust architecture.
  • Experience with PKI mTLS certificate lifecycle management and device attestation.
  • Experience with event-driven security architectures.
  • Experience implementing secure CI/CD and automated security gates.
  • Security architecture certifications are a plus but not required.