Security Engineer / Architect Identity, Authorization & Platform Security
Location: Denver, CO 100% Onsite
Job Type: Contract
Duration: Contract / Long-Term Engagement
Position Overview
We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform.
The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security.
This is a builder's role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions.
Key Responsibilities
Identity & Access Management / RBAC
- Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.
- Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning.
- Build automated user/group/role provisioning and lifecycle management.
- Implement access recertification and governance processes.
- Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
- Establish SSO and API authentication across services.
- Implement consistent organization and tenant isolation across identity and downstream platforms.
Authorization & Policy Engineering
- Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
- Implement an externalized policy-decision engine and manage policies as code.
- Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
- Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction.
- Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.
AI Agent & Tool Security
- Design authorization models for AI agents and automated tool invocation.
- Establish agent workload identities and delegated authorization.
- Implement per-agent cryptographic identities and on-behalf-of authorization.
- Define tool-level permissions based on users, agents, tenants, resources, and actions.
- Implement human-in-the-loop approval workflows for sensitive operations.
- Maintain complete, tamper-evident audit trails for agent and tool activity.
- Apply security controls against prompt injection and unauthorized tool execution.
Secrets & Cloud Security
- Implement centralized secrets management and automated credential rotation.
- Design secure cloud IAM architectures and least-privilege access.
- Implement secure credential management for applications, workloads, agents, and infrastructure.
- Support secure execution environments and sandboxing for sensitive tool calls.
Vulnerability Management
- Implement continuous vulnerability scanning across:
- Edge compute nodes
- Containers and container images
- Operating systems
- Application dependencies
- Container-orchestration platforms
- Third-party libraries
- Device firmware where applicable
- Implement SBOM generation, tracking, and vulnerability correlation.
- Correlate CVEs with asset exposure and exploitability.
- Develop risk-based vulnerability prioritization and remediation workflows.
- Build operational and executive vulnerability dashboards.
- Integrate vulnerability findings with event platforms and ticketing workflows.
Security Telemetry & SIEM
- Deploy security telemetry capabilities across edge environments.
- Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
- Normalize security events into a common schema.
- Integrate security telemetry with centralized SIEM platforms.
- Implement store-and-forward capabilities for intermittently connected edge environments.
- Design bandwidth-aware event batching and reliable event delivery.
- Implement tamper-evident and mutually authenticated telemetry pipelines.
- Maintain tenant isolation throughout the telemetry pipeline.
- Develop SIEM detection and correlation rules that associate security events with verified identities.
- Route actionable security alerts into event buses and on-call workflows.
Platform Security Integration
- Establish security standards for event-platform authentication and authorization.
- Implement message signing and secure service-to-service communication.
- Support edge-device identity, mTLS, PKI, and certificate lifecycle management.
- Integrate security controls into CI/CD pipelines.
- Implement security gates including artifact signing, IaC scanning, and automated security validation.
- Partner with engineering teams to establish reusable security primitives and standards.
Required Qualifications
- 8+ years of experience in security engineering.
- 3+ years of experience architecting and implementing Identity & Access Management at scale.
- Strong hands-on experience with enterprise Identity Providers and identity federation.
- Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning.
- Experience mapping federated identities to downstream authorization models.
- Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
- Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
- Experience with externalized authorization/policy engines.
- Strong cloud IAM experience.
- Hands-on experience with centralized secrets management and automated credential rotation.
- Experience with containers and container orchestration.
- Ability to develop production-quality code and implement security solutions hands-on.
- Demonstrated experience implementing least-privilege and Just-in-Time access.
- Experience building fully auditable access-control systems.
Preferred Qualifications
- Experience securing AI agents, LLM applications, and automated tool-invocation interfaces.
- Knowledge of prompt-injection and AI tool-boundary security.
- Experience with workload identity and machine-to-machine authentication.
- Experience building security telemetry pipelines and SIEM integrations.
- Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
- Experience securing edge, IoT, or intermittently connected environments.
- Experience with lightweight host-based security telemetry agents.
- Knowledge of Zero Trust architecture.
- Experience with PKI, mTLS, certificate lifecycle management, and device attestation.
- Experience with event-driven security architectures.
- Experience implementing secure CI/CD and automated security gates.
- Security architecture certifications are a plus but not required.