RESPONSIBILITIES:
Kforce has a client that is seeking an AI Lead/Agentic Identity Engineer in Miami, FL (Florida).
Responsibilities:
* Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability
* Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement
* Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution
* Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services
* Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls
* Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows
* Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access
* Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers
* Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns
* Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities
REQUIREMENTS:
* 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security
* Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale
* Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models
* Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments
* Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs
* Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control
* Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation
* Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives
* Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: kforcecx
- Position Id: ITEQG2182870
- Posted 1 day ago