Job#: 3032959 Job Description: The AI identity engineer is responsible for applying artificial intelligence and machine learning capabilities to accelerate and enhance the organization's identity modernization initiatives. This role sits at the intersection of AI and IAM, translating intelligent automation and model driven insights into practical identity outcomes reducing manual overhead, improving access precision, and strengthening identity assurance across the enterprise.
Initial focus areas for this role include identity proofing, least privileged enforcement, and entitlement management, leveraging the capabilities of Okta and persona to build smarter, more adaptive identity workflows that scale with the program's evolving needs. The role will be defining and enforcing identity management strategies tailored for AI agents, including life cycles, entitlements, and owner relationships. Additionally, the role will be responsible for architecting and integrating AI-based features, such as adaptive access control, identity analytics, into the IAM framework.
Core Skillset:
- Experience applying AI/ML techniques to identity and access management use cases
- Hands-on familiarity with Okta's platform capabilities including Identity Engine, Workflows, and adaptive access controls
- Working knowledge of Persona or comparable identity proofing and verification platforms
- Understanding of entitlement management principles, role engineering, and least privilege frameworks
- Ability to translate AI model outputs into actionable IAM policy and workflow automation
- Familiarity with IGA platforms (SailPoint) and how AI can augment access certification and provisioning
Key Responsibilities:
- Provide deep subject-matter expertise across IAM domains (authentication, authorization, federation, SSO, directories, identity lifecycle, and access governance) spanning both cloud and on-premises enterprise technologies, including hybrid integration patterns.
- Define, evolve, and drive adoption of authentication and authorization reference architectures for existing, new, and emerging IAM capabilities.
- Design end-to-end IAM solutions that are secure-by-design, scalable, resilient, and reusable-meeting immediate project needs while enabling a coherent, phased architecture aligned to the firm's strategic direction.
- Lead technical discovery and solutioning for complex, global IAM challenges; propose creative and pragmatic approaches to reduce risk, improve user experience, and increase automation.
- Translate IAM strategy and security principles into implementable technical designs, patterns, and standards (e.g., blueprints, reusable components, configuration baselines).
- Participate in IAM governance processes and influence firm-wide adoption of IAM standards through technical guidance, architecture reviews, and engineering guardrails.
- Partner with Information Security, Infrastructure, and Application teams to ensure solutions adhere to security policies and standards and are operationally supportable.
- Serve as hands-on technical lead on IAM initiatives-owning solution design, engineering delivery, and technical alignment across stakeholders (this is not a project manager role).
- Develop and maintain technical roadmaps for IAM and cloud security capabilities, including modernization, platform lifecycle planning, and decommissioning of legacy technologies.
- Provide architecture and engineering expertise for secure cross-organizational identity integration and information sharing (e.g., B2B/B2C, partner federation, API access patterns).
- Evaluate emerging threats, technology changes, and process gaps; recommend and implement improvements to IAM controls, patterns, and platform configurations.
- Produce and maintain high-quality technical documentation: architecture diagrams, engineering specifications, security patterns, configuration standards, and implementation guides.
Analytical / Decision-Making Responsibilities:
- Interpret IAM strategy and business requirements and convert them into actionable architecture and engineering plans.
- Make design decisions that balance security, usability, scalability, performance, and implementation complexity.
- Identify technical risks, propose mitigation strategies, and drive alignment on architecture direction across engineering teams and stakeholders.
- Contribute to the firm's overall IAM direction through thought leadership, pattern development, and continuous improvement of the IAM ecosystem.
Knowledge, Skills, and Experience Requirements- Strong foundation in Information Security concepts, with demonstrated experience designing and implementing IAM solutions in enterprise environments.
- Hands-on experience architecting and engineering IAM solutions in Microsoft Azure and AWS (experience with additional cloud providers is a plus).
Strong knowledge of IAM protocols and standards including SAML, SCIM, OpenID Connect, OAuth (and familiarity with XACML/SPML where applicable).
Expertise in federation concepts and technologies, particularly ADFS and Ping Identity (or equivalent platforms).
- In-depth experience with Microsoft Entra ID (Azure AD), including tenant architecture, hybrid identity patterns, conditional access, and integrations to enterprise infrastructure.
- Strong experience with directories, SSO, federation, delegated administration models, API gateways, and service-to-service authentication/authorization patterns.
- Solid understanding of cloud architecture, technical design, and implementation approaches across IaaS, PaaS, and SaaS delivery models.
- Experience integrating IAM solutions with cloud security and governance tooling (e.g., CASBs and related controls) and relevant virtualization technologies.
- Strong troubleshooting and analytical skills with the ability to design for failure modes, resiliency, and secure operations.
- Excellent written and verbal communication skills, including the ability to influence technical direction across teams and communicate architecture decisions to varied audiences.
- Ability to work independently and collaboratively under minimal supervision; comfortable leading technical delivery and mentoring others.
- Scripting/automation skills (e.g., PowerShell, JavaScript, Python, etc.) to build tooling, automate integrations, and streamline engineering delivery.
- Experience advising customer organizations and senior leaders on architecture options, implementation scope, and technical tradeoffs.
- Understanding of AI/ML-driven identity controls and adaptive access patterns, including how to incorporate them into modern access architectures.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click for more details.
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.