Position Overview
We are seeking an experienced Security Architect Agentic Identity & Access Management to design and govern the target-state authorization architecture for autonomous AI applications, AI agents, and non-human identities across enterprise and cloud environments.
This role serves as the Subject Matter Expert bridging Identity Governance and Administration (IGA), Privileged Access Management (PAM), Cloud Security, and AI Engineering. The Architect will establish scalable authorization patterns (user-to-agent, agent-to-tool, agent-to-agent), implement Zero Standing Privilege (ZSP) and dynamic policy enforcement, and define full lifecycle governance for autonomous agentic workflows and Model Context Protocol (MCP) integrations.
Key Responsibilities
Agentic IAM Target-State Architecture: Define and lead the enterprise target-state architecture, reference models, and governance frameworks for identities, delegated authority, and runtime authorization across AI applications, agents, APIs, and human users.
Authorization Patterns & Delegation: Architect reusable authorization patterns for user-to-agent delegation, agent-to-tool invocation, agent-to-agent collaboration, and machine-to-machine communications utilizing OAuth 2.0, OIDC, token exchange, and workload identity federation.
Zero Trust & Policy Enforcement: Design context-aware access policies enforcing least privilege, Zero Standing Privilege (ZSP), separation of duties, dynamic runtime decisioning, and human-in-the-loop escalation guardrails.
Non-Human Identity (NHI) Lifecycle Governance: Define lifecycle governance standards for AI agents, including registration, ownership/sponsorship models, credential vaulting, automated rotation, periodic recertification, suspension, and deprovisioning.
Auditability & Traceability Frameworks: Architect logging and observability requirements to link every autonomous agent action directly to its agent identity, sponsoring owner, delegated human principal, authorization decision, and downstream resource.
Tool Evaluation & Integration: Evaluate vendor and native identity platforms (e.g., Ping Identity, SailPoint, CyberArk, AWS IAM/Secrets Manager, Microsoft Entra ID) to integrate emerging agentic IAM capabilities into infrastructure.
Cross-Functional Advisory: Partner with Cloud Security, Application Security, AI Governance, Enterprise Architecture, and Agile delivery teams to guide threat-informed design decisions for AI use cases, MCP servers, and tool integrations.
Required Skills & Experience (Ranked by Importance)
- Enterprise IAM Architecture & Integration (3 5+ years): Proven experience architecting enterprise Identity and Access Management, Identity Governance (IGA), and Privileged Access Management (PAM) across hybrid and multi-cloud environments.
- Agentic AI & Non-Human Identity Governance: Deep understanding of authorization models for AI agents, autonomous tools, MCP servers, service accounts, and API access patterns.
- Advanced Authentication & Delegation Standards: Hands-on expertise designing modern token exchange protocols, OAuth 2.0 / OIDC flows, short-lived credentials, and workload identity patterns for machine-to-machine interactions.
- Secrets Management & Tooling Expertise: Experience integrating enterprise IAM and security tools such as CyberArk, SailPoint (Identity Security Cloud / Entro), Ping Identity Platform, Microsoft Entra ID, HashiCorp Vault, or AWS Secrets Manager / IAM.
- Zero Trust & Runtime Authorization: Proven track record applying Zero Trust principles, Zero Standing Privilege (ZSP), attribute-based access control (ABAC), and policy-as-code.
- AI Safety & Governance Frameworks: Familiarity with NIST AI RMF, OWASP Top 10 for LLMs, and audit/compliance standards for autonomous AI operations.
- Agile Delivery & Stakeholder Influence: Experience collaborating in cross-functional technical teams (preferably Scaled Agile Framework / SAFe), translating complex identity concepts into clear architecture decision records (ADRs) and executive briefings.
Qualifications & Education
Education: Bachelor s degree in Technology, Computer Science, Cybersecurity, Information Systems, Business, or equivalent practical work experience.
Preferred Certifications
Security & Architecture: CISSP, CCSP, CISM, or AWS Certified Security Specialty.
Identity & Vendor Platforms: Certified CyberArk Defender/Sentry, SailPoint Certified IdentityIQ/IdentityNow Engineer, or Ping Identity Certified Professional.
AI & Cloud Fundamentals: AWS Certified AI Practitioner, AWS Cloud Practitioner, or AI Risk/Security certifications (e.g., AAISM, CompTIA Sec AI+).
Work Style & Core Competencies
Strategic thinker with the ability to navigate ambiguity and create structured architecture in rapidly evolving domains.
Strong consensus-builder capable of mediating technical tradeoffs between AI velocity, usability, and rigorous identity controls.
High attention to detail with clear documentation skills for enterprise standards, roadmaps, and reference architectures.