AI IAM Architect

LPL Financial

New York (NY)

Hybrid

USD 153,470 - 255,749

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401K matching
Health benefits
Employee stock options
Paid time off

Job summary

LPL Financial is seeking an experienced Identity and Access Management (IAM) Architect to lead the architecture and implementation of identity solutions tailored for AI workloads. In this role, you will work closely with engineering teams to secure tools and access while designing enterprise IAM patterns that align with best practices.

The ideal candidate will possess extensive IAM experience, particularly with OAuth and OIDC, alongside a solid understanding of regulatory compliance. This position offers a competitive salary and an extensive benefits package, making it a significant opportunity for a dedicated professional.

Qualifications

  • 10+ years in IAM, security architecture, or platform engineering.
  • 2+ years building IAM POCs.
  • Strong communication skills.

Responsibilities

  • Lead design and implementation of IAM patterns for AI workloads.
  • Produce architecture artifacts and reference implementations.
  • Deliver POC summaries and implementation guidance.

Skills

OAuth 2.0
OIDC
IAM architecture
API gateway integration
AI platform integration

Education

10+ years in IAM or security architecture

Tools

PingOne AIC
Microsoft Entra ID

Job description

Overview

We are seeking an experienced Identity and Access Management (IAM) Architect with a strong AI and agent-integration focus to lead the design, proof-of-concept (POC), and hands-on implementation of identity patterns for AI workloads, conversational agents, and AI platform integrations across the enterprise. The ideal candidate combines deep IAM architecture expertise with practical engineering skills—building POCs, configuring OAuth/OIDC flows, and partnering directly with AI engineering teams to secure agent runtimes, tool access, and human-in-the-loop experiences.

This role owns IAM architecture for AI use cases, including delegated and service-to-service access, API gateway/BFF token flows, scoped credentials, and governance alignment. You will design and validate OAuth/OIDC patterns (Auth Code + PKCE, OBO, token exchange, client credentials) across identity providers (PingOne AIC, Entra ID), gateways, and agent platforms. The IAM Architect partners across AI/platform engineering, IAM, security, and enterprise architecture to define reusable, secure, and production-ready identity standards for agents.

Key Responsibilities
  • Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs.
  • Assess existing SSO, MFA, federation, and API authorization models; identify gaps in delegation, token lifecycle, scopes, secrets, and auditability.
  • Design enterprise IAM patterns (user context propagation, delegation chains, BFF sessions, least-privilege access) and OAuth/OIDC client models.
  • Define standards for securing agent tools, data access, and cross-domain integrations; align to zero trust and regulatory controls.
  • Produce architecture artifacts (CAD/HLD/PSS) and reference implementations.
  • Lead and build IAM POCs (end-to-end flows, token exchange, gateway enforcement, delegated agent access).
  • Configure/test identity flows; troubleshoot tokens, scopes, and integrations.
  • Implement or guide IAM integrations across gateways, BFFs, agent orchestration, and observability.
  • Transition validated patterns to IAM engineering for production rollout.
  • Define agent identity lifecycle (registration, credential rotation, revocation, environment separation).
  • Integrate IAM across AI platform components; support CI/CD and IaC for IAM configurations.
  • Establish patterns for human-in-the-loop controls, break-glass access, and rate limiting.
  • Maintain documentation, decision records, diagrams, and runbooks.
  • Deliver POC summaries, evaluations, and implementation guidance; communicate risks and dependencies.
  • Ensure regulatory compliance; partner on threat modeling and controls (secrets, PAM, audit evidence).
  • Serve as IAM SME for AI initiatives; mentor engineers.
  • Deliver production-ready IAM patterns and reduce identity risk across AI workloads.
Requirements
  • 10+ years in IAM, security architecture, or platform engineering with significant IAM scope.
  • 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows (Auth Code + PKCE, refresh tokens, client credentials, token exchange, OBO).
  • 2+ years with PingOne AIC and/or Microsoft Entra ID.
Core Competencies
  • Hands-on experience designing identity for APIs, microservices, and BFF architectures.
  • Experience integrating IAM with API gateways, AI/ML platforms, and modern application stacks.
  • Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns.
  • Familiarity with agent/tool identity models and secure integration patterns.
  • Ability to translate AI requirements into secure identity designs; strong communication skills.
Preferences
  • Experience delivering AI/ML agents or copilots to production.
  • Experience with SailPoint, CyberArk/Delinea, or Auth0/CIAM.
  • Knowledge of AI-aware API gateways (e.g., Kong).
  • Experience with IAM modernization or M&A programs.
  • Relevant certifications (CISSP, CCSP, Entra, Ping, SailPoint, AWS).
  • Familiarity with zero trust and identity threat detection.
Pay Range

$153,470.00 - $255,749.00

Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. LPL Total Rewards package is designed to support your success at work, at home, and at play, including 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more.

Company Overview

LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. LPL supports over 32,000 financial advisors and the wealth management practices of approximately 1,100 financial institutions, servicing and custodying approximately $2.3 trillion in brokerage and advisory assets on behalf of approximately 8 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services.

EEO statement: Principals only. EOE.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI IAM Architect
AI IAM Architect

LPL Financial • Austin (TX)

Hybrid
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2
AI IAM Architect
AI IAM Architect

LPL Financial • San Diego (CA)

On-site
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2
AI IAM Architect
AI IAM Architect

LPL Financial LLC • Town of Charlotte (NY), Fort Mill (SC)

On-site
USD 153,000 - 256,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • Austin (TX)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • Fort Mill (SC)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • Tempe (AZ)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • New York (NY)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • San Diego (CA)

On-site
USD 123,000 - 204,000
AI IAM Architect: Secure Identities for AI Agents
AI IAM Architect: Secure Identities for AI Agents

LPL Financial • New York (NY)

Hybrid
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+1
AI IAM Architect: Secure Identities for AI Agents
AI IAM Architect: Secure Identities for AI Agents

LPL Financial • Austin (TX)

Hybrid
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2