AVP, IAM AI Engineer

Jobtailor

California (MO)

On-site

USD 180,000 - 240,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced IAM leader to design and operationalize identity controls for human and non-human actors, including AI agents. You will build governance guardrails, integrate IAM into AI app development, and ensure real-time enforcement across cloud platforms.

You will mentor a team and partner with engineering, data science, and governance stakeholders to deliver secure, scalable IAM solutions in a regulated environment.

Qualifications

  • 5+ years in identity and access management or information security, including hands‑on engineering.
  • Demonstrated experience building and/or leading technical teams.
  • 5+ years with Ping Identity (PingFederate, PingOne, or PingAccess) or a comparable access‑management/federation platform.
  • 5+ years with SailPoint (IdentityIQ or Identity Security Cloud) or a comparable IGA platform.
  • 3+ years with Idira (CyberArk, formerly Conjur), HashiCorp Vault, or a comparable secrets‑management platform.
  • Working knowledge of identity and authorization for users and agents, including user‑to‑agent and agent‑to‑agent patterns.
  • Knowledge of OIDC and OAuth 2.0/2.1 tokens and API keys across authentication and authorization.
  • Proficiency in a scripting/programming language such as Python.
  • Experience with infrastructure‑as‑code such as Terraform.
  • Experience with CI/CD pipelines and REST API integration.
  • Experience applying IAM in AWS, Azure, and/or GCP.
  • Experience with containerized and Kubernetes workloads.
  • Familiarity with SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload‑identity federation.
  • Working understanding of LLMs, agent frameworks, tool‑calling, and authentication patterns such as MCP.
  • Experience in a regulated industry and associated compliance regimes.
  • Relevant certifications such as CISSP, CyberArk Defender/Sentry, SailPoint, Ping, or a major cloud security certification
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience

Responsibilities

  • Design, operationalize, and automate identity controls governing human and non-human actors, with a focus on AI agents and non-human identities.
  • Build runtime controls, secrets workflows, and governance guardrails for safe AI adoption.
  • Embed identity, authentication, and authorization into new AI application development from the earliest design stages.
  • Operationalize and automate real-time authentication, authorization, and policy enforcement.
  • Design and automate governance controls across the lifecycle of AI agents and non-human identities, including provisioning, entitlement, rotation, certification/attestation, and deprovisioning.
  • Develop and automate secrets-manager workflows, including secret rotation, just-in-time and episodic credentials, and secure secret delivery.
  • Define and enforce fine‑privilege authorization models using policy-as-code.
  • Establish identity‑flow standards and reference patterns for user‑to‑agent, agent‑to‑agent, and workload‑to‑service authentication and authorization.
  • Partner with engineering and data science teams on AI application development.
  • Support deployment and adoption of IAM controls for end users.
  • Integrate identity telemetry with SIEM/SOC tooling and build monitoring and anomaly detection for NHI and agent behavior.
  • Support incident response for compromised or misused credentials.
  • Partner with GRC, risk, and audit stakeholders to satisfy regulatory and internal requirements and produce audit evidence.
  • Recruit, build, mentor, and lead a team; set technical direction and roadmap for NHI and agentic IAM.

Skills

Identity And Access Management
Authentication
Authorization
Policy Enforcement
Secrets Management
Terraform
CI/CD Pipelines
REST API Integration
Cloud IAM
Containerization (Kubernetes)
Team Leadership
Mentoring
Collaboration
LLM Familiarity

Education

Bachelor's degree in Computer Science, Information Security, or related field
Equivalent practical experience

Tools

Ping Identity (PingFederate, PingOne, PingAccess)
SailPoint (IdentityIQ or Identity Security Cloud)
CyberArk Defender/Sentry
HashiCorp Vault

Job description


  • Design, operationalize, and automate identity controls governing human and non-human actors, with a focus on AI agents and non-human identities.

  • Build runtime controls, secrets workflows, and governance guardrails for safe AI adoption.

  • Embed identity, authentication, and authorization into new AI application development from the earliest design stages.

  • Operationalize and automate real-time authentication, authorization, and policy enforcement.

  • Design and automate governance controls across the lifecycle of AI agents and non-human identities, including provisioning, entitlement, rotation, certification/attestation, and deprovisioning.

  • Develop and automate secrets-manager workflows, including secret rotation, just-in-time and episodic credentials, and secure secret delivery.

  • Define and enforce fine‑privilege authorization models using policy-as-code.

  • Establish identity‑flow standards and reference patterns for user‑to‑agent, agent‑to‑agent, and workload‑to‑service authentication and authorization.

  • Partner with engineering and data science teams on AI application development.

  • Support deployment and adoption of IAM controls for end users.

  • Integrate identity telemetry with SIEM/SOC tooling and build monitoring and anomaly detection for NHI and agent behavior.

  • Support incident response for compromised or misused credentials.

  • Partner with GRC, risk, and audit stakeholders to satisfy regulatory and internal requirements and produce audit evidence.

  • Recruit, build, mentor, and lead a team; set technical direction and roadmap for NHI and agentic IAM.


Requirements


  • 5+ years in identity and access management or information security, including hands‑on engineering

  • Demonstrated experience building and/or leading technical teams

  • 5+ years with Ping Identity (PingFederate, PingOne, or PingAccess) or a comparable access‑management/federation platform

  • 5+ years with SailPoint (IdentityIQ or Identity Security Cloud) or a comparable IGA platform

  • 3+ years with Idira (CyberArk, formerly Conjur), HashiCorp Vault, or a comparable secrets‑management platform

  • Working knowledge of identity and authorization for users and agents, including user‑to‑agent and agent‑to‑agent patterns

  • Knowledge of OIDC and OAuth 2.0/2.1 tokens and API keys across authentication and authorization

  • Proficiency in a scripting/programming language such as Python

  • Experience with infrastructure‑as‑code such as Terraform

  • Experience with CI/CD pipelines and REST API integration

  • Experience applying IAM in AWS, Azure, and/or GCP

  • Experience with containerized and Kubernetes workloads

  • Familiarity with SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload‑identity federation

  • Working understanding of LLMs, agent frameworks, tool‑calling, and authentication patterns such as MCP

  • Experience in a regulated industry and associated compliance regimes

  • Relevant certifications such as CISSP, CyberArk Defender/Sentry, SailPoint, Ping, or a major cloud security certification

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience


Core Competencies

Demonstrates expertise in identity and access management, focusing on the automation and governance of identity controls for AI agents and non‑human identities. Proficient in implementing fine‑grained authorization models and integrating IAM solutions across various cloud platforms.


Highest-signal resume keywords


  • Identity And Access Management

  • Ping Identity (PingFederate, PingOne, PingAccess)

  • SailPoint (IdentityIQ, Identity Security Cloud)

  • Secrets Management (CyberArk, HashiCorp Vault)

  • Scripting/Programming (Python)


ATS Optimization Keywords

Hard Skills


  • Identity And Access Management

  • Authentication

  • Authorization

  • Policy Enforcement

  • Secrets Management

  • Infrastructure-As-Code (Terraform)

  • CI/CD Pipelines

  • REST API Integration

  • Cloud IAM (AWS, Azure, GCP)

  • Containerization (Kubernetes)


Soft Skills


  • Team Leadership

  • Mentoring

  • Collaboration


Certifications & Qualifications


  • CISSP

  • CyberArk Defender/Sentry

  • SailPoint Certification

  • Ping Certification

  • Cloud Security Certification


Industry Keywords


  • Regulated Industry

  • Compliance Regimes

  • AI Application Development

  • Governance Controls

  • Identity Telemetry


Tools & Technologies


  • Ping Identity

  • SailPoint

  • CyberArk

  • HashiCorp Vault

  • SIEM/SOC Tools

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity and Access Management (IAM) Consultant
Senior Identity and Access Management (IAM) Consultant

Jobtailor • Colorado

On-site
USD 140,000 - 210,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Jobtailor • Westbrook (ME)

On-site
USD 120,000 - 180,000
Senior Identity & Access Management Security Engineer
Senior Identity & Access Management Security Engineer

Jobtailor • Coral Gables (FL)

On-site
USD 120,000 - 160,000
Senior Identity and Access Engineer
Senior Identity and Access Engineer

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 180,000
None
Senior Identity Access Management Engineer
Senior Identity Access Management Engineer

Jobtailor • Illinois

On-site
USD 120,000 - 150,000
Cyber Security Identity Staff Engineer
Cyber Security Identity Staff Engineer

Jobtailor • California (MO)

On-site
USD 110,000 - 170,000
Identity Governance & Administration Leader
Identity Governance & Administration Leader

Jobtailor • McLean (VA)

On-site
USD 170,000 - 250,000
Senior Solution Architect – Identity and Access Management
Senior Solution Architect – Identity and Access Management

Jobtailor • Colorado

On-site
USD 120,000 - 170,000
Manager, Privileged Access Management – PAM
Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 190,000
Senior Manager, Authentication Engineer
Senior Manager, Authentication Engineer

Jobtailor • New York (NY)

Hybrid
USD 150,000 - 230,000