AVP, IAM AI Engineer

LPL Financial

Tempe (AZ)

On-site

USD 123,000 - 204,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LPL Financial is seeking an AVP, IAM AI Engineer to design, operationalize, and automate identity controls for human and non-human actors, including AI agents. You will build runtime controls, secrets workflows, and governance guardrails to enable safe AI adoption while scaling the team.

Embedded in AI app development from the outset, you will ensure AuthN/AuthZ and secure secrets handling, lead a new team, and collaborate with engineering and data science to implement robust IAM across cloud

Qualifications

  • 5+ years in identity & access management or information security, including hands-on engineering.
  • Proven experience building and/or leading technical teams.
  • 5+ years with PingFederate/PingOne/PingAccess or a comparable access-management platform.
  • 5+ years with SailPoint IdentityIQ or Identity Security Cloud or a comparable IGA platform.
  • 3+ years with Idira (CyberArk, formerly Conjur) / HashiCorp Vault or a comparable secrets-management platform.

Responsibilities

  • Identity runtime controls. Operationalize and automate identity runtime controls across human and non-human identities, including real-time authentication, authorization, and policy enforcement.
  • NHI & agentic governance. Design, build, and automate governance controls for AI agents and non-human identities — covering provisioning, entitlement, rotation, certification/attestation, and deprovisioning.
  • Secrets management for AI. Develop and automate secrets-manager workflows for AI systems and agents, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery to workloads.
  • Least privilege & policy-as-code. Define and enforce fine-grained, least-privilege authorization models for agents and workloads, expressed as policy-as-code wherever possible.
  • Reference architecture & standards. Establish standards and reference patterns for how identity flows through agentic systems — user-to-agent, agent-to-agent (A2A), and workload-to-service authentication and authorization.
  • Embedded in AI development. Partner with engineering and data science teams on all new AI application development, ensuring identity, AuthN/AuthZ, and secrets handling are designed in from the start.
  • End-user IAM deployment. Support the deployment and adoption of IAM controls for end users where required.
  • Monitoring & response. Integrate identity telemetry with SIEM/SOC tooling; build monitoring and anomaly detection for NHI/agent behavior; support incident response for compromised or misused credentials.
  • Governance, risk & compliance. Partner with GRC, risk, and audit stakeholders to ensure controls satisfy regulatory and internal requirements, and to produce audit evidence.
  • Team building & leadership. Recruit, build, mentor, and lead a team to support these workstreams; set technical direction and roadmap for NHI and agentic IAM.

Skills

Identity & access management
Hands-on engineering
Team leadership
Automation & scripting (Python)
Cloud security IAM (AWS/Azure/GCP)
OIDC/OAuth2

Education

Bachelor's degree in Computer Science, Information Security, or a related field

Tools

PingFederate
PingOne
PingAccess
SailPoint IdentityIQ
SailPoint Identity Security Cloud
HashiCorp Vault
CyberArk Idira
Spiffe/SPIRE
Terraform
Kubernetes

Job description

Where Ambition Meets Innovation

Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you’ll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.

Where Ambition Meets Innovation

Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you’ll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.

Job Overview:

We are looking for an AVP, IAM AI Engineer to design, operationalize, and automate the identity controls that govern both human and non-human actors across our environment — with a specific focus on AI agents and the emerging class of agentic and non-human identities (NHI). This is a hands-on engineering and technical leadership role: you will build the runtime controls, secrets workflows, and governance guardrails that let the organization adopt AI safely, while standing up and growing a team to sustain and scale that work. You will be embedded in new AI application development from the earliest design stages, ensuring identity, authentication, and authorization are built in rather than bolted on.

Responsibilities:
  • Identity runtime controls. Operationalize and automate identity runtime controls across human and non-human identities, including real-time authentication, authorization, and policy enforcement.
  • NHI & agentic governance. Design, build, and automate governance controls for AI agents and non-human identities — covering the full lifecycle: provisioning, entitlement, rotation, certification/attestation, and deprovisioning.
  • Secrets management for AI. Develop and automate secrets-manager workflows for AI systems and agents, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery to workloads.
  • Least privilege & policy-as-code. Define and enforce fine-grained, least-privilege authorization models for agents and workloads, expressed as policy-as-code wherever possible.
  • Reference architecture & standards. Establish standards and reference patterns for how identity flows through agentic systems — user-to-agent, agent-to-agent (A2A), and workload-to-service authentication and authorization.
  • Embedded in AI development. Partner with engineering and data science teams on all new AI application development, ensuring identity, AuthN/AuthZ, and secrets handling are designed in from the start.
  • End-user IAM deployment. Support the deployment and adoption of IAM controls for end users where required.
  • Monitoring & response. Integrate identity telemetry with SIEM/SOC tooling; build monitoring and anomaly detection for NHI/agent behavior; support incident response for compromised or misused credentials.
  • Governance, risk & compliance. Partner with GRC, risk, and audit stakeholders to ensure controls satisfy regulatory and internal requirements, and to produce audit evidence.
  • Team building & leadership. Recruit, build, mentor, and lead a team to support these workstreams; set technical direction and roadmap for NHI and agentic IAM.
What are we looking for?

We’re looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work.

Requirements:
  • 5+ years in identity & access management or information security, including hands-on engineering.
  • Demonstrated experience building and/or leading technical teams.
  • 5+ years with Ping Identity (PingFederate / PingOne / PingAccess) or a comparable access-management / federation platform.
  • 5+ years with SailPoint (IdentityIQ / Identity Security Cloud) or a comparable identity governance & administration (IGA) platform.
  • 3+ years with Idira (CyberArk, formerly Conjur) / HashiCorp Vault or a comparable secrets-management platform.
Core Competencies:
  • Working knowledge of identity and authorization for both users and agents: user-to-agent and agent-to-agent (A2A) patterns, OIDC and OAuth 2.0/2.1 tokens, and API keys, across both authentication (AuthN) and authorization (AuthZ).
  • Strong automation and engineering skills: proficiency in a scripting/programming language (e.g., Python), infrastructure-as-code (e.g., Terraform), CI/CD pipelines, and REST API integration.
  • Experience applying IAM in cloud environments (AWS, Azure, and/or GCP) and in containerized / Kubernetes workloads.
Preferences:
  • Familiarity with workload-identity and machine-identity standards: SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation.
  • Working understanding of AI/agentic systems: LLMs, agent frameworks, tool-calling, and emerging authentication patterns such as the Model Context Protocol (MCP).
  • Experience in a regulated industry (financial services, healthcare, etc.) and with associated compliance regimes.
  • Relevant certifications, e.g., CISSP, CyberArk (Defender/Sentry), SailPoint, Ping, or a major cloud security certification.
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Pay Range:

$122,570.00 - $204,249.00

Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!

Company Overview:

LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. As a leader in the financial advisor-mediated marketplace(6) , LPL supports over 32,000 financial advisors and the wealth management practices of approximately 1,100 financial institutions, servicing and custodying approximately $2.3 trillion in brokerage and advisory assets on behalf of approximately 8 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services, ensuring that advisors and institutions have the flexibility to choose the business model, services, and technology resources they need to run thriving businesses. For further information about LPL, please visit www.lpl.com.

At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.

For further information about LPL, please visit www.lpl.com.

Join the LPL team and help us make a difference by turning life’s aspirations into financial realities. Principals only. EOE.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • Fort Mill (SC)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • Austin (TX)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • San Diego (CA)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial • New York (NY)

On-site
USD 123,000 - 204,000
AVP, IAM AI Engineer
AVP, IAM AI Engineer

LPL Financial LLC • Town of Charlotte (NY), Fort Mill (SC)

On-site
USD 123,000 - 204,000
401K matching
health benefits
employee stock options
+3
AVP, Agentic Platform Controls, Non-Human Identity & AI Security
AVP, Agentic Platform Controls, Non-Human Identity & AI Security

LPL Financial LLC • Town of Charlotte (NY), Fort Mill (SC)

On-site
USD 109,000 - 181,000
AI IAM Architect
AI IAM Architect

LPL Financial • New York (NY)

Hybrid
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+1
AI IAM Architect
AI IAM Architect

LPL Financial • Austin (TX)

Hybrid
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2
AI IAM Architect
AI IAM Architect

LPL Financial • San Diego (CA)

On-site
USD 153,000 - 256,000
401K matching
Health benefits
Employee stock options
+2
AVP, Agentic Platform Controls, Non-Human Identity & AI Security
AVP, Agentic Platform Controls, Non-Human Identity & AI Security

LPL Financial • Fort Mill (SC)

On-site
USD 109,000 - 181,000
401K matching
Health benefits
Employee stock options
+1