Security Engineer, Agentic AI & Identity

Blueface Ltd

Mount Laurel Township (NJ)

On-site

USD 105,000 - 158,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Comcast is seeking an enterprise IAM leader to drive the strategy, design, implementation, and operational support of identity security across Azure, AWS, and GCP, with emphasis on authentication, federation, workload identities, and Zero Trust for modern cloud and AI ecosystems.

You will partner with security and platform teams to design scalable IAM architectures, automate controls, and produce technical documentation. Strong experience with Entra ID CA and multi-cloud environments is required.

Qualifications

  • 5+ years of IAM experience with authentication, federation, and access management in enterprise environments.
  • Hands-on experience with Microsoft Entra ID Conditional Access and workload identities.
  • Experience with SAML, OAuth 2.0, OpenID Connect, and modern authentication architectures.
  • Knowledge of Agentic AI tech including MCP, RAG, LLMs, and related frameworks.

Responsibilities

  • Architect, deploy, and maintain Microsoft Entra ID Conditional Access policies and Zero Trust controls.
  • Develop secure identity solutions for users, apps, APIs, workloads, and AI agents.
  • Design Agent Identity frameworks using Agent IDs, Workload Identity Federation, SPIFFE/SPIRE.
  • Collaborate with teams to integrate identity controls into Agentic AI solutions.
  • Implement IAM automation via PowerShell, Python, Graph APIs, REST, Terraform.
  • Monitor security, troubleshoot authentication and access issues across environments.

Skills

IAM
Authentication
Federation
Zero Trust
Agentic AI
Multi-cloud
SAML
OAuth 2.0
OIDC
Terraform
PowerShell
Python
Microsoft Graph APIs
REST APIs

Education

Bachelor's degree

Tools

Terraform
PowerShell
Python
Microsoft Graph APIs
REST APIs

Job description

Job Summary

This role is responsible for driving the strategy, design, implementation, and operational support of enterprise AI Identity and Access Management solutions, while advancing identity security capabilities for modern cloud, API, and Agentic AI ecosystems. The position serves as a subject matter expert for authentication, federation, workload identities, Zero Trust architecture, and secure AI agent interactions across multi‑cloud environments.

What You’ll Do
  • Architect, deploy, and maintain Microsoft Entra ID Conditional Access Policies, including risk‑based access controls, workload identities, and Zero Trust security controls.
  • Develop and manage secure identity solutions for users, applications, APIs, workloads, and AI agents across hybrid and multi‑cloud environments.
  • Design and implement Agent Identity frameworks utilizing Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, service principals, and machine‑to‑machine authentication mechanisms.
  • Partner with security, platform, and application teams to integrate identity controls into Agentic AI solutions leveraging MCP, RAG, A2A communications, LLMs, LangChain, LangGraph, Semantic Kernel, and related technologies.
  • Establish and enforce Zero Trust security principles across enterprise applications, APIs, cloud workloads, and AI‑driven systems.
  • Evaluate, troubleshoot, and resolve complex authentication, authorization, federation, and application access issues across enterprise environments.
  • Design secure authentication and authorization architectures for modern applications and APIs, incorporating token‑based security and identity best practices.
  • Implement IAM automation and operational efficiencies through PowerShell, Python, Microsoft Graph APIs, REST APIs, Terraform, and Infrastructure as Code practices.
  • Collaborate with cloud engineering teams to integrate identity platforms across Azure, AWS, and GCP environments.
  • Develop and maintain identity architecture standards, security patterns, implementation guides, and operational procedures.
  • Create technical documentation, workflows, architecture diagrams, and knowledge articles using Markdown, Mermaid, and related documentation tools.
  • Monitor emerging technologies and industry trends within Identity Security, Agentic AI, and cloud security, driving adoption of innovative capabilities where appropriate.
  • Participate in security reviews, threat modeling exercises, and architecture governance processes to ensure compliance with enterprise security requirements.
What You’ll Need
  • 5+ years of IAM experience, with a strong focus on authentication, federation, application onboarding, access management, and identity security in enterprise environments.
  • Hands‑on experience designing, implementing, and troubleshooting Microsoft Entra ID Conditional Access Policies, including workload identities and risk‑based access controls.
  • Strong experience onboarding and integrating enterprise applications using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern authentication architectures.
  • Solid understanding of Agentic AI technologies including MCP, RAG, A2A communication, LLMs, Agent SDKs, LangChain, LangGraph, Semantic Kernel, and related frameworks.
  • Strong knowledge of Agent Identity concepts, including Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, SSI, service principals, and machine‑to‑machine authentication.
  • Experience applying Zero Trust principles across users, applications, APIs, workloads, and AI Agents.
  • Good understanding of application architecture, API security, token‑based authentication, and secure application design.
  • Experience working in multi‑cloud environments (Azure, AWS, GCP) and integrating identity services across platforms.
  • Experience with IAM automation using PowerShell, Python, Microsoft Graph APIs, REST APIs, and Infrastructure as Code tools such as Terraform is preferred.
  • Ability to troubleshoot complex authentication, authorization, and application access issues in large‑scale enterprise environments.
Soft Skills
  • Ability to quickly learn and adapt to emerging technologies, particularly within Identity, Security, and Agentic AI domains.
  • Strong communication and presentation skills, with the ability to explain technical concepts to both technical and non‑technical audiences.
  • Experience creating and maintaining technical documentation, architecture diagrams, and workflows using Markdown, Mermaid, and related tools.
  • Strong analytical, problem‑solving, and collaboration skills, with the ability to work effectively across security, engineering, and business teams.
  • Demonstrated ownership, accountability, and ability to drive technical initiatives from design through production support.
Disclaimer

This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.

Compensation & Benefits

Primary Location Pay Range: $104,958.81 - $157,438.22. Comcast intends to offer the selected candidate base pay within this range, dependent on job‑related, non‑discriminatory factors such as experience. The total rewards package includes bonuses and commissions as applicable. You will also receive best‑in‑class benefits to support you physically, financially, and emotionally.

Education & Certifications
  • Bachelor's Degree (Required). Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.
  • Relevant certifications (if applicable).
  • Relevant work experience: 5‑7 years.
Equal Opportunity Employment

Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Agentic AI & Identity
Security Engineer, Agentic AI & Identity

Comcast • Mount Laurel Township (NJ)

On-site
USD 104,959 - 157,438
Cyber Security Engineer - RADIUS, TACACS+
Cyber Security Engineer - RADIUS, TACACS+

Blueface Ltd • Mount Laurel Township (NJ), Northern (KY)

Hybrid
USD 105,000 - 157,000
Engineer 6, Machine Learning, Data & AI
Engineer 6, Machine Learning, Data & AI

Blueface Ltd • Philadelphia

On-site
USD 224,000 - 352,000
Engineer 6, Machine Learning, Data & AI
Engineer 6, Machine Learning, Data & AI

Comcast • Philadelphia

On-site
USD 224,000 - 352,000
Engineer 6, Machine Learning, Data & AI
Engineer 6, Machine Learning, Data & AI

Comcast • Washington

On-site
USD 224,000 - 352,000
Senior Applied AI Engineer
Senior Applied AI Engineer

Comcast • Pennsylvania

On-site
USD 140,000 - 190,000
Senior Applied AI Engineer
Senior Applied AI Engineer

Comcast • Philadelphia

On-site
USD 140,000 - 190,000
Senior Platform Engineer, Agentic Systems
Senior Platform Engineer, Agentic Systems

Blueface Ltd • Philadelphia

On-site
USD 140,000 - 180,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Blueface Ltd • Philadelphia

On-site
USD 120,000 - 190,000
Sr. Engineer, MarTech Agentic Platforms
Sr. Engineer, MarTech Agentic Platforms

Blueface Ltd • Philadelphia

On-site
USD 120,000 - 180,000