AI Lead / Agentic Identity Engineer
Location: Remote - with occasional travel to the Miami office Duration: 5 months
We are seeking a Lead AI / Agentic Identity Engineer to lead the higher-level design and implementation of an enterprise identity architecture for AI agents, autonomous workflows, and other non-human identities. This role will define how AI agents are represented, governed, authorized, monitored, and controlled across internal, guest-facing, cloud, and hybrid environments. The architect will establish the target-state identity model, reference architecture, implementation roadmap, and reusable design patterns needed to treat AI agents as first-class governed identities. The role is expected to bridge strategy and delivery: translating emerging agentic AI security requirements into practical controls, integration patterns, and implementation guidance that engineering teams can execute. This is a hands-on architecture leadership role. The ideal candidate can design across IAM, workload identity, cloud security, API authorization, AI runtime controls, and governance processes while also guiding proof-of-concepts, platform integrations, and adoption across product, security, infrastructure, and application teams.
Engagement objectives & key responsibilities:
- Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability.
- Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement.
- Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution.
- Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services.
- Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls.
- Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows.
- Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access.
- Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers.
- Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns.
- Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities.
- Define telemetry, logging, audit, and traceability requirements to capture user → agent → sub-agent → tool → data access chains for compliance, forensics, and operational monitoring.
- Lead architecture reviews, threat modeling sessions, design workshops, and implementation planning with IAM, AI/ML, platform, cloud, application, and product teams.
- Produce executive-ready roadmaps, architecture decision records, implementation patterns, control mappings, and knowledge-transfer materials for long-term internal ownership.
Required skills & experience:
- 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security.
- Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale.
- Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models.
- Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control.
- Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments.
- Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems.
- Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation.
- Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs.
- Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives.
Preferred / nice to have:
- Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards.
- Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, or certificate lifecycle management.
- Experience with policy-as-code, runtime authorization, ABAC/ReBAC models, or centralized policy decision points.
- Experience designing controls for regulated, SOX-relevant, PCI, privacy-sensitive, or high-availability environments.
- Experience building maturity models, capability roadmaps, control frameworks, or executive-level investment cases for emerging security domains.
Comments for Suppliers: Submit candidates based on the job description, not on the rate card. The rate can be substantially higher than listed, based on the right qualifications.
AI Lead / Agentic Identity Engineer in Remote at Unknown Company
This position is listed as full time and able to be worked remotely.