Unknown Company

AI Lead / Agentic Identity Engineer

Remote • Posted 2 weeks ago
Remote Full Time Architecture and Engineering Occupations
AI Lead / Agentic Identity Engineer

Location: Remote - with occasional travel to the Miami office Duration: 5 months

We are seeking a Lead AI / Agentic Identity Engineer to lead the higher-level design and implementation of an enterprise identity architecture for AI agents, autonomous workflows, and other non-human identities. This role will define how AI agents are represented, governed, authorized, monitored, and controlled across internal, guest-facing, cloud, and hybrid environments. The architect will establish the target-state identity model, reference architecture, implementation roadmap, and reusable design patterns needed to treat AI agents as first-class governed identities. The role is expected to bridge strategy and delivery: translating emerging agentic AI security requirements into practical controls, integration patterns, and implementation guidance that engineering teams can execute. This is a hands-on architecture leadership role. The ideal candidate can design across IAM, workload identity, cloud security, API authorization, AI runtime controls, and governance processes while also guiding proof-of-concepts, platform integrations, and adoption across product, security, infrastructure, and application teams.

Engagement objectives & key responsibilities:

  • Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability.
  • Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement.
  • Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution.
  • Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services.
  • Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls.
  • Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows.
  • Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access.
  • Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers.
  • Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns.
  • Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities.
  • Define telemetry, logging, audit, and traceability requirements to capture user → agent → sub-agent → tool → data access chains for compliance, forensics, and operational monitoring.
  • Lead architecture reviews, threat modeling sessions, design workshops, and implementation planning with IAM, AI/ML, platform, cloud, application, and product teams.
  • Produce executive-ready roadmaps, architecture decision records, implementation patterns, control mappings, and knowledge-transfer materials for long-term internal ownership.

Required skills & experience:

  • 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security.
  • Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale.
  • Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models.
  • Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control.
  • Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments.
  • Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems.
  • Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation.
  • Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs.
  • Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives.

Preferred / nice to have:

  • Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards.
  • Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, or certificate lifecycle management.
  • Experience with policy-as-code, runtime authorization, ABAC/ReBAC models, or centralized policy decision points.
  • Experience designing controls for regulated, SOX-relevant, PCI, privacy-sensitive, or high-availability environments.
  • Experience building maturity models, capability roadmaps, control frameworks, or executive-level investment cases for emerging security domains.

Comments for Suppliers: Submit candidates based on the job description, not on the rate card. The rate can be substantially higher than listed, based on the right qualifications.

AI Lead / Agentic Identity Engineer in Remote at Unknown Company

This position is listed as full time and able to be worked remotely.

Back to Job Search