
AVP, IAM AI Engineer
LPL Financial27 days ago
Austin, TX, USA +3 moreStaff+
Base Salary
$123k - $204k/yr
Responsibilities
- Automate identity runtime controls for human and non-human identities, including authentication, authorization, and policy enforcement.
- Design and build governance controls for AI agents and non-human identities across provisioning, entitlement, rotation, certification, attestation, and deprovisioning.
- Develop secrets-manager workflows for AI systems, including rotation, just-in-time credentials, ephemeral credentials, and secure secret delivery.
- Define least-privilege authorization models and express them as policy-as-code.
- Establish identity-flow standards and reference architectures for user-to-agent, agent-to-agent, and workload-to-service authentication and authorization.
- Partner with engineering and data science teams to embed IAM, authentication, authorization, and secrets handling into AI application development.
- Support deployment and adoption of IAM controls for end users.
- Integrate identity telemetry with SIEM and SOC tooling, build NHI and agent-behavior monitoring, and support incident response.
- Partner with GRC, risk, and audit stakeholders to satisfy regulatory and internal requirements and produce audit evidence.
- Recruit, build, mentor, and lead a technical team and set the roadmap for non-human and agentic IAM.
Requirements
- At least 5 years of IAM or information-security experience, including hands-on engineering.
- Demonstrated experience building or leading technical teams.
- At least 5 years of experience with Ping Identity, including PingFederate, PingOne, and PingAccess, or a comparable access-management or federation platform.
- At least 5 years of experience with SailPoint, including IdentityIQ or Identity Security Cloud, or a comparable IGA platform.
- At least 3 years of experience with Idira, CyberArk formerly Conjur, HashiCorp Vault, or a comparable secrets-management platform.
- Working knowledge of identity and authorization for users and agents, including user-to-agent and agent-to-agent patterns, OIDC, OAuth 2.0/2.1 tokens, and API keys.
- Proficiency in a scripting or programming language such as Python, infrastructure-as-code such as Terraform, CI/CD pipelines, and REST API integration.
- Experience applying IAM in AWS, Azure, and/or GCP environments and in containerized or Kubernetes workloads.
- Familiarity with SPIFFE/SPIRE, OAuth token exchange under RFC 8693, mTLS, and cloud workload-identity federation is preferred.
- Understanding of LLMs, agent frameworks, tool-calling, and authentication patterns such as the Model Context Protocol is preferred.
- Experience in a regulated industry and with applicable compliance regimes is preferred.
- Relevant certifications such as CISSP, CyberArk Defender/Sentry, SailPoint, Ping, or a major cloud-security certification are preferred.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Benefits
- Hybrid work arrangement.
- Pay range of $122,570.00 to $204,249.00 in base salary.
- 401(k) matching, health benefits, employee stock options, paid time off, and volunteer time off.