Base Salary
$150k - $180k/yr
Responsibilities
- Design the identity model for AI agents, including delegated on-behalf-of actions, composite identities, and audit attribution.
- Build the real-time authorization engine that determines what an agent is allowed to do and help select its policy technology.
- Define trust for identities issued by external platforms such as Microsoft Entra and Salesforce and by emerging agent standards such as OpenID Connect.
- Build authorization and continuous-evaluation capabilities using live session and decision signals from existing identity products.
- Own the interfaces and contracts used by the rest of the platform and maintain them as the platform scales.
- Act as a technical leader across teams by setting direction and raising engineering standards.
Requirements
- Typically 10 or more years of software engineering experience with deep expertise in identity, authorization, or distributed-systems security.
- Hands-on experience building authorization or policy systems such as Cedar, OPA, OpenFGA, or a comparable engine.
- Working knowledge of OAuth, OpenID Connect, SPIFFE, SPIRE, or workload identity federation.
- Track record of designing scalable systems and interfaces that other teams build on.
- Ability to lead technical decisions spanning multiple teams and communicate them clearly to varied audiences.
- Experience securing AI or agentic systems is preferred.
- Contributions to identity, authorization, or security standards or open source are preferred.
- Background in privileged access, secrets management, or identity governance is preferred.
Benefits
- Healthcare insurance, pension/retirement matching, comprehensive life insurance, employee assistance program, time off plans, paid company holidays, competitive salaries, and a meaningful bonus program.
- The role is not open to candidates who require current or future US work authorization, including F1-OPT, F1-CPT, H-1B, TN, L-1, and J1 visas.
- Employment requires a comprehensive criminal background check and verification of education and employment; publicly posted social media sites may also be reviewed.
About Delinea
Delinea helps organizations reduce identity-based risk while enabling secure, seamless access across the modern enterprise. As the identity security control plane, Delinea protects every human, machine, and AI identity with real-time, context-aware access. It replaces static privilege with just-in-time, policy-driven controls that maintain security without slowing down the business. Delinea continuously discovers identities, privileges, and access pathways, giving teams full visibility into who has access and why. With unified enforcement, automation, and auditing, organizations can apply least privilege consistently and move toward Zero Standing Privilege at their own pace, without requiring a rip-and-replace approach.