Responsibilities
- Design identity and access management architectures covering authentication, authorization, federation, lifecycle management, and governance for AI systems and agents.
- Architect and productize identity services, including reference architectures, platform evaluation, selection, and service definition.
- Define AI agent identity lifecycles covering human sponsorship, declared scope, short-lived credentials, and revocation.
- Bring AI models, agents, and datasets into shared entitlement models and access certification processes.
- Design delegated authorization using OAuth 2.1, RFC 8693 token exchange, on-behalf-of flows, DPoP, mTLS, OIDC claims, and audiences.
- Build or integrate production authorization systems, policy engines, authorization services, or token-level identity-provider integrations.
- Implement policy-as-code controls for agent scopes and tool permissions using OPA/Rego or Cedar.
- Define identity assertions, tool allow-listing, and per-task isolation for Model Context Protocol and agent frameworks.
- Design retrieval architectures that enforce asker identity entitlements at prompt time and during RAG retrieval.
- Deploy AI gateways or prompt-control layers integrated with identity providers and entitlement models.
- Design non-human identity governance and SPIFFE/SPIRE workload identity for agent credentials.
Requirements
- Deep identity and access management architecture experience across authentication, authorization, federation, lifecycle, and governance, applied to AI systems and agents.
- Experience architecting and productizing identity services rather than only implementing them.
- Hands-on experience with at least one of Microsoft Entra Agent ID, Okta cross-app access, SailPoint Agent Identity Security, or Cisco/Astrix.
- Experience with SailPoint ISC or Saviynt at registry and API level, and SCIM 2.0.
- Protocol-level delegated authorization expertise with OAuth 2.1, RFC 8693, on-behalf-of flows, DPoP, mTLS, OIDC claims, and audiences.
- Production experience building or integrating an authorization system, policy engine, authorization service, or token-level identity-provider integration.
- Experience with OPA/Rego or Cedar for policy as code.
- Experience with Model Context Protocol or agent frameworks, including tool-call identity, tool allow-listing, and per-task isolation.
- Experience with RAG entitlement enforcement, AI gateways or prompt-control layers, Microsoft Entra ID or Okta, and SPIFFE/SPIRE.
- Good to have familiarity with Microsoft, Google, AWS, Anthropic, Mistral, Aleph Alpha, OCSF, EU AI Act, GDPR, works-council constraints, and MITRE ATLAS.
- The posting emphasizes service-architecture experience, SOC fluency for ITE, key ceremony and PKI design depth for Machine Identity, and protocol-level authorization and IAM architecture depth for Identity for AI.
Benefits
- Work location is Bangalore or Mumbai.
- Atos states that diversity and inclusion are embedded in its work environment.
About Atos
Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. €7.2 billion (at the go-forward perimeter), operating in 54 countries under two brands - Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris. Atos is the services brand of Atos Group, delivering AI powered, secure and end to end digital services to public and private organizations worldwide. Atos designs, builds and run digital environments that are critical to performance, resilience and sovereignty, helping clients keep control of their data, infrastructure and compliance, with clear accountability from strategy to operations. With more than 54,000 people serving 4,500+ clients in 54 countries, Atos helps modernize core IT, accelerate cloud and data transformation, strengthen cybersecurity and enable secure digital workplaces, delivering impact for clients, employees and society at large. Atos offers end-to-end IT services across the cloud, cybersecurity, data and AI, application services, smart platforms and digital workplace, as well as localized consulting and advisory services under its brand Atos Amplify. Atos is trusted to operate complex, business-critical environments, especially in regulated and sovereign contexts.
