Uniphore

Senior Security Engineer, Identity & Machine Access

Uniphore
Apply
2 months ago
Chennai, India or Bengaluru, IndiaSenior

Responsibilities

  • Own the non-human identity program, including inventory, governance, and security for service accounts, workload identities, API keys, tokens, OAuth clients, certificates, applications, pipelines, AI agents, and MCP servers.
  • Design and operate least-privilege, short-lived, auditable machine credentials, including issuance, scoping, rotation, and revocation.
  • Define authorization models for AI agents and tool access, ensuring agents can access only explicitly entitled resources.
  • Own Privileged Access Management across engineering and cloud environments, including vaulting, just-in-time access, session control, and elimination of standing privilege.
  • Own secrets management by centralizing and rotating secrets, eliminating hardcoded credentials, and embedding secret hygiene into CI/CD and runtime environments.
  • Automate identity governance, access reviews, entitlement management, and least-privilege enforcement across human and non-human identities.
  • Architect multi-cloud IAM across AWS and Rackspace, including workload identity and cross-account or cross-provider trust.
  • Govern Entra application registrations and OAuth scope management.
  • Partner with DevOps and engineering to embed automated identity controls into pipelines and Infrastructure as Code.
  • Partner with IT on corporate endpoint and email security baselines while IT retains ownership of device management.
  • Create and maintain documentation and standards for identity, secrets, and privileged-access processes.

Requirements

  • 5–7 years of hands-on Identity and Access Management engineering experience.
  • Expertise securing machine and non-human identities, including service accounts, workload identity, API keys, tokens, certificates, and secrets.
  • Deep understanding of service-to-service authentication and authorization using OAuth 2.0, OIDC, JWT, mTLS, and workload authentication patterns.
  • Hands-on experience deploying and operating a Privileged Access Management solution in engineering environments using just-in-time and least-privilege models.
  • Deep experience securing resources with AWS IAM; multi-cloud identity experience is strongly preferred.
  • Strong understanding of RBAC, ABAC, least privilege, and identity governance.
  • Preferred experience securing identity for AI, ML, LLM, or agentic systems, including agent credentials and MCP or tool-access authorization.
  • Scripting experience with Python or PowerShell and Infrastructure as Code experience with Terraform.
  • Hands-on experience with HashiCorp Vault, cloud secret managers, certificate lifecycle management, and SPIFFE/SPIRE or equivalent workload-identity tooling.
  • Experience automating secrets and certificate lifecycles.
  • Relevant certifications such as CISSP and a degree in Computer Science, Information Security, or a related field are preferred.

Benefits

  • Preferred locations are Bangalore or Chennai, India.
  • Uniphore is an equal opportunity employer committed to diversity in the workplace.

Tech Stack

Categories

Uniphore

About Uniphore

501-1,000 employees
Contact me