Our Client is seeking an AI Lead/Agentic Identity Engineer .
Responsibilities:
- Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability
- Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement
- Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution
- Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services
- Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls
- Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows
- Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access
- Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers
- Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns
- Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities
Requirements
- 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security
- Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale
- Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models
- Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments
- Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs
- Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control
- Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation
- Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives
- Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems
-
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#AlbionarcJobs#FintechJobs
#AsiaJobs#MiddleEastCareers
#TechTalent#FintechRecruitment
#FinanceOpportunities#
