AI Lead / Agentic Identity Engineer

Expert In Recruitment Solutions

  • Tampa, FL
  • 4 days ago
  • Remote

    Highlights

    The ideal candidate can design across IAM, workload identity, cloud security, API authorization, AI runtime controls, and governance processes while also guiding proof-of-concepts, platform integrations, and adoption across product, security, infrastructure, and application teams. Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access.

    Numbers & Facts

    LocationTampa, FL (
    Remote
    )

    Description




    Role: AI Lead / Agentic Identity Engineer
    Location: Remote - with occasional travel to the Miami office
    Duration: 5 months





    Job Description: About the engagement

    We are seeking a Lead AI / Agentic Identity Engineer to lead the higher-level design and implementation of an enterprise identity architecture for AI agents, autonomous workflows, and other non-human identities. This role will define how AI agents are represented, governed, authorized, monitored, and controlled across internal, guest-facing, cloud, and hybrid environments.

    The architect will establish the target-state identity model, reference architecture, implementation roadmap, and reusable design patterns needed to treat AI agents as first-class governed identities. The role is expected to bridge strategy and delivery: translating emerging agentic AI security requirements into practical controls, integration patterns, and implementation guidance that engineering teams can execute.

    This is a hands-on architecture leadership role. The ideal candidate can design across IAM, workload identity, cloud security, API authorization, AI runtime controls, and governance processes while also guiding proof-of-concepts, platform integrations, and adoption across product, security, infrastructure, and application teams.

    Engagement objectives & key responsibilities

    Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability.

    Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement.

    Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution.

    Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services.

    Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls.

    Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows.

    Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access.

    Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers.

    Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns.

    Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities.

    Define telemetry, logging, audit, and traceability requirements to capture user agent sub-agent tool data access chains for compliance, forensics, and operational monitoring.

    Lead architecture reviews, threat modeling sessions, design workshops, and implementation planning with IAM, AI/ML, platform, cloud, application, and product teams.

    Produce executive-ready roadmaps, architecture decision records, implementation patterns, control mappings, and knowledge-transfer materials for long-term internal ownership.

    Required skills & experience

    10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security.

    Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale.

    Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models.

    Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control.

    Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments.

    Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems.

    Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation.

    Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs.

    Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives.

    Preferred / nice to have

    Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards.

    Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, or certificate lifecycle management.

    Experience with policy-as-code, runtime authorization, ABAC/ReBAC models, or centralized policy decision points.

    Experience designing controls for regulated, SOX-relevant, PCI, privacy-sensitive, or high-availability environments.

    Experience building maturity models, capability roadmaps, control frameworks, or executive-level investment cases for emerging security domains.
    Comments for Suppliers: Submit candidates based on the job description, not on the rate card. The rate can be substantially higher than listed, based on the right qualifications.

    Similar Jobs

    See more jobs