CareerPlanSign in

MTS Lead, Identity and Access Management

New York, NY💼 Full-time🗓 2026-07-14 → 2026-09-25

Core

Architecting, building, and operating a zero-trust identity infrastructure for a research lab's massive-scale compute environments and GPU clusters.

Role type

Principal Security Architect & Software Engineer (Identity & Access Management)

Builds

Cloud-native identity architecture, phishing-resistant authentication systems, JIT credentialing for GPU clusters, and workload identity frameworks.

Domain

AI Research Security / Cloud Infrastructure / Zero Trust Architecture

Deliverable

production ML models | infrastructure

Required skills

Zero-trust architecture design, hardware-backed authentication (WebAuthn/FIDO2), Just-in-time credentialing, Privileged Access Management (PAM), Workload identity (SPIFFE/SPIRE), Policy as Code (OPA/Cedar), Cryptographic fundamentals, Cloud-native IAM (AWS/GCP/OCI), Infrastructure as Code (Terraform/Pulumi), Software engineering (Go/Python/Rust)

Preferred skills

Experience with nation-state threat modeling, Adversary detection logic, Open-source security tooling, Developer-first security design

Technologies

Okta, OIDC, OAuth 2.0, Cloudflare Access, Tailscale, WireGuard, Teleport, HashiCorp Boundary, SPIFFE, SPIRE, OPA, Rego, Cedar, AWS, GCP, OCI, Kubernetes, Terraform, Pulumi

Responsibilities

Design and implement resilient cloud-native identity architecture; Mandate and enforce hardware-backed phishing-resistant authentication globally; Build short-lived, just-in-time credentialing systems for GPU cluster access; Architect service-to-service communication frameworks using SPIFFE/SPIRE; Treat authorization policies as code using OPA/Cedar; Build automated provisioning workflows via SCIM and API-first tooling.

Seniority

Principal, hands-on IC with strategic oversight

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.