MTS Lead, Identity and Access Management
Core
Architecting, building, and operating a zero-trust identity infrastructure for a research lab's massive-scale compute environments and GPU clusters.
Role type
Principal Security Architect & Software Engineer (Identity & Access Management)
Builds
Cloud-native identity architecture, phishing-resistant authentication systems, JIT credentialing for GPU clusters, and workload identity frameworks.
Domain
AI Research Security / Cloud Infrastructure / Zero Trust Architecture
Deliverable
production ML models | infrastructure
Required skills
Zero-trust architecture design, hardware-backed authentication (WebAuthn/FIDO2), Just-in-time credentialing, Privileged Access Management (PAM), Workload identity (SPIFFE/SPIRE), Policy as Code (OPA/Cedar), Cryptographic fundamentals, Cloud-native IAM (AWS/GCP/OCI), Infrastructure as Code (Terraform/Pulumi), Software engineering (Go/Python/Rust)
Preferred skills
Experience with nation-state threat modeling, Adversary detection logic, Open-source security tooling, Developer-first security design
Technologies
Okta, OIDC, OAuth 2.0, Cloudflare Access, Tailscale, WireGuard, Teleport, HashiCorp Boundary, SPIFFE, SPIRE, OPA, Rego, Cedar, AWS, GCP, OCI, Kubernetes, Terraform, Pulumi
Responsibilities
Design and implement resilient cloud-native identity architecture; Mandate and enforce hardware-backed phishing-resistant authentication globally; Build short-lived, just-in-time credentialing systems for GPU cluster access; Architect service-to-service communication frameworks using SPIFFE/SPIRE; Treat authorization policies as code using OPA/Cedar; Build automated provisioning workflows via SCIM and API-first tooling.
Seniority
Principal, hands-on IC with strategic oversight