AI Identity Engineer
Core
Design and operationalize runtime guardrails and identity-driven control planes to govern AI agents as non-human identities within distributed, agentic systems.
Role type
Senior IC security engineer specializing in AI agent identity and access management
Builds
Secure runtime environments for consumer-facing and internal agentic services
Domain
Artificial Intelligence security, Identity and Access Management (IAM), Cloud-native security
Deliverable
production ML models | product features | infrastructure
Required skills
Enterprise IAM and non-human identity solutions, Web application and API security, Fine-grained least-privilege access modeling, AI-enabled system security, MCP security standards, Agent runtime authorization, WAF and API gateway configuration, Cloud-native service-to-service security, NHI lifecycle management, OAuth 2.0/2.1 and OIDC, Token exchange (OBO), PKCE, Audience binding, Short-lived tokens, Workload identity (SPIFFE/SPIRE), mTLS, PKI/certificate-based authentication, Secrets management, Zero Trust architecture
Preferred skills
Reasoning about non-deterministic execution, Applying deterministic controls to agentic systems
Technologies
OAuth, OIDC, SPIFFE, SPIRE, mTLS, PKI, WAF, API Gateways, Cloud IAM
Responsibilities
Build an IAM program for AI agents treating them as governed non-human identities, Design and operationalize runtime guardrails across guest-facing and internal systems, Implement identity-aware authorization and policy enforcement, Secure non-deterministic systems and tool-calling agents using identity-driven control planes, Support both consumer-facing and internal agentic services, Ground solutions in established web, API, and edge-security practices