Назад
Company hidden
4 дня назад

AI Identity & Endpoint Controls Lead

158 600 - 285 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead/director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
AI Identity & Endpoint Controls Lead (AI/Cybersecurity): Designing and implementing enterprise controls for non-human identities, agentic AI governance, credential security, and endpoint execution across Windows and macOS with an accent on identity lifecycle management, policy enforcement, and security telemetry. Focus on building the AI security control plane, integrating secrets and endpoint platforms, and solving complex governance and enforcement challenges at enterprise scale.

Location: Cambridge, Massachusetts, United States; 70% in-office work model

Salary: $158,600–$285,500 annually, with potential annual bonus, incentive compensation, or equity.

Company

hirify.global develops mRNA-based medicines, vaccines, and delivery technologies for infectious diseases, immuno-oncology, rare diseases, and cardiovascular conditions.

What you will do

  • Own the technical strategy, architecture, and roadmap for non-human identity, credential security, agentic AI identity governance, and endpoint execution controls.
  • Lead and develop senior security engineers while coordinating contingent workers and professional services partners.
  • Evaluate and deploy secrets management, agentic identity governance, and endpoint application allow-listing platforms, including vendor selection and proof-of-value exercises.
  • Design credential lifecycle controls including vaulting, brokered access, short-lived credentials, workload identity, rotation, attestation, and decommissioning.
  • Build the AI security control plane with enforcement points, approval workflows, policy guardrails, exception handling, and audit telemetry.
  • Lead Windows and macOS execution control, configuration hardening, detection, reporting, compliance, and incident-response collaboration.

Requirements

  • 8+ years of experience in security engineering, identity engineering, platform engineering, or a related field, with principal-level technical leadership.
  • Deep knowledge of non-human identities, programmatic credentials, microservices, CI/CD, infrastructure as code, automation, and APIs.
  • Hands-on experience with secrets management, PKI and certificate lifecycles, token issuance and exchange, short-lived credentials, and automated rotation.
  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, mTLS, key management, least privilege, and scoped permissions.
  • Experience implementing endpoint execution controls and configuration baselines across Windows and macOS, including policy rollout and exception management.
  • Must qualify as a U.S. person under U.S. export-control requirements; non-U.S. persons are not eligible and visa sponsorship is unavailable.

Nice to have

  • Experience with HashiCorp Vault, Conjur, Azure Key Vault, AWS Secrets Manager, or GCP Secret Manager.
  • Experience with workload identity and federation, including SPIFFE/SPIRE or Kubernetes service account federation.
  • Familiarity with Microsoft Intune, Jamf, MDM configuration profiles, Group Policy, WDAC, code signing, macOS notarization, and security telemetry pipelines.
  • Experience building AI and automation guardrails, threat models, and measurable security outcomes.

Culture & Benefits

  • 70/30 in-office work model emphasizing collaboration, mentorship, and direct teamwork.
  • Competitive healthcare and voluntary benefit programs.
  • Fitness, mindfulness, mental health, and broader well-being resources.
  • Family planning support, including fertility, adoption, and surrogacy benefits.
  • Paid vacation, volunteer days, sabbatical, global recharge days, and discretionary year-end shutdown.
  • Savings and investment programs plus location-specific benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →