Назад
Company hidden
3 дня назад

Principal IAM AI Engineer (AI)

104 300 - 193 700$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal IAM AI Engineer (AI/IAM): Building authentication, authorization, credential management, and compliance infrastructure for AI agents, machine identities, and workloads across global travel technology with an accent on zero-standing-privilege access, lifecycle governance, and secure AI adoption. Focus on designing AWS identity architecture, automating secrets and credentials, integrating controls into AI development, and leading enterprise machine identity programs.

Location: United States

Salary: $104,300–$193,700 base salary annually, plus an eligible discretionary annual bonus.

Company

hirify.global operates global business travel technology, including booking platforms, payment flows, traveler data protection, and supplier integrations.

What you will do

  • Build and automate runtime authentication, authorization, and identity controls for non-human identities, AI agents, and workloads.
  • Develop lifecycle governance for machine identities and agents, including discovery, registration, permissions, access reviews, credential rotation, and secure retirement.
  • Implement credential management systems with short-lived credentials, automated secret cycling, and protected runtime distribution.
  • Design fine-grained, zero-standing-privilege authorization using infrastructure-as-code and declarative policy frameworks.
  • Partner with application development, ML, InfoSec, compliance, risk, and audit teams to embed identity controls throughout AI initiatives.
  • Lead the engineering team, set technical strategy, advise senior leadership, evaluate vendors, and mentor engineers and architects.

Requirements

  • 8+ years of IAM or cybersecurity experience, including 5+ years at architect or principal level.
  • Enterprise-scale experience designing identity, access, and governance controls for service accounts, workload identities, and AI agents.
  • Strong AWS or equivalent public cloud identity experience at multi-account scale, including ephemeral credentials, OIDC federation, secrets, certificates, and least privilege.
  • Hands-on experience with Okta or a comparable federation platform, Saviynt or a comparable IGA platform, and PAM tools such as Idira, CyberArk, or HashiCorp Vault.
  • Mastery of OAuth, OIDC, SAML, SCIM, JWT, mTLS, and machine-to-machine identity across on-premises, hybrid, and multi-cloud environments.
  • Strong cross-functional leadership, communication, and judgment in an emerging identity discipline.

Nice to have

  • ITDR, identity posture management, SPIFFE/SPIRE, service mesh identity, or externalized authorization experience.
  • Knowledge of emerging AI regulations and frameworks, Model Context Protocol, and agent-to-agent patterns.
  • Kubernetes and container security experience with workload identity.
  • Automation experience with Python, PowerShell, or Terraform.
  • CISSP, CISM, CCSP, CyberArk, Okta, AWS Security, or architecture certifications.

Culture & Benefits

  • Inclusive and collaborative culture with an emphasis on employee voice and impact.
  • Country-specific health and welfare insurance, retirement programs, parental leave, adoption assistance, and wellbeing resources.
  • Travel discounts for flights, hotels, cruises, car rentals, and other travel services.
  • Access to more than 20,000 learning courses, leadership programs, and internal career opportunities.
  • Inclusion groups supporting connection, discussion, and organizational awareness.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →