Назад
Company hidden
3 дня назад

AVP, IAM AI Architect Cyber Security (AI)

122 673 - 204 455$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
AVP, IAM AI Architect Cyber Security (AI): Designing and implementing identity patterns for AI workloads, conversational agents, and enterprise AI platform integrations with an accent on OAuth/OIDC flows, delegated access, and non-human identity management. Focus on building IAM proofs of concept, securing agent tools and MCP integrations, enforcing least-privilege access, and delivering production-ready controls for reliability, observability, and regulatory compliance.

Location: Hybrid role based in Fort Mill/Charlotte, United States

Pay range: $122,673.00–$204,455.00 annually

Company

hirify.global is a U.S. wealth management firm providing financial advisors and institutions with investment solutions, fintech tools, custody, and practice management services.

What you will do

  • Design enterprise IAM patterns for AI workloads, conversational agents, APIs, microservices, BFFs, and agent runtimes.
  • Build and lead end-to-end IAM proofs of concept, including OAuth/OIDC flows, token exchange, delegated access, gateway enforcement, and human-in-the-loop controls.
  • Define identity lifecycle, entitlement, credential rotation, revocation, and secrets-management patterns for non-human and autonomous workloads.
  • Secure agent tools, datasets, external developer access, and MCP integrations through federation, scoped credentials, and policy-driven authorization.
  • Integrate IAM with PingOne AIC, Microsoft Entra ID, API gateways, AI platforms, observability, CI/CD, and infrastructure as code.
  • Produce architecture artifacts, runbooks, threat-modeling input, implementation guidance, and transition plans for IAM engineering.

Requirements

  • 6+ years of experience in IAM, security architecture, or platform engineering with significant IAM responsibility.
  • 2+ years building IAM proofs of concept and troubleshooting OAuth 2.0 and OIDC flows, including Auth Code + PKCE, refresh tokens, client credentials, token exchange, and OBO.
  • 2+ years of experience with PingOne AIC and/or Microsoft Entra ID.
  • Hands-on expertise with SAML, OAuth, OIDC, JWTs, scopes, authorization models, APIs, microservices, and BFF architectures.
  • Experience integrating IAM with API gateways, AI/ML platforms, modern application stacks, and agent or tool identity models.
  • Ability to work in the hybrid Fort Mill/Charlotte location.

Nice to have

  • Experience delivering AI/ML agents or copilots to production.
  • Experience with SailPoint, CyberArk, Delinea, Auth0, CIAM, or non-human identity and secrets-management platforms.
  • Knowledge of AI-aware API gateways such as Kong, IAM modernization, M&A programs, zero trust, or identity threat detection.
  • Relevant certifications such as CISSP, CCSP, Entra, Ping, SailPoint, or AWS.

Culture & Benefits

  • Collaborative environment with opportunities to influence enterprise security and AI architecture.
  • 401(k) matching, health benefits, employee stock options, paid time off, and volunteer time off.
  • Resources and flexibility designed to support work, home, and personal well-being.

Hiring process

  • Recruiting and interview communication is conducted directly through an official @lplfinancial.com email address.
  • LPL does not request payment or bank or credit card information during interviews.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →