Назад
Company hidden
5 часов назад

Cybersecurity IAM Architect - Staff Engineer (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity IAM Architect - Staff Engineer (AI) (IAM, Zero Trust, AI identity security): Designing enterprise identity and access architectures across cloud, on-premises, SaaS, and hybrid environments with an accent on least-privilege controls, governance, and secure AI agent identities. Focus on reviewing identity risks, hardening agent-to-tool authorization, aligning controls with NIST, CMMC, and PCI DSS, and building reusable architecture standards.

Location: Baltimore, MD, United States

Company

hirify.global is a regulated financial services company focused on enterprise lending and financial solutions.

What you will do

  • Develop enterprise IAM and identity security architectures aligned with NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principles.
  • Design identity solutions covering authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environments.
  • Define secure patterns for AI agents, non-human and workload identities, service accounts, APIs, secrets, delegated authority, and agent-to-tool interactions.
  • Lead architecture and security reviews for applications, AI agents, automation platforms, APIs, and enterprise systems, identifying identity risks and mitigation strategies.
  • Establish IAM standards, governance policies, access control frameworks, and expectations for lifecycle processes, entitlement reviews, separation of duties, privileged access, and exception management.
  • Collaborate with engineering, cloud, infrastructure, application, AI, compliance, and risk teams while mentoring architects and security engineers.

Requirements

  • 7–10 years of cybersecurity experience, including at least 3 years in IAM architecture, security architecture, or a similar solution design role.
  • Deep knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust.
  • Experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environments.
  • Strong knowledge of identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties.
  • Hands-on familiarity with Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies.
  • Understanding of LLMs, AI and GenAI solutions, agentic AI, MCP and tool hardening, non-human identity governance, delegated access, and auditability of agent actions.

Nice to have

  • CISSP, CISM, CISA, CCSP, or identity-focused certifications.
  • Experience with Zero Trust Architecture, modern identity security models, and enterprise access governance programs.
  • Experience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validation.
  • Experience developing governance models for machine, workload, AI agent, service account, secret, and API identities.

Culture & Benefits

  • Work across IT, engineering, compliance, risk, and AI product functions as an identity security subject matter expert.
  • Contribute to security governance boards, architecture review boards, maturity assessments, and continuous improvement initiatives.
  • Operate in a large regulated environment with requirements tied to CMMC, PCI DSS, internal risk controls, and audit expectations.
  • Provide executive-facing communication, architecture documentation, mentoring, and guidance throughout the system development lifecycle.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →