Role: AI Lead / Agentic Identity Engineer (IAM/Cloud Security/Zero Trust)
Location : Remote (Occasional travel to Miami, FL)
Position type : Contract
Project Duration : Long Term
Â
Visa : US Citizen
Â
Detailed JD :
This is a hands-on architecture leadership role. The ideal candidate can design across IAM, workload identity, cloud security, API authorization, AI runtime controls, and governance processes while also guiding proof-of-concepts, platform integrations, and adoption across product, security, infrastructure, and application teams.
Â
Requirements:
- 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security.
- Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale.
- Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models.
- Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control.
- Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments.
- Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems.
- Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation.
- Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs.
- Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives.
Â
Preferred / nice to have:
Â
- Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards.
- Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, or certificate lifecycle management.
- Experience with policy-as-code, runtime authorization, ABAC/ReBAC models, or centralized policy decision points.
- Experience designing controls for regulated, SOX-relevant, PCI, privacy-sensitive, or high-availability environments.
- Experience building maturity models, capability roadmaps, control frameworks, or executive-level investment cases for emerging security domains.
Â
Â
Looking forward to work with you!
Â
Â
Thanks & Regards
Â
Lokesh Yadav
Sr. Technical Recruiter
CloudThink Tech Inc