Senior Consultant, Strategy, Growth, and Transformation, Identity & Gen AI Engineer

Deloitte T.T.L.
Arlington, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$105,400.0 - $207,800.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Cloud Engineering Cyber Security Information Systems Cursor (Graphical User Interface Elements) Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language)
+28 more
Key Management OAuth OpenID Open Web Application Security Openid Connect Azure Active Directory Ansible JSON Web Token Security Assertion Markup Language (SAML) Single Sign-On Software Engineering Systems Integration Policy as Code Data Logging Enterprise Software Applications Cloud Platform System Okta Cyberark GitHub Copilot Retrieval-Augmented Generation Large Language Models Generative AI Kubernetes Information Technology Hashicorp Virtual Agents SailPoint Terraform

Job description

As organizations adopt generative AI, securing how AI agents, models, and automated workflows access enterprise systems and data has become a core engineering challenge. As an Identity & Gen AI Engineer, you will build generative AI solutions with identity, access, and trust engineered in from the start, securing both human and non-human identities and governing how AI agents and GenAI platforms reach data and downstream systems. This role focuses on hands-on engineering, integration, and continuous enhancement of AI solutions in which identity and access controls are a first-class concern.

Work you’ll do

As an Identity & Gen AI Engineer on the Identity and Access Management team, you will be responsible for…

  • Build and integrate generative AI solutions, including LLM applications, retrieval-augmented generation, and AI agents, with secure access to data and downstream systems.

  • Engineer authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities operating across enterprise and cloud environments.

  • Develop guardrails for agentic workflows, including scoped permissions, least-privilege access, credential and secrets management, and runtime policy enforcement.

  • Implement logging, monitoring, and governance that provide traceability and accountability for AI system actions.

  • Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.

  • Create and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.

Requirements

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others, Required:
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a similar technical field
  • Ability to work onsite up to 5 days a week.
  • 3+ years of software engineering experience with Python or a comparable language
  • 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as large language model (LLM) applications, retrieval-augmented generation (RAG), or AI agents, including use of model APIs, orchestration frameworks, and AI development tools such as Claude Code, OpenAI Codex, GitHub Copilot, or Cursor
  • Working knowledge of identity and access management concepts and protocols, including authentication, authorization, single sign-on (SSO), and standards such as OpenID Connect (OIDC), Security Assertion Markup Language (SAML), OAuth, and JSON Web Token (JWT)
  • Ability to travel 15%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Ability to obtain and maintain the necessary security clearance.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Experience deploying generative AI solutions to production environments
  • Hands-on experience with identity and access management platforms such as SailPoint, Okta, or Microsoft Entra ID
  • Experience securing non-human or machine identities, service accounts, secrets, and credentials using tools such as HashiCorp Vault or CyberArk
  • Experience with AI agent frameworks and protocols such as LangChain, LangGraph, or Model Context Protocol (MCP)
  • Experience with fine-grained authorization or policy-as-code using tools such as Open Policy Agent (OPA), Cedar, or OpenFGA
  • Familiarity with AI and LLM security risks such as the OWASP Top 10 for LLM Applications, prompt injection, and excessive agency
  • Experience applying AI governance and risk frameworks such as the NIST AI Risk Management Framework (AI RMF)
  • 2+ years of experience building or deploying workloads in cloud environments such as Amazon Web Services (AWS) and Microsoft Azure
  • Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), or a cloud engineering certification such as AWS Certified Solutions Architect or Microsoft Certified: Azure Solutions Architect
  • 1+ year of experience supporting federal government environments
  • 1+ year of experience with infrastructure-as-code or automation technologies such as Terraform or Ansible

Benefits & conditions

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

About the company

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Our Digital Trust & Privacy offering enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all