> Markdown version of [/jobs/ext/2039023-avp-iam-ai-engineer](https://www.wearedevelopers.com/jobs/ext/2039023-avp-iam-ai-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AVP, IAM AI Engineer - **Company:** LPL Financial - **Location:** Fort Mill, SC, United States (Remote available) - **Experience:** Experienced - **Salary:** $122,570.0 - $204,249.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Python (Programming Language), Key Management, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Security Information and Event Management, Policy as Code, Scripting, Cloud Platform System, Cyberark, Large Language Models, Pingfederate, Kubernetes, Information Technology, Sentry, Hashicorp, SailPoint, Restful APIs, Terraform - **Published:** August 12, 2026 - **Apply:** https://lplfinancial.wd1.myworkdayjobs.com/External/job/Fort-MillCharlotte/AVP--IAM-AI-Engineer_R-052664-1 ## About the Role * 5+ years in identity & access management or information security, including hands-on engineering. * Demonstrated experience building and/or leading technical teams. * 5+ years with Ping Identity (PingFederate / PingOne / PingAccess) or a comparable access-management / federation platform. * 5+ years with SailPoint (IdentityIQ / Identity Security Cloud) or a comparable identity governance & administration (IGA) platform. * 3+ years with Idira (CyberArk, formerly Conjur) / HashiCorp Vault or a comparable secrets-management platform., * Working knowledge of identity and authorization for both users and agents: user-to-agent and agent-to-agent (A2A) patterns, OIDC and OAuth 2.0/2.1 tokens, and API keys, across both authentication (AuthN) and authorization (AuthZ). * Strong automation and engineering skills: proficiency in a scripting/programming language (e.g., Python), infrastructure-as-code (e.g., Terraform), CI/CD pipelines, and REST API integration. * Experience applying IAM in cloud environments (AWS, Azure, and/or GCP) and in containerized / Kubernetes workloads. Preferences: * Familiarity with workload-identity and machine-identity standards: SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation. * Working understanding of AI/agentic systems: LLMs, agent frameworks, tool-calling, and emerging authentication patterns such as the Model Context Protocol (MCP). * Experience in a regulated industry (financial services, healthcare, etc.) and with associated compliance regimes. * Relevant certifications, e.g., CISSP, CyberArk (Defender/Sentry), SailPoint, Ping, or a major cloud security certification. * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. ## Description We are looking for an AVP, IAM AI Engineer to design, operationalize, and automate the identity controls that govern both human and non-human actors across our environment - with a specific focus on AI agents and the emerging class of agentic and non-human identities (NHI). This is a hands-on engineering and technical leadership role: you will build the runtime controls, secrets workflows, and governance guardrails that let the organization adopt AI safely, while standing up and growing a team to sustain and scale that work. You will be embedded in new AI application development from the earliest design stages, ensuring identity, authentication, and authorization are built in rather than bolted on., * Identity runtime controls. Operationalize and automate identity runtime controls across human and non-human identities, including real-time authentication, authorization, and policy enforcement. * NHI & agentic governance. Design, build, and automate governance controls for AI agents and non-human identities - covering the full lifecycle: provisioning, entitlement, rotation, certification/attestation, and deprovisioning. * Secrets management for AI. Develop and automate secrets-manager workflows for AI systems and agents, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery to workloads. * Least privilege & policy-as-code. Define and enforce fine-grained, least-privilege authorization models for agents and workloads, expressed as policy-as-code wherever possible. * Reference architecture & standards. Establish standards and reference patterns for how identity flows through agentic systems - user-to-agent, agent-to-agent (A2A), and workload-to-service authentication and authorization. * Embedded in AI development. Partner with engineering and data science teams on all new AI application development, ensuring identity, AuthN/AuthZ, and secrets handling are designed in from the start. * End-user IAM deployment. Support the deployment and adoption of IAM controls for end users where required. * Monitoring & response. Integrate identity telemetry with SIEM/SOC tooling; build monitoring and anomaly detection for NHI/agent behavior; support incident response for compromised or misused credentials. * Governance, risk & compliance. Partner with GRC, risk, and audit stakeholders to ensure controls satisfy regulatory and internal requirements, and to produce audit evidence. * Team building & leadership. Recruit, build, mentor, and lead a team to support these workstreams; set technical direction and roadmap for NHI and agentic IAM. What are we looking for? We're looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)