> Markdown version of [/jobs/ext/2120183-security-architect-with-iam-hybrid](https://www.wearedevelopers.com/jobs/ext/2120183-security-architect-with-iam-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect with IAM (Hybrid) - **Company:** New York, Inc. - **Location:** Dallas, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Integration Architecture, Audit Trail, User Authentication, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Key Management, OAuth, OpenID, Open Web Application Security, Ping (Networking Utility), Azure Active Directory, Zero Trust Network Access, Software Safety, Scaled Agile Framework, Policy as Code, Data Logging, Cloud Platform System, Cyberark, Large Language Models, Software Security, Multi-Cloud, Information Technology, Sentry, Hashicorp, Virtual Agents, SailPoint - **Published:** August 19, 2026 - **Apply:** https://www.dice.com/job-detail/f5748d10-11a3-45fe-9b85-98de10c1ef51 ## About the Role 1. Enterprise IAM Architecture & Integration (3 5+ years): Proven experience architecting enterprise Identity and Access Management, Identity Governance (IGA), and Privileged Access Management (PAM) across hybrid and multi-cloud environments. 2. Agentic AI & Non-Human Identity Governance: Deep understanding of authorization models for AI agents, autonomous tools, MCP servers, service accounts, and API access patterns. 3. Advanced Authentication & Delegation Standards: Hands-on expertise designing modern token exchange protocols, OAuth 2.0 / OIDC flows, short-lived credentials, and workload identity patterns for machine-to-machine interactions. 4. Secrets Management & Tooling Expertise: Experience integrating enterprise IAM and security tools such as CyberArk, SailPoint (Identity Security Cloud / Entro), Ping Identity Platform, Microsoft Entra ID, HashiCorp Vault, or AWS Secrets Manager / IAM. 5. Zero Trust & Runtime Authorization: Proven track record applying Zero Trust principles, Zero Standing Privilege (ZSP), attribute-based access control (ABAC), and policy-as-code. 6. AI Safety & Governance Frameworks: Familiarity with NIST AI RMF, OWASP Top 10 for LLMs, and audit/compliance standards for autonomous AI operations. 7. Agile Delivery & Stakeholder Influence: Experience collaborating in cross-functional technical teams (preferably Scaled Agile Framework / SAFe), translating complex identity concepts into clear architecture decision records (ADRs) and executive briefings. Qualifications & Education Education: Bachelor s degree in Technology, Computer Science, Cybersecurity, Information Systems, Business, or equivalent practical work experience. Preferred Certifications Security & Architecture: CISSP, CCSP, CISM, or AWS Certified Security Specialty. Identity & Vendor Platforms: Certified CyberArk Defender/Sentry, SailPoint Certified IdentityIQ/IdentityNow Engineer, or Ping Identity Certified Professional. AI & Cloud Fundamentals: AWS Certified AI Practitioner, AWS Cloud Practitioner, or AI Risk/Security certifications (e.g., AAISM, CompTIA Sec AI+). Work Style & Core Competencies Strategic thinker with the ability to navigate ambiguity and create structured architecture in rapidly evolving domains. Strong consensus-builder capable of mediating technical tradeoffs between AI velocity, usability, and rigorous identity controls. High attention to detail with clear documentation skills for enterprise standards, roadmaps, and reference architectures. ## Description We are seeking an experienced Security Architect Agentic Identity & Access Management to design and govern the target-state authorization architecture for autonomous AI applications, AI agents, and non-human identities across enterprise and cloud environments. This role serves as the Subject Matter Expert bridging Identity Governance and Administration (IGA), Privileged Access Management (PAM), Cloud Security, and AI Engineering. The Architect will establish scalable authorization patterns (user-to-agent, agent-to-tool, agent-to-agent), implement Zero Standing Privilege (ZSP) and dynamic policy enforcement, and define full lifecycle governance for autonomous agentic workflows and Model Context Protocol (MCP) integrations., Agentic IAM Target-State Architecture: Define and lead the enterprise target-state architecture, reference models, and governance frameworks for identities, delegated authority, and runtime authorization across AI applications, agents, APIs, and human users. Authorization Patterns & Delegation: Architect reusable authorization patterns for user-to-agent delegation, agent-to-tool invocation, agent-to-agent collaboration, and machine-to-machine communications utilizing OAuth 2.0, OIDC, token exchange, and workload identity federation. Zero Trust & Policy Enforcement: Design context-aware access policies enforcing least privilege, Zero Standing Privilege (ZSP), separation of duties, dynamic runtime decisioning, and human-in-the-loop escalation guardrails. Non-Human Identity (NHI) Lifecycle Governance: Define lifecycle governance standards for AI agents, including registration, ownership/sponsorship models, credential vaulting, automated rotation, periodic recertification, suspension, and deprovisioning. Auditability & Traceability Frameworks: Architect logging and observability requirements to link every autonomous agent action directly to its agent identity, sponsoring owner, delegated human principal, authorization decision, and downstream resource. Tool Evaluation & Integration: Evaluate vendor and native identity platforms (e.g., Ping Identity, SailPoint, CyberArk, AWS IAM/Secrets Manager, Microsoft Entra ID) to integrate emerging agentic IAM capabilities into infrastructure. Cross-Functional Advisory: Partner with Cloud Security, Application Security, AI Governance, Enterprise Architecture, and Agile delivery teams to guide threat-informed design decisions for AI use cases, MCP servers, and tool integrations. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)