Cybersecurity IAM Senior Principal Engineer job in Plano

PepsiCo, Inc.
Plano, TX, United States
13 days ago
Apply on jobs.diversity.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$123,500.0 - $206,750.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Identity and Access Management OAuth OpenID Open Web Application Security Openid Connect
+10 more
Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Spring Cloud Large Language Models Togaf AI Platforms Information Technology Virtual Agents SailPoint

Job description

IAM Principal Cybersecurity Architect will lead the strategy, solution design, and governance of Identity and Access Management (IAM) services including AI, Large Language Models (LLMs), and autonomous AI agents and security.

This is a senior technical leadership role responsible for defining enterprise standards for AI identity, securing AI platforms, and enabling the safe adoption of Agentic AI across the organization. The role will partner closely with AI Engineering, Cloud, Enterprise Architecture, and Security teams to design scalable, secure, and compliant AI solutions.

The ideal candidate has deep expertise in IAM, cloud security, Zero Trust architecture, and AI security, with experience building governance models for AI agents and non-human identities.

Responsibilities

IAM & Cloud Security

  • Lead solution architecture across IAM services for critical cross functional programs
  • Lead modernization of IAM capabilities supporting AI and cloud-native applications.
  • Design secure identity architectures leveraging AWS IAM, AWS Identity Center, Microsoft Entra ID, and cloud-native identity services.
  • Integrate AI platforms with enterprise IAM, Identity Governance (IGA), and Privileged Access Management (PAM) solutions.

AI Agent Security Strategy & Architecture

  • Define the enterprise architecture and security strategy for AI systems, LLMs, and Agentic AI platforms.
  • Develop architecture standards, reference designs, and best practices for securing AI workloads.
  • Partner with AI Engineering and platform teams to embed security-by-design into AI solutions.
  • Drive adoption of Zero Trust principles across AI and cloud environments.

AI Agent Identity & Governance

  • Design and govern the complete identity lifecycle for AI agents, including onboarding, authentication, authorization, certification, monitoring, and decommissioning.
  • Establish governance standards for AI identities, non-human identities (NHI), and machine identities.
  • Implement least privilege, Just-in-Time (JIT), and Just-Enough-Access (JEA) access models for AI workloads.
  • Ensure AI systems meet enterprise security, compliance, privacy, and regulatory requirements.

Leadership & Collaboration

  • Serve as the technical authority for AI identity security across the enterprise.
  • Partner with Cybersecurity, Enterprise Architecture, AI Engineering, Cloud, GRC, Privacy, and business teams to deliver secure AI capabilities.
  • Mentor architects and engineers on AI security, IAM, and cloud identity best practices.
  • Communicate architecture decisions and security risks effectively to executive leadership and technical stakeholders.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field.
  • 15+ years of experience in Cybersecurity, with significant expertise in Identity and Access Management (IAM).
  • 7+ years in a Principal, Lead, or Senior Architecture role supporting enterprise or cloud-native environments.
  • Expert knowledge of IAM technologies, including AWS IAM, AWS Identity Center, Microsoft Entra ID, OAuth 2.0, OpenID Connect (OIDC), SAML, and Zero Trust Architecture.
  • Experience securing AI platforms, LLMs, Agentic AI applications, or autonomous AI agents.
  • Strong understanding of cloud security, workload identities, and non-human identity (NHI) management.
  • Excellent communication and stakeholder management skills.

Preferred Qualifications

  • Experience with AWS Bedrock, Amazon AgentCore, Azure AI, or similar enterprise AI platforms.
  • Experience with Identity Governance (IGA) platforms such as Saviynt, SailPoint, or equivalent.
  • Knowledge of OWASP Top 10 for LLM Applications, prompt injection defenses, and AI security best practices.
  • Experience with SPIFFE/SPIRE, workload identity frameworks, or service identity management.
  • Familiarity with AI governance, AI risk management, and responsible AI frameworks.
  • Professional certifications such as CISSP, CISM, CCSP, AWS Certified Security - Specialty, TOGAF, or cloud architecture certifications.

Benefits & conditions

  • The expected compensation range for this position is between $123,500 - $206,750.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 15% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.diversity.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all