> Markdown version of [/jobs/ext/2212648-cybersecurity-iam-senior-principal-engineer-job-in-plano](https://www.wearedevelopers.com/jobs/ext/2212648-cybersecurity-iam-senior-principal-engineer-job-in-plano). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity IAM Senior Principal Engineer job in Plano - **Company:** PepsiCo, Inc. - **Location:** Plano, TX, United States - **Experience:** Expert - **Salary:** $123,500.0 - $206,750.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, OAuth, OpenID, Open Web Application Security, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Spring Cloud, Large Language Models, Togaf, AI Platforms, Information Technology, Virtual Agents, SailPoint - **Published:** August 24, 2026 - **Apply:** https://jobs.diversity.com/career/2463097/cybersecurity-iam-senior-principal-engineer-texas-tx-plano ## About the Role * Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field. * 15+ years of experience in Cybersecurity, with significant expertise in Identity and Access Management (IAM). * 7+ years in a Principal, Lead, or Senior Architecture role supporting enterprise or cloud-native environments. * Expert knowledge of IAM technologies, including AWS IAM, AWS Identity Center, Microsoft Entra ID, OAuth 2.0, OpenID Connect (OIDC), SAML, and Zero Trust Architecture. * Experience securing AI platforms, LLMs, Agentic AI applications, or autonomous AI agents. * Strong understanding of cloud security, workload identities, and non-human identity (NHI) management. * Excellent communication and stakeholder management skills. Preferred Qualifications * Experience with AWS Bedrock, Amazon AgentCore, Azure AI, or similar enterprise AI platforms. * Experience with Identity Governance (IGA) platforms such as Saviynt, SailPoint, or equivalent. * Knowledge of OWASP Top 10 for LLM Applications, prompt injection defenses, and AI security best practices. * Experience with SPIFFE/SPIRE, workload identity frameworks, or service identity management. * Familiarity with AI governance, AI risk management, and responsible AI frameworks. * Professional certifications such as CISSP, CISM, CCSP, AWS Certified Security - Specialty, TOGAF, or cloud architecture certifications. ## Description IAM Principal Cybersecurity Architect will lead the strategy, solution design, and governance of Identity and Access Management (IAM) services including AI, Large Language Models (LLMs), and autonomous AI agents and security. This is a senior technical leadership role responsible for defining enterprise standards for AI identity, securing AI platforms, and enabling the safe adoption of Agentic AI across the organization. The role will partner closely with AI Engineering, Cloud, Enterprise Architecture, and Security teams to design scalable, secure, and compliant AI solutions. The ideal candidate has deep expertise in IAM, cloud security, Zero Trust architecture, and AI security, with experience building governance models for AI agents and non-human identities. Responsibilities IAM & Cloud Security * Lead solution architecture across IAM services for critical cross functional programs * Lead modernization of IAM capabilities supporting AI and cloud-native applications. * Design secure identity architectures leveraging AWS IAM, AWS Identity Center, Microsoft Entra ID, and cloud-native identity services. * Integrate AI platforms with enterprise IAM, Identity Governance (IGA), and Privileged Access Management (PAM) solutions. AI Agent Security Strategy & Architecture * Define the enterprise architecture and security strategy for AI systems, LLMs, and Agentic AI platforms. * Develop architecture standards, reference designs, and best practices for securing AI workloads. * Partner with AI Engineering and platform teams to embed security-by-design into AI solutions. * Drive adoption of Zero Trust principles across AI and cloud environments. AI Agent Identity & Governance * Design and govern the complete identity lifecycle for AI agents, including onboarding, authentication, authorization, certification, monitoring, and decommissioning. * Establish governance standards for AI identities, non-human identities (NHI), and machine identities. * Implement least privilege, Just-in-Time (JIT), and Just-Enough-Access (JEA) access models for AI workloads. * Ensure AI systems meet enterprise security, compliance, privacy, and regulatory requirements. Leadership & Collaboration * Serve as the technical authority for AI identity security across the enterprise. * Partner with Cybersecurity, Enterprise Architecture, AI Engineering, Cloud, GRC, Privacy, and business teams to deliver secure AI capabilities. * Mentor architects and engineers on AI security, IAM, and cloud identity best practices. * Communicate architecture decisions and security risks effectively to executive leadership and technical stakeholders. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)