> Markdown version of [/jobs/ext/3115422-principal-identity-access-management-iam-security-engineer](https://www.wearedevelopers.com/jobs/ext/3115422-principal-identity-access-management-iam-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Identity & Access Management (IAM) Security Engineer - **Company:** BINGHAMTOM UNIVERSITY - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $153,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Continuous Integration, Distributed Systems, Federated Identity Management, Identity and Access Management, Intrusion Detection and Prevention, OAuth, OpenID, Role-Based Access Control, Zero Trust Network Access, JSON Web Token, Security Assertion Markup Language (SAML), Data Logging, Spoofing, Autodesk Autocad - **Published:** September 27, 2026 - **Apply:** https://www.themuse.com/jobs/autodesk/sr-principal-iam-security-engineer?utm_source=uconnect ## About the Role * 10+ years in IAM / security engineering, including designing identity architectures at enterprise scale. * Proven experience securing non-human identities across cloud, CI/CD, and production runtimes. * Deep knowledge of auth standards: OAuth2, OIDC, SAML, JWT, token exchange, federation, and modern workload identity patterns. * Strong authorization design experience: modeling permissions, least privilege, policy enforcement, and access governance. * Experience designing or securing systems where software agents act on behalf of users/services (delegation, impersonation, tool access, constrained execution). * Ability to define guardrails for agentic actions: approval gates, scoped permissions, auditable trails, and containment strategies. * Strong software engineering fundamentals (APIs, distributed systems, logging/telemetry); ability to review designs and code. * Experience with cloud IAM ecosystems and platform primitives (identity federation, workload identity, secretless patterns, KMS/HSM integration). * Experience building identity paved roads and internal developer platforms (IDP) patterns for identity. * Experience with privileged access management and tiering models for admin access. * Familiarity with CI/CD identity, signing, and provenance controls (build identities, artifact trust, token hardening). * Drives measurable risk reduction and adoption across orgs. * Sets standards others follow; resolves ambiguous identity problems; leads through influence. This is a strategic and hands-on role for someone who wants to lead Autodesk's enterprise identity posture, drive large-scale impact across teams, and ensure our systems are secure, automated, and aligned with Zero Trust principles. ## Description Autodesk's Cyber Defense team is looking for a Sr. Principal IAM Security Engineer to lead the strategy and execution for modern Identity and Access Management across human and non-human identities, including service accounts, workloads, secrets-backed identities, federated identities, and emerging AI/agentic identity patterns. You'll design and drive scalable, secure-by-default identity guardrails for workforce and platform/product environments, enabling engineering teams to move fast while reducing systemic identity risk., Identity strategy & governance * Define the enterprise and platform IAM strategy for human identities, NHI, and AI/agent identities, including lifecycle, authentication, authorization, and auditing standards. * Establish identity reference architectures, patterns, and paved roads for product teams and internal engineering. Non-human identity security (enterprise + platform) * Build and operationalize controls for service identities, workload identities, API identities, bots, and automation accounts across cloud, CI/CD, and runtime environments. * Drive adoption of short-lived, federated credentials where feasible; reduce static secrets and unmanaged service accounts. * Implement lifecycle governance for NHI: creation standards, ownership, rotation/attestation, inactivity reaping, and incident response playbooks. AI / agentic identity enablement * Define secure patterns for AI acting on behalf of users or services, including delegated authorization, scoped tokens, and least-privilege access models. * Partner with AI platform teams to implement guardrails: identity provenance, policy enforcement, auditing, and kill-switch mechanisms for misbehaving agents. * Ensure AI identity behaviors are measurable and governable (logging, traceability, approvals for sensitive actions, segmentation of duties). AI Identity Engineering * Embed AI and machine learning capabilities into IAM platforms and security tooling to enable intelligent, automated identity governance - including access decisioning, anomaly detection, and agent behavior monitoring. * Design, build, and deploy purpose-built AI agents and ML-powered security systems that autonomously execute IAM functions - including identity lifecycle management, entitlement reviews, and real-time response to identity-based threats. * Fine-tune and optimize existing AI models against Autodesk-specific identity and access data to improve accuracy of threat detection, behavioral anomaly identification, and access risk scoring within the IAM environment. Authorization, policy, and access modeling * Build/standardize authorization models (RBAC/ABAC/ReBAC as appropriate) across workforce and product systems. * Drive consistent policy as code, access reviews, and privileged access workflows. * Define standards for token scopes, claims, session constraints, step-up auth, and sensitive action protections. Operational excellence & incident readiness * Improve detection/response for identity threats: anomalous token use, privilege escalation, credential misuse, service-account sprawl. * Create metrics and reporting for identity posture and platform adoption (coverage, drift, exceptions, time-to-remediate). * Lead identity-related investigations and post-incident improvements. Leadership & influence * Serve as a senior technical leader influencing engineering orgs, platform teams, and security; mentor others and raise the bar on identity engineering. * Translate risk into pragmatic engineering requirements; drive roadmaps across multiple teams. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)