> Markdown version of [/jobs/ext/3139480-principal-iam-ai-engineer](https://www.wearedevelopers.com/jobs/ext/3139480-principal-iam-ai-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IAM AI Engineer - **Company:** Amex Gbt - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $104,000.0 - $194,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Artificial Intelligence, Amazon Web Services, Cloud Computing, Cyber Security, Payment Systems, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Security Assertion Markup Language (SAML), Software Engineering, Okta, Cyberark, Istio, Multi-Cloud, Kubernetes, Hashicorp, Virtual Agents, SailPoint, Terraform - **Published:** September 29, 2026 - **Apply:** https://www.builtincolorado.com/job/principal-iam-ai-engineer/11408420?handler=ApplyRedirect ## About the Role * Deep expertise in enterprise identity infrastructure: PAM (CyberArk or equivalent), Okta as IdP, and IGA platforms like Saviynt, including extending governance beyond human identities. * Strong AWS and cloud identity skills: IAM design, ephemeral credentials, OIDC federation, secrets/certificate management, and least-privilege at scale. * Mastery of core identity standards (OAuth, OIDC, SAML, SCIM, JWT, mTLS) and machine-to-machine/workload identity across on-prem, hybrid, and multi-cloud environments. * Proven ability to architect enterprise-scale identity security programs and govern non-human identities (inventory, ownership, certification, credential rotation, risk). * Strong cross-functional leadership and communication skills, with sound judgment for operating in an emerging, still-being-defined discipline. Must Have * 8+ years in IAM/cybersecurity, with 5+ years at architect or principal level owning target-state design for an enterprise security or identity domain. * Proven experience designing identity, access, and governance controls for non-human identities - service accounts, workload identities, and AI agents - at enterprise scale. * Strong AWS (or equivalent public cloud) identity and access design experience at multi-account scale. * Hands-on experience with Okta (or comparable access management/federation platform) and Saviynt (or comparable IGA platform). * Experience with privileged access management platforms such as Idira (formerly CyberArk) and HashiCorp Vault, or comparable tools., * Identity Threat Detection and Response (ITDR) and posture management Experience with SPIFFE/SPIRE or service mesh identity patterns * Knowledge of emerging AI regulation and frameworks * Externalized authorization and policy orchestration expertise * Experience with Model Context Protocol (MCP) and agent-to-agent patterns * Kubernetes and container security with workload identity * Automation ability in Python, PowerShell or Terraform * Relevant certifications: CISSP, CISM, CCSP, CyberArk, Okta, AWS Security, or architecture certifications ## Description Design and build enterprise IAM infrastructure for AI agents, workloads, and non-human identities. Develop authentication, authorization, credential management, secrets rotation, zero-standing-privilege policies, and identity governance across cloud and hybrid environments. Partner with AI, ML, application, compliance, risk, and audit teams to embed controls into AI development. Lead technical strategy, mentor engineers, advise senior leadership, evaluate vendors, and oversee machine identity and agent IAM programs. The summary above was generated by AI Amex GBT is a place where colleagues find inspiration in travel as a force for good and - through their work - can make an impact on our industry. We're here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. We are seeking a Principal IAM AI Engineer who brings an AI-first mindset rather than a traditional security-first lens to identity architecture. This role sits at the intersection of IAM, AI/agentic systems, and product thinking, for someone who's as comfortable designing a scalable access model for AI agents as they are challenging why a control exists in the first place. It also sits at the intersection of engineering, risk management, and the technical realities of running global travel technology: booking platforms, payment flows, traveler data protection, and extensive supplier integrations. We need someone who can look at how AI agents, copilots, and autonomous workflows are being adopted across the business, understand the actual product and business intent behind them, and build security and identity architecture that enables adoption safely rather than just implementing it. This is a technical and hands-on engineering position where you will construct the authentication and authorization infrastructure, credential management systems, and compliance frameworks that enable responsible AI deployment across the organization. Additionally, you will lead a technical team to maintain, expand, and evolve these capabilities. You will be integrated into AI initiative planning from inception, ensuring identity, access controls, and secrets management are embedded in the architecture from day one rather than implemented after deployment. What You'll Do * Access control execution. Deploy and automate identity controls at runtime for NHI identity - including immediate authentication verification, access authorization, and real-time rule application across the environment. * Machine identity & agentic system governance. Build, deploy, and automate lifecycle governance for agents and machine identities - spanning discovery and registration, permission assignment, credential lifecycle, periodic access reviews, and secure retirement. * Credential workflows for AI workloads. Construct and operationalize credential management systems for AI-driven applications and agents, encompassing automated secret cycling, short-lived credential issuance, and protected distribution to runtime environments. * Granular authorization & declarative policies. Establish and implement fine-grained, zero-standing-privilege access models for agents and workloads, documented and managed through infrastructure-as-code and policy declaration frameworks. * Integration with AI development lifecycle. Collaborate with application development and ML teams throughout all AI initiative phases, ensuring identity requirements, credential handling, and access controls are incorporated during design rather than retrofitted. * End-user identity controls rollout. Facilitate implementation and adoption of identity governance controls for human users as required by organizational standards. * Compliance, audit & risk alignment. Work with compliance, risk and audit functions to confirm controls align with regulatory requirements and internal policies; facilitate audit evidence generation and regulatory reporting. * Organization building & technical strategy. Lead an engineering team supporting these initiatives; establish technical direction, strategic priorities and delivery roadmap for machine identity and agent IAM programs. * Advisory, enablement and leadership + Serve as a trusted advisor to senior leadership on machine and AI identity risk, and translate it into funded, sequenced remediation. + Partner with InfoSec and AI Security teams on proof-of-concept evaluations and vendor assessments for AI and agent governance platforms. + Mentor engineers and architects on non-human and agent identity patterns, and raise the organization's overall fluency in machine identity security., Prepares individual, business, and fiduciary tax returns and projections; researches tax issues; supports engagement planning; communicates with clients and engagement leaders; manages deadlines and budgets; identifies engagement opportunities; provides technical client assistance; and participates in professional development and community activities. Top Skills: AdobeAxcessCasewareDepreciation Processing SoftwareGofileroomExcelMicrosoft PowerpointMicrosoft WordRia Wipfli Senior Accountant 9 Minutes Ago Remote or Hybrid Senior level Senior level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Manage partnership tax compliance and advisory engagements, including federal and multistate returns, tax research, projections, and client communications. Lead client relationships, support business development, mentor staff, coordinate multidisciplinary teams, and ensure engagement deadlines and budgets are met. The role focuses on Subchapter K partnership taxation and requires technical consultation, review of tax-related information, and use of tax preparation software. Wipfli Senior Accountant 9 Minutes Ago Remote or Hybrid Senior level Senior level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Manage partnership tax compliance and advisory engagements, review federal and multistate returns, handle client relationships, consult on technical tax matters, support business development, and mentor staff. Prepare individual, business, and fiduciary returns, conduct tax research, communicate with engagement leaders, manage deadlines and budgets, and provide client technical assistance, primarily involving Subchapter K partnership taxation. What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)