Security Engineer / Architect Identity, Authorization & Platform Security

Cyber Resource Provider LLC
Denver, CO, United States
9 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Cloud Computing Security Cyber Security Continuous Integration Federated Identity Management Firmware Identity and Access Management Information Systems Security Architecture Professional Key Management Network Connections OAuth
+16 more
OpenID Public Key Infrastructure Role-Based Access Control Zero Trust Network Access JSON Web Token Security Assertion Markup Language (SAML) Security Software Security Information and Event Management Single Sign-On Software Vulnerability Management Cloud Platform System Large Language Models Kubernetes Production Code Virtual Agents Vulnerability Analysis

Job description

We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform.

The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security.

This is a builder’s role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions., * Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.

  • Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning.
  • Build automated user/group/role provisioning and lifecycle management.
  • Implement access recertification and governance processes.
  • Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
  • Establish SSO and API authentication across services.
  • Implement consistent organization and tenant isolation across identity and downstream platforms.

Authorization & Policy Engineering

  • Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
  • Implement an externalized policy-decision engine and manage policies as code.
  • Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
  • Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction.
  • Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.

AI Agent & Tool Security

  • Design authorization models for AI agents and automated tool invocation.
  • Establish agent workload identities and delegated authorization.
  • Implement per-agent cryptographic identities and on-behalf-of authorization.
  • Define tool-level permissions based on users, agents, tenants, resources, and actions.
  • Implement human-in-the-loop approval workflows for sensitive operations.
  • Maintain complete, tamper-evident audit trails for agent and tool activity.
  • Apply security controls against prompt injection and unauthorized tool execution.

Secrets & Cloud Security

  • Implement centralized secrets management and automated credential rotation.
  • Design secure cloud IAM architectures and least-privilege access.
  • Implement secure credential management for applications, workloads, agents, and infrastructure.
  • Support secure execution environments and sandboxing for sensitive tool calls.

Vulnerability Management

  • Implement continuous vulnerability scanning across:
  • Edge compute nodes
  • Containers and container images
  • Operating systems
  • Application dependencies
  • Container-orchestration platforms
  • Third-party libraries
  • Device firmware where applicable
  • Implement SBOM generation, tracking, and vulnerability correlation.
  • Correlate CVEs with asset exposure and exploitability.
  • Develop risk-based vulnerability prioritization and remediation workflows.
  • Build operational and executive vulnerability dashboards.
  • Integrate vulnerability findings with event platforms and ticketing workflows.

Security Telemetry & SIEM

  • Deploy security telemetry capabilities across edge environments.
  • Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
  • Normalize security events into a common schema.
  • Integrate security telemetry with centralized SIEM platforms.
  • Implement store-and-forward capabilities for intermittently connected edge environments.
  • Design bandwidth-aware event batching and reliable event delivery.
  • Implement tamper-evident and mutually authenticated telemetry pipelines.
  • Maintain tenant isolation throughout the telemetry pipeline.
  • Develop SIEM detection and correlation rules that associate security events with verified identities.
  • Route actionable security alerts into event buses and on-call workflows.

Platform Security Integration

  • Establish security standards for event-platform authentication and authorization.
  • Implement message signing and secure service-to-service communication.
  • Support edge-device identity, mTLS, PKI, and certificate lifecycle management.
  • Integrate security controls into CI/CD pipelines.
  • Implement security gates including artifact signing, IaC scanning, and automated security validation.
  • Partner with engineering teams to establish reusable security primitives and standards.

Requirements

  • 8+ years of experience in security engineering.
  • 3+ years of experience architecting and implementing Identity & Access Management at scale.
  • Strong hands-on experience with enterprise Identity Providers and identity federation.
  • Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning.
  • Experience mapping federated identities to downstream authorization models.
  • Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
  • Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
  • Experience with externalized authorization/policy engines.
  • Strong cloud IAM experience.
  • Hands-on experience with centralized secrets management and automated credential rotation.
  • Experience with containers and container orchestration.
  • Ability to develop production-quality code and implement security solutions hands-on.
  • Demonstrated experience implementing least-privilege and Just-in-Time access.
  • Experience building fully auditable access-control systems.

Preferred Qualifications

  • Experience securing AI agents, LLM applications, and automated tool-invocation interfaces.
  • Knowledge of prompt-injection and AI tool-boundary security.
  • Experience with workload identity and machine-to-machine authentication.
  • Experience building security telemetry pipelines and SIEM integrations.
  • Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
  • Experience securing edge, IoT, or intermittently connected environments.
  • Experience with lightweight host-based security telemetry agents.
  • Knowledge of Zero Trust architecture.
  • Experience with PKI, mTLS, certificate lifecycle management, and device attestation.
  • Experience with event-driven security architectures.
  • Experience implementing secure CI/CD and automated security gates.
  • Security architecture certifications are a plus but not required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

4:00 min

Customizing keyboards with mechanical switches and custom firmware

Andreas Taranetz Andreas Taranetz · Europe 2026 Virtual

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all