> Markdown version of [/jobs/ext/3212630-security-engineer-architect-identity-authorization-platform-security](https://www.wearedevelopers.com/jobs/ext/3212630-security-engineer-architect-identity-authorization-platform-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer / Architect Identity, Authorization & Platform Security - **Company:** Cyber Resource Provider LLC - **Location:** Denver, CO, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Computing Security, Cyber Security, Continuous Integration, Federated Identity Management, Firmware, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Network Connections, OAuth, OpenID, Public Key Infrastructure, Role-Based Access Control, Zero Trust Network Access, JSON Web Token, Security Assertion Markup Language (SAML), Security Software, Security Information and Event Management, Single Sign-On, Software Vulnerability Management, Cloud Platform System, Large Language Models, Kubernetes, Production Code, Virtual Agents, Vulnerability Analysis - **Published:** September 23, 2026 - **Apply:** https://www.dice.com/job-detail/2c9ba666-fcb9-4db5-b423-58f5c2b4aa56 ## About the Role * 8+ years of experience in security engineering. * 3+ years of experience architecting and implementing Identity & Access Management at scale. * Strong hands-on experience with enterprise Identity Providers and identity federation. * Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning. * Experience mapping federated identities to downstream authorization models. * Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions. * Hands-on experience implementing RBAC and at least one of ABAC or ReBAC. * Experience with externalized authorization/policy engines. * Strong cloud IAM experience. * Hands-on experience with centralized secrets management and automated credential rotation. * Experience with containers and container orchestration. * Ability to develop production-quality code and implement security solutions hands-on. * Demonstrated experience implementing least-privilege and Just-in-Time access. * Experience building fully auditable access-control systems. Preferred Qualifications * Experience securing AI agents, LLM applications, and automated tool-invocation interfaces. * Knowledge of prompt-injection and AI tool-boundary security. * Experience with workload identity and machine-to-machine authentication. * Experience building security telemetry pipelines and SIEM integrations. * Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization. * Experience securing edge, IoT, or intermittently connected environments. * Experience with lightweight host-based security telemetry agents. * Knowledge of Zero Trust architecture. * Experience with PKI, mTLS, certificate lifecycle management, and device attestation. * Experience with event-driven security architectures. * Experience implementing secure CI/CD and automated security gates. * Security architecture certifications are a plus but not required. ## Description We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform. The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security. This is a builder's role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions., * Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems. * Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning. * Build automated user/group/role provisioning and lifecycle management. * Implement access recertification and governance processes. * Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation. * Establish SSO and API authentication across services. * Implement consistent organization and tenant isolation across identity and downstream platforms. Authorization & Policy Engineering * Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models. * Implement an externalized policy-decision engine and manage policies as code. * Define fine-grained authorization boundaries for users, applications, agents, services, and tools. * Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction. * Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough. AI Agent & Tool Security * Design authorization models for AI agents and automated tool invocation. * Establish agent workload identities and delegated authorization. * Implement per-agent cryptographic identities and on-behalf-of authorization. * Define tool-level permissions based on users, agents, tenants, resources, and actions. * Implement human-in-the-loop approval workflows for sensitive operations. * Maintain complete, tamper-evident audit trails for agent and tool activity. * Apply security controls against prompt injection and unauthorized tool execution. Secrets & Cloud Security * Implement centralized secrets management and automated credential rotation. * Design secure cloud IAM architectures and least-privilege access. * Implement secure credential management for applications, workloads, agents, and infrastructure. * Support secure execution environments and sandboxing for sensitive tool calls. Vulnerability Management * Implement continuous vulnerability scanning across: + Edge compute nodes + Containers and container images + Operating systems + Application dependencies + Container-orchestration platforms + Third-party libraries + Device firmware where applicable * Implement SBOM generation, tracking, and vulnerability correlation. * Correlate CVEs with asset exposure and exploitability. * Develop risk-based vulnerability prioritization and remediation workflows. * Build operational and executive vulnerability dashboards. * Integrate vulnerability findings with event platforms and ticketing workflows. Security Telemetry & SIEM * Deploy security telemetry capabilities across edge environments. * Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity. * Normalize security events into a common schema. * Integrate security telemetry with centralized SIEM platforms. * Implement store-and-forward capabilities for intermittently connected edge environments. * Design bandwidth-aware event batching and reliable event delivery. * Implement tamper-evident and mutually authenticated telemetry pipelines. * Maintain tenant isolation throughout the telemetry pipeline. * Develop SIEM detection and correlation rules that associate security events with verified identities. * Route actionable security alerts into event buses and on-call workflows. Platform Security Integration * Establish security standards for event-platform authentication and authorization. * Implement message signing and secure service-to-service communication. * Support edge-device identity, mTLS, PKI, and certificate lifecycle management. * Integrate security controls into CI/CD pipelines. * Implement security gates including artifact signing, IaC scanning, and automated security validation. * Partner with engineering teams to establish reusable security primitives and standards. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)