> Markdown version of [/jobs/ext/3531346-principal-iam-ai-engineer](https://www.wearedevelopers.com/jobs/ext/3531346-principal-iam-ai-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IAM AI Engineer - **Company:** Global Business Travel Group, Inc. - **Location:** Dover, DE, United States - **Experience:** Expert - **Salary:** $104,300.0 - $193,700.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Artificial Intelligence, Amazon Web Services, Cyber Security, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Security Assertion Markup Language (SAML), Software Engineering, Okta, Cyberark, Istio, Multi-Cloud, Agentic-AI, Kubernetes, Hashicorp, Virtual Agents, SailPoint, Model Context Protocol, Terraform - **Published:** October 1, 2026 - **Apply:** https://dejobs.org/x/x/25647DDC73714CD9933F9BEC073B747A/job/ ## About the Role * Deep expertise in enterprise identity infrastructure: PAM (CyberArk or equivalent), Okta as IdP, and IGA platforms like Saviynt, including extending governance beyond human identities. * Strong AWS and cloud identity skills: IAM design, ephemeral credentials, OIDC federation, secrets/certificate management, and least-privilege at scale. * Mastery of core identity standards (OAuth, OIDC, SAML, SCIM, JWT, mTLS) and machine-to-machine/workload identity across on-prem, hybrid, and multi-cloud environments. * Proven ability to architect enterprise-scale identity security programs and govern non-human identities (inventory, ownership, certification, credential rotation, risk). * Strong cross-functional leadership and communication skills, with sound judgment for operating in an emerging, still-being-defined discipline. Must Have * 8+ years in IAM/cybersecurity, with 5+ years at architect or principal level owning target-state design for an enterprise security or identity domain. * Proven experience designing identity, access, and governance controls for non-human identities - service accounts, workload identities, and AI agents - at enterprise scale. * Strong AWS (or equivalent public cloud) identity and access design experience at multi-account scale. * Hands-on experience with Okta (or comparable access management/federation platform) and Saviynt (or comparable IGA platform). * Experience with privileged access management platforms such as Idira (formerly CyberArk) and HashiCorp Vault, or comparable tools., * Identity Threat Detection and Response (ITDR) and posture management Experience with SPIFFE/SPIRE or service mesh identity patterns * Knowledge of emerging AI regulation and frameworks * Externalized authorization and policy orchestration expertise * Experience with Model Context Protocol (MCP) and agent-to-agent patterns * Kubernetes and container security with workload identity * Automation ability in Python, PowerShell or Terraform * Relevant certifications: CISSP, CISM, CCSP, CyberArk, Okta, AWS Security, or architecture certifications ## Description * Access control execution. Deploy and automate identity controls at runtime for NHI identity - including immediate authentication verification, access authorization, and real-time rule application across the environment. * Machine identity & agentic system governance. Build, deploy, and automate lifecycle governance for agents and machine identities - spanning discovery and registration, permission assignment, credential lifecycle, periodic access reviews, and secure retirement. * Credential workflows for AI workloads. Construct and operationalize credential management systems for AI-driven applications and agents, encompassing automated secret cycling, short-lived credential issuance, and protected distribution to runtime environments. * Granular authorization & declarative policies. Establish and implement fine-grained, zero-standing-privilege access models for agents and workloads, documented and managed through infrastructure-as-code and policy declaration frameworks. * Integration with AI development lifecycle. Collaborate with application development and ML teams throughout all AI initiative phases, ensuring identity requirements, credential handling, and access controls are incorporated during design rather than retrofitted. * End-user identity controls rollout. Facilitate implementation and adoption of identity governance controls for human users as required by organizational standards. * Compliance, audit & risk alignment. Work with compliance, risk and audit functions to confirm controls align with regulatory requirements and internal policies; facilitate audit evidence generation and regulatory reporting. * Organization building & technical strategy. Lead an engineering team supporting these initiatives; establish technical direction, strategic priorities and delivery roadmap for machine identity and agent IAM programs. Advisory, enablement and leadership * Serve as a trusted advisor to senior leadership on machine and AI identity risk, and translate it into funded, sequenced remediation. * Partner with InfoSec and AI Security teams on proof-of-concept evaluations and vendor assessments for AI and agent governance platforms. * Mentor engineers and architects on non-human and agent identity patterns, and raise the organization's overall fluency in machine identity security., * Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and wellbeing resources to support you and your immediate family. * Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals. * Develop the skills you want when the time is right for you, with access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first. * We strive to champion Inclusion in every aspect of our business at Amex GBT. You can connect with colleagues through our global INclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action. * And much more! All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law. Click Here (https://explorer.amexglobalbusinesstravel.com/rs/346-POJ-129/images/Additional%20Disclosures%20in%20Accordance%20with%20the%20LA%20County%20Fair%20Chance%20Ordinance.pdf?version=2) for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [ I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.](https://www.wearedevelopers.com/magazine/773-i-gave-a-video-editor-more-autonomy-than-a-trading-bot-on-purpose) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)