Identity Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+17 more
Job description
Security Engineer / Architect Identity, Authorization & Platform Security Location: Denver, CO 100% Onsite Job Type: Contract Duration: Contract / Long-Term Engagement Position Overview We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform. The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security. This is a builder’s role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions. Key Responsibilities Identity & Access Management / RBAC
- Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.
- Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning.
- Build automated user/group/role provisioning and lifecycle management.
- Implement access recertification and governance processes.
- Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
- Establish SSO and API authentication across services.
- Implement consistent organization and tenant isolation across identity and downstream platforms.
Authorization & Policy Engineering
- Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
- Implement an externalized policy-decision engine and manage policies as code.
- Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
- Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction.
- Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.
AI Agent & Tool Security
- Design authorization models for AI agents and automated tool invocation.
- Establish agent workload identities and delegated authorization.
- Implement per-agent cryptographic identities and on-behalf-of authorization.
- Define tool-level permissions based on users, agents, tenants, resources, and actions.
- Implement human-in-the-loop approval workflows for sensitive operations.
- Maintain complete, tamper-evident audit trails for agent and tool activity.
- Apply security controls against prompt injection and unauthorized tool execution.
Secrets & Cloud Security
- Implement centralized secrets management and automated credential rotation.
- Design secure cloud IAM architectures and least-privilege access.
- Implement secure credential management for applications, workloads, agents, and infrastructure.
- Support secure execution environments and sandboxing for sensitive tool calls.
Vulnerability Management
- Implement continuous vulnerability scanning across: Edge compute nodes, Containers and container images, Operating systems, Application dependencies, Container-orchestration platforms, Third-party libraries, Device firmware where applicable.
- Implement SBOM generation, tracking, and vulnerability correlation.
- Correlate CVEs with asset exposure and exploitability.
- Develop risk-based vulnerability prioritization and remediation workflows.
- Build operational and executive vulnerability dashboards.
- Integrate vulnerability findings with event platforms and ticketing workflows.
Security Telemetry & SIEM
- Deploy security telemetry capabilities across edge environments.
- Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
- Normalize security events into a common schema.
- Integrate security telemetry with centralized SIEM platforms.
- Implement store-and-forward capabilities for intermittently connected edge environments.
- Design bandwidth-aware event batching and reliable event delivery.
- Implement tamper-evident and mutually authenticated telemetry pipelines.
- Maintain tenant isolation throughout the telemetry pipeline.
- Develop SIEM detection and correlation rules that associate security events with verified identities.
- Route actionable security alerts into event buses and on-call workflows.
Platform Security Integration
- Establish security standards for event-platform authentication and authorization.
- Implement message signing and secure service-to-service communication.
- Support edge-device identity, mTLS, PKI, and certificate lifecycle management.
- Integrate security controls into CI/CD pipelines.
- Implement security gates including artifact signing, IaC scanning, and automated security validation.
- Partner with engineering teams to establish reusable security primitives and standards., Key Responsibilities Active Directory Architecture & Administration Design: Design, maintain, and support enterprise Microsoft Active Directory environments. Architect secure and…
- 18 hours ago
- Apply easily +
Requirements
- 8+ years of experience in security engineering.
- 3+ years of experience architecting and implementing Identity & Access Management at scale.
- Strong hands-on experience with enterprise Identity Providers and identity federation.
- Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning.
- Experience mapping federated identities to downstream authorization models.
- Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
- Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
- Experience with externalized authorization/policy engines.
- Strong cloud IAM experience.
- Hands-on experience with centralized secrets management and automated credential rotation.
- Experience with containers and container orchestration.
- Ability to develop production-quality code and implement security solutions hands-on.
- Demonstrated experience implementing least-privilege and Just-in-Time access.
- Experience building fully auditable access-control systems.
Preferred Qualifications
- Experience securing AI agents, LLM applications, and automated tool-invocation interfaces.
- Knowledge of prompt-injection and AI tool-boundary security.
- Experience with workload identity and machine-to-machine authentication.
- Experience building security telemetry pipelines and SIEM integrations.
- Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
- Experience securing edge, IoT, or intermittently connected environments.
- Experience with lightweight host-based security telemetry agents.
- Knowledge of Zero Trust architecture.
- Experience with PKI, mTLS, certificate lifecycle management, and device attestation.
- Experience with event-driven security architectures.
- Experience implementing secure CI/CD and automated security gates.
- Security architecture certifications are a plus but not required.
About the company
Cargill is committed to providing food and agricultural solutions to nourish the world in a safe, responsible, and sustainable way. Sitting at the heart of the supply chain, we par…
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship
Everything a Developer Needs to Know About MCP with Neo4j
Understanding and Mitigating Common Web Vulnerabilities