> Markdown version of [/jobs/ext/642468-ai-iam-architect](https://www.wearedevelopers.com/jobs/ext/642468-ai-iam-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI IAM Architect - **Company:** LPL Financial - **Location:** Fort Mill, SC, United States (Remote available) - **Experience:** Experienced - **Salary:** $153,470.0 - $255,749.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Cyber Security, Continuous Integration, Data Security, Identity and Access Management, Intrusion Detection and Prevention, OAuth, OpenID, Ping (Networking Utility), Azure Active Directory, Zero Trust Network Access, Azure Machine Learning, JSON Web Token, Runbook, Security Assertion Markup Language (SAML), Systems Integration, Cyberark, Customer Identity Access Management, AI Platforms, Api Gateway, SailPoint, Microservices - **Published:** June 25, 2026 - **Apply:** https://lplfinancial.wd1.myworkdayjobs.com/External/job/Fort-MillCharlotte/AI-IAM-Architect_R-050862 ## About the Role * 10+ years in IAM, security architecture, or platform engineering with significant IAM scope. * 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows (Auth Code + PKCE, refresh tokens, client credentials, token exchange, OBO). * 2+ years with PingOne AIC and/or Microsoft Entra ID. Core Competencies: * Hands-on experience designing identity for APIs, microservices, and BFF architectures. * Experience integrating IAM with API gateways, AI/ML platforms, and modern application stacks. * Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns. * Familiarity with agent/tool identity models and secure integration patterns. * Ability to translate AI requirements into secure identity designs; strong communication skills. Preferences: * Experience delivering AI/ML agents or copilots to production. * Experience with SailPoint, CyberArk/Delinea, or Auth0/CIAM. * Knowledge of AI-aware API gateways (e.g., Kong). * Experience with IAM modernization or M&A programs. * Relevant certifications (CISSP, CCSP, Entra, Ping, SailPoint, AWS). * Familiarity with zero trust and identity threat detection. ## Description We are seeking an experienced Identity and Access Management (IAM) Architect with a strong AI and agent-integration focus to lead the design, proof-of-concept (POC), and hands-on implementation of identity patterns for AI workloads, conversational agents, and AI platform integrations across the enterprise. The ideal candidate combines deep IAM architecture expertise with practical engineering skills-building POCs, configuring OAuth/OIDC flows, and partnering directly with AI engineering teams to secure agent runtimes, tool access, and human-in-the-loop experiences. This role owns IAM architecture for AI use cases, including delegated and service-to-service access, API gateway/BFF token flows, scoped credentials, and governance alignment. You will design and validate OAuth/OIDC patterns (Auth Code + PKCE, OBO, token exchange, client credentials) across identity providers (PingOne AIC, Entra ID), gateways, and agent platforms. The AI IAM Architect partners across AI/platform engineering, IAM, security, and enterprise architecture to define reusable, secure, and production-ready identity standards for agents., * Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs. * Assess existing SSO, MFA, federation, and API authorization models; identify gaps in delegation, token lifecycle, scopes, secrets, and auditability. * Design enterprise IAM patterns (user context propagation, delegation chains, BFF sessions, least-privilege access) and OAuth/OIDC client models. * Define standards for securing agent tools, data access, and cross-domain integrations; align to zero trust and regulatory controls. * Produce architecture artifacts (CAD/HLD/PSS) and reference implementations. * Lead and build IAM POCs (end-to-end flows, token exchange, gateway enforcement, delegated agent access). * Configure/test identity flows; troubleshoot tokens, scopes, and integrations. * Implement or guide IAM integrations across gateways, BFFs, agent orchestration, and observability. * Transition validated patterns to IAM engineering for production rollout. * Define agent identity lifecycle (registration, credential rotation, revocation, environment separation). * Integrate IAM across AI platform components; support CI/CD and IaC for IAM configurations. * Establish patterns for human-in-the-loop controls, break-glass access, and rate limiting. * Maintain documentation, decision records, diagrams, and runbooks. * Deliver POC summaries, evaluations, and implementation guidance; communicate risks and dependencies. * Ensure regulatory compliance; partner on threat modeling and controls (secrets, PAM, audit evidence). * Serve as IAM SME for AI initiatives; mentor engineers. * Deliver production-ready IAM patterns and reduce identity risk across AI workloads. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development)