About this role
About the Role The Associate Director will lead the design, selection, and implementation of enterprise cybersecurity solutions spanning non-human identity (NHI) and credential management — including agentic AI identities — and endpoint software execution and configuration controls across Windows and macOS. This is a hands-on leadership role that will grow and then guide a small team of senior security engineers, remain directly engaged in architecture decisions and vendor evaluations, and advance complex technical problem-solving. A core focus is building the AI security control plane — the identities, enforcement points, telemetry, and governance that make agentic AI and automation safe to operate at enterprise scale. What You'll Do
- Own the technical strategy, architecture, and roadmap for NHI and credential security, agentic AI identity governance, and endpoint execution and configuration control across Windows and macOS.
- Lead and develop a team of senior security engineers, direct contingent workers and professional services engagements to deliver program outcomes.
- Evaluate, select, and deploy enterprise platforms for secrets management, agentic identity governance, and endpoint application allow-listing — leading vendor selection, POV exercises, and integration into the broader security stack.
- Design and operationalize the full credential lifecycle for non-human identities — vaulting, brokered access, short-lived credentials, workload identity, rotation, attestation, and decommissioning — for services, automation, CI/CD, and AI agents.
- Build the AI security control plane: enforcement points, approval and exception workflows, audit telemetry, and policy guardrails governing how agents and programmatic identities access tools, data, and endpoints.
- Partner with AI platform owners and engineering teams to make secure credential use and policy-compliant tool access the default in developer workflows.
- Lead endpoint execution control and configuration hardening — allow-listing, code-signing trust, script and installer controls, policy authoring, staged rollouts, exception handling, and continuous compliance.
- Build detection and reporting for credential misuse and execution-control bypass; partner with SecOps and Cyber Incident Response on playbooks and response.
- Author standards, reference architectures, and technical documentation; serve as a principal-level reviewer and mentor across identity and endpoint security initiatives. What We're Looking For
- 8+ years of experience in security engineering, identity engineering, platform engineering, or a closely related domain, with demonstrated principal-level technical leadership.
- Demonstrated ability to drive complex initiatives across multiple teams, balancing risk reduction, delivery timelines, and stakeholder alignment.
- Ability to navigate ambiguous and sometimes conflicting requirements and priorities, cut through noise to make decisions and take action, incorporate feedback constructively, and maintain strong judgment when sustained direction is needed—delivering short-term progress while building toward long-term solutions.
- Experience leading and scaling delivery through a mix of direct reports, contingent workers, and/or professional services partners.
- Deep understanding of non-human identity patterns and programmatic credential use in modern systems (microservices, CI/CD, IaC, automation, and APIs).
- Hands-on experience implementing credential security controls such as secrets management/vaulting, PKI/cert lifecycle, token issuance/exchange, short-lived credentials, and automated rotation.
- Strong knowledge of authentication and authorization concepts (OAuth 2.0, OIDC, SAML, JWT, mTLS, key management, least privilege, scoped permissions).
- Experience designing operational processes for credential inventory, ownership, attestation, and lifecycle governance at scale.
- Endpoint platform familiarity across Windows and macOS, including OS security primitives, software distribution, and device management concepts.
- Experience implementing endpoint execution controls and configuration baselines across Windows and macOS, including policy rollout, exception management, and measurable enforcement outcomes.
- Familiarity and hands-on experience with modern AI platforms and developer assistants (e.g., OpenAI, Anthropic, GitHub Copilot), including how they are integrated and governed in enterprise environments.
- Strong cybersecurity fundamentals and experience designing preventive/detective controls and control-plane architectures (policy, enforcement, monitoring) that scale across platforms and teams.
- Ability to translate risk into pragmatic designs and to influence across Security, IT, and Product/Engineering stakeholders.
- Strong written communication and documentation skills; ability to define standards and drive adoption. Nice to Have
- Experience with enterprise secrets/token platforms (HashiCorp Vault, Conjur, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager) and integrating them into developer platforms.
- Experience with GxP regulated environments.
- Experience with workload identity and federation patterns (SPIFFE/SPIRE, cloud workload).