Talent Apply
Log in
All jobs
A

Identity and access management architecture

Atos
Bangalore & Mumbai, India Posted Sep 28, 2026
On-site

About this role

Identity and access management architecture

Identity and access management architecture at design depth (authentication, authorisation, federation, lifecycle, governance), applied to AI systems and agents

  • Architected and productised identity services (reference architecture, platform evaluation and selection, service definition), not implementation only
  • AI agent identity lifecycle: registration with a human sponsor, declared scope, short-lived credential issuance, revocation; hands-on with at least one of Microsoft Entra Agent ID, Okta cross-app access, SailPoint Agent Identity Security, Cisco/Astrix
  • AI access governance: bringing models, agents and datasets under the same entitlement model and access certification as applications, through SailPoint ISC or Saviynt at registry and API level, and SCIM 2.0
  • Delegated authorisation at protocol depth: how a user's authority becomes an agent's authority via OAuth 2.1, token exchange (RFC 8693) and on-behalf-of flows, sender-constrained tokens (DPoP, mTLS), OIDC claims and audiences
  • Built or integrated an authorisation system in production (policy engine, authorisation service or token-level IdP integration)
  • Policy as code for agent scopes and tool permissions: OPA/Rego or Cedar
  • Model Context Protocol and agent frameworks: where identity is asserted in a tool call, tool allow-listing, per-task isolation
  • Prompt-time entitlement enforcement: RAG architecture with retrieval scoped to the asker's identity entitlements (permission filtering at retrieval, index scoping per asker)
  • AI gateway / prompt control layer deployment (Microsoft Purview, Zenity, Lasso or open-source) integrated with the identity provider for the asker's token and the entitlement model for their rights
  • Microsoft Entra ID or Okta at token issuance, conditional access and session level, where an agent's delegated authority originates and is revoked
  • Non-human identity governance and SPIFFE/SPIRE workload identity as the source of agent credentials

Good to have

  • Microsoft, Google, AWS and Anthropic agent and model platforms; sovereign model hosting (Mistral, Aleph Alpha)
  • Telemetry modelling in an open schema (OCSF)
  • EU AI Act human-oversight obligations; GDPR and works-council constraints on prompt inspection
  • Awareness of AI security and MITRE ATLAS (prompt injection, model safety), which is adjacent to this role rather than part of it

Candidates will rarely tick every must-have, and that is expected. The ones that should not be waived are:

  • the service-architecture experience on all three
  • SOC fluency for ITE
  • key ceremony and PKI design depth for Machine Identity, and
  • the protocol-level authorisation experience and IAM architecture depth for Identity for AI

Work Location: Bangalore & Mumbai

Here at Atos, diversity and inclusion are embedded in our DNA. Read more about our commitment to a fair work environment for all.

Atos is a recognized leader in its industry across Environment, Social and Governance (ESG) criteria. Find out more on our CSR commitment.

Choose your future. Choose Atos.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →