About this role
Job title: Identity & Gen AI Engineer
About the Role
As organizations adopt generative AI, securing how AI agents, models, and automated workflows access enterprise systems and data has become a core engineering challenge. As an Identity & Gen AI Engineer, you will build generative AI solutions with identity, access, and trust engineered in from the start, securing both human and non-human identities and governing how AI agents and GenAI platforms reach data and downstream systems. This role focuses on hands-on engineering, integration, and continuous enhancement of AI solutions in which identity and access controls are a first-class concern.
What You'll Do
- Build and integrate generative AI solutions, including LLM applications, retrieval-augmented generation, and AI agents, with secure access to data and downstream systems.
- Engineer authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities operating across enterprise and cloud environments.
- Develop guardrails for agentic workflows, including scoped permissions, least-privilege access, credential and secrets management, and runtime policy enforcement.
- Implement logging, monitoring, and governance that provide traceability and accountability for AI system actions.
- Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.
- Create and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.
What We're Looking For
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a similar technical field.
- Ability to work onsite up to 5 days a week.
- 3+ years of software engineering experience with Python or a comparable language.
- 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as large language model (LLM) applications, retrieval-augmented generation (RAG), or AI agents, including use of model APIs and tools such as Claude Code, OpenAI Codex, GitHub Copilot, or Cursor.
- Working knowledge of identity and access management concepts and protocols, including authentication, authorization, single sign-on (SSO), and standards such as OpenID Connect (OIDC), Security Assertion Markup Language (SAML), OAuth, and JSON Web Token (JWT).
- Ability to travel 15% on average.
- Ability to obtain and maintain the necessary security clearance. Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Nice to Have
- Experience deploying generative AI solutions to production environments.
- Hands-on experience with identity and access management platforms such as SailPoint, Okta, or Microsoft Entra ID.
- Experience securing non-human or machine identities, service accounts, secrets, and credentials using tools such as HashiCorp Vault or CyberArk.
- Experience with AI agent frameworks and protocols such as LangChain, LangGraph, or Model Context.
Compensation & Benefits
- Salary and benefits are not disclosed in the posting.