CXC Global is partnering with an innovative, AI-driven organization that is leveraging advanced technologies to transform business operations through intelligent automation and agentic AI solutions. We are seeking a Senior Information Security Analyst – Agentic AI Identity Governance to lead the development and operationalization of governance frameworks that secure and manage AI-powered agents operating across enterprise environments.
This is an exciting opportunity for a security professional who understands identity governance, risk management, and access controls, and is passionate about helping organizations adopt AI responsibly, securely, and at scale.
Location: Toronto, ON or Mt. Laurel, NJ
Duration: 6-Month Contract with Potential Extension
Start Date: Immediate
Work Authorization: Citizens and Green Card Holders only. Sponsorship or transfer of sponsorship is not available for this opportunity.
Position Summary
As a Senior Information Security Analyst focused on Agentic AI Identity Governance, you will be responsible for establishing and overseeing governance controls for AI agents and other non-human identities. You will work across cybersecurity, IAM, AI engineering, compliance, privacy, legal, and risk management functions to ensure AI systems operate within defined security guardrails while maintaining accountability, transparency, and regulatory compliance.
The ideal candidate brings a strong background in identity governance, privileged access management, security controls, and risk assessment, coupled with an interest in emerging AI governance practices.
Key Responsibilities
AI Identity Governance & Lifecycle Management
- Define and maintain governance standards for AI agents and non-human identities across enterprise systems.
- Establish processes for identity registration, ownership assignment, classification, and entitlement management.
- Develop and manage lifecycle controls covering onboarding, provisioning, approval workflows, access reviews, suspension, and decommissioning.
- Ensure accountable business ownership is assigned for all AI agent identities.
Access Control & Security Architecture
- Design access models based on least privilege, segregation of duties, policy-based authorization, delegated authority, and just-in-time access principles.
- Support implementation of governance controls for privileged and non-privileged AI agents.
- Collaborate with IAM and security teams to align AI identity controls with enterprise security architecture and Zero Trust strategies.
Risk, Compliance & Oversight
- Conduct risk assessments focused on AI agent activities, decision-making capabilities, tool usage, system integrations, and privileged operations.
- Identify governance gaps and recommend appropriate control enhancements.
- Assist in policy development related to AI governance, human oversight requirements, escalation procedures, and exception management.
- Participate in audit readiness activities and compliance reviews related to AI-enabled technologies.
Monitoring, Auditability & Reporting
- Define monitoring and audit requirements to ensure AI activity is observable, attributable, and traceable.
- Support implementation of logging, analytics, and reporting capabilities for AI identities.
- Conduct periodic access certification reviews and governance maturity assessments.
- Produce executive-level reporting on security posture, control effectiveness, risk exposure, and remediation progress.
Cross-Functional Collaboration
- Partner with Cybersecurity, IAM, AI Engineering, Privacy, Compliance, Legal, and Risk teams to establish secure AI operating models.
- Contribute to threat modeling exercises focused on identity misuse, privilege escalation, credential compromise, unauthorized tool execution, and policy violations.
- Provide guidance on emerging AI governance requirements and industry best practices.
Required Qualifications
- 5+ years of experience in Information Security, Identity & Access Management (IAM), Security Governance, Risk Management, Cybersecurity, or a related discipline.
- Strong understanding of Identity Governance & Administration (IGA), Privileged Access Management (PAM), authentication, authorization, access lifecycle management, and certification processes.
- Experience supporting controls for non-human identities, including service accounts, machine identities, APIs, automation platforms, bots, or AI-enabled systems.
- Knowledge of Zero Trust security principles and least-privilege access methodologies.
- Experience conducting risk assessments, control evaluations, compliance reviews, and audit support activities.
- Ability to translate complex technology risks into practical governance controls and business recommendations.
- Excellent communication, stakeholder management, analytical, and problem-solving skills.
Preferred Qualifications
- Experience supporting AI governance, responsible AI initiatives, data governance programs, or model risk management activities.
- Familiarity with agentic AI concepts such as autonomous planning, memory, tool orchestration, delegated authority, and multi-agent workflows.
- Hands-on experience with:
- IAM platforms
- IGA solutions
- PAM technologies
- SIEM/SOAR platforms
- API security solutions
- Cloud identity platforms
- Security monitoring tools
- Industry certifications such as:
- CISSP
- CISM
- CISA
- CCSP
- CRISC
- Security+
- Identity-focused certifications
- Experience working within highly regulated industries such as financial services, healthcare, government, or critical infrastructure.
Technical & Governance Expertise
Successful candidates should demonstrate experience in:
- Identity governance across human, privileged, machine, service, and AI-agent identities
- Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Policy-Based Access Control (PBAC)
- Privileged Access Management (PAM) and Just-In-Time (JIT) access models
- Security monitoring, audit logging, identity analytics, and anomaly detection
- AI identity governance frameworks and control design
- Risk assessment methodologies and security control mapping
- Security policy development and governance documentation
- Cross-functional collaboration across security, architecture, compliance, risk, and engineering teams