Required Qualifications
- 5+ years of experience in identity and access management, security engineering, or cloud security, with hands-on ownership of production IAM platforms.
- Deep working knowledge of OAuth 2.0, OIDC, and SAML 2.0, including:
- Token Exchange (RFC 8693)
- Assertion-based grants (RFC 7522/7523)
- JWT/JWK internals
- Direct experience with Workload Identity Federation (WIF) across at least one major cloud platform: GCP, Azure, or AWS.
- Practical understanding of emerging AI-agent identity patterns, including Cross-App Access (XAA), ID-JAG, and delegated authorization for autonomous agents.
- Experience designing or operating Zero Trust architectures, including continuous verification, least privilege, and micro-segmentation, for both human and non-human identities.
- Hands-on architectural experience with at least one enterprise identity platform, such as Okta or Microsoft Entra ID, including custom authorization servers, Workflows/Conditional Access, and SCIM provisioning.
- Familiarity with SIEM/EDR-driven detection of identity abuse, including Splunk, SentinelOne, or equivalent.
- Working knowledge of SOX, ISO 27001, and PCI DSS as they apply to identity controls.
- Strong written communication skills, with the ability to translate identity risk into governance artifacts and executive-ready findings.
Preferred Qualifications
- Security certifications such as CISSP, CCSP, CISM, or CISA.
- Direct experience securing AI/ML platforms such as Vertex AI, Databricks, or Azure AI, or building authentication layers for internal agent frameworks.
- Experience with MCP (Model Context Protocol) or similar agent-to-tool authorization models.
- Background contributing to or tracking IETF/OAuth Working Group drafts related to agentic and delegated authentication.
- Experience running an NHI discovery and remediation program from scratch, including build-vs-buy evaluation, rollout, and adoption metrics.
- Prior incident response experience involving compromised service accounts or leaked long-lived credentials.
- Experience working in regulated, multi-brand, or M&A-heavy enterprise environments.
Technical Environment
Identity Platforms
- Okta - OIDC, SAML, Workflows, custom authorization servers, System Log
- Microsoft Entra ID / Azure AD
- Entra Connect
- SCIM
Cloud IAM
- GCP IAM & Vertex AI service accounts
- Azure Managed Identity
- AWS IAM, as applicable
- Workload Identity Federation across GCP, Azure, and AWS
AI / Data Platforms
- Databricks Unity Catalog
- Vertex AI
- Internal agent and automation frameworks
Security Operations
- Splunk - SIEM / SPL
- SentinelOne - EDR / Singularity
- Cloud audit logging:
- GCP Audit Logs
- Azure Activity Logs
Protocols & Standards
- OAuth 2.0
- OIDC
- SAML 2.0
- RFC 8693 - Token Exchange
- RFC 7522/7523 - SAML/JWT Bearer Assertion
- ID-JAG
- Cross-App Access (XAA)
- Workload Identity Federation (WIF)
Governance & Security Frameworks
- SOX
- ISO 27001
- PCI DSS
- COBIT
- OWASP Top 10