Lead AI / Agentic Identity Engineer: $107/hr
Apply Now! Job Code: 072026LAIEJob Description
One of Infonet's premier clients has an opening for a Lead AI / Agentic Identity Engineer. (1238)
TERMS: Contract
SCOPE OF WORK
• Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability
• Design the operating model for treating agents as governed non-human identities, including ownership, lifecycle, registration, approval, attestation, recertification, and retirement
• Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and end-to-end attribution
• Lead design of agent identity patterns across IdPs, CI/CD pipelines, agent build platforms, secrets management, API gateways, service meshes, and cloud-native workload identity services
• Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE or equivalent patterns, mTLS, short-lived credentials, certificate-based authentication, and key lifecycle controls
• Define authorization patterns for OAuth 2.0/2.1, OIDC, token exchange, on-behalf-of flows, audience-bound tokens, just-in-time access, and delegated authority in agentic workflows
• Establish architecture principles for Model Context Protocol, Agent2Agent, multi-agent orchestration, and tool-calling systems, including no token pass-through, bounded delegation, and least-privilege tool access
• Design policy decision and enforcement models that apply consistently from edge to API to service to AI runtime layers
• Guide implementation of runtime guardrails for high-risk actions, including step-up controls, human-in-the-loop approvals, revocation, rate limits, transaction thresholds, and emergency stop patterns
• Partner with security engineering teams to align agent identity architecture with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering capabilities
• Define telemetry, logging, audit, and traceability requirements to capture user → agent → sub-agent → tool → data access chains for compliance, forensics, and operational monitoring
• Lead architecture reviews, threat modeling sessions, design workshops, and implementation planning with IAM, AI/ML, platform, cloud, application, and product teams
• Produce executive-ready roadmaps, architecture decision records, implementation patterns, control mappings, and knowledge-transfer materials for long-term internal ownership
REQUIRED SKILLS / EXPERIENCE
• 10+ years of experience in enterprise security architecture, IAM architecture, cloud security architecture, platform security, or application security
• Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity capabilities at scale
• Strong architecture experience across identity providers, OAuth/OIDC, token security, service-to-service authentication, API security, and cloud-native authorization models
• Deep understanding of Zero Trust, least privilege, privileged access management, identity governance, access certification, and policy-based access control
• Experience designing secure architectures for distributed systems, microservices, APIs, containers, service meshes, and hybrid or multi-cloud environments
• Ability to design deterministic security controls for non-deterministic or autonomous AI-enabled systems
• Familiarity with agentic AI security concepts, AI agent runtimes, tool-calling patterns, delegated authority, and risks such as excessive agency, prompt injection, unsafe tool use, and runaway automation
• Experience leading cross-functional architecture workshops and translating business, risk, and compliance objectives into implementable technical designs
• Strong written communication skills, including architecture documentation, design standards, implementation guides, executive summaries, and control narratives
PREFERRED SKILLS / EXPERIENCE
• Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards
• Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, or certificate lifecycle management
• Experience with policy-as-code, runtime authorization, ABAC/ReBAC models, or centralized policy decision points
• Experience designing controls for regulated, SOX-relevant, PCI, privacy-sensitive, or high-availability environments
• Experience building maturity models, capability roadmaps, control frameworks, or executive-level investment cases for emerging security domains
PREFERRED EDUCATION
• Bachelor’s in Computer Science or Equivalent
TRAVEL REQUIREMENT
• Yes – Occasional Meetings in Miami
** No 3rd party vendors ** Unable to sponsor H1-B visas **
Please refer to position: 072026LAIE - Lead AI / Agentic Identity Engineer: $107/hr in the subject line of all correspondence.
Please select the "Apply Now" button. We look forward to reviewing your resume and speaking with you personally.