×
Register Here to Apply for Jobs or Post Jobs. X

Lead AI​/Agentic Identity Engineer

Job in Dover, Kent County, Delaware, 19904, USA
Listing for: CAI
Full Time position
Listed on 2026-08-12
Job specializations:
  • IT/Tech
    Cybersecurity, AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 117000 - 124000 USD Yearly USD 117000.00 124000.00 YEAR
Job Description & How to Apply Below

Lead AI/Agentic Identity Engineer

Req number:

R8266

Employment type:

Full time

Worksite flexibility:

Remote

Who we are

CAI is a global services firm with over 9,000 associates worldwide and a yearly revenue of $1.3 billion+. We have over 40 years of excellence in uniting talent and technology to power the possible for our clients, colleagues, and communities. As a privately held company, we have the freedom and focus to do what is right—whatever it takes. Our tailor-made solutions create lasting results across the public and commercial sectors, and we are trailblazers in bringing neurodiversity to the enterprise.

Job Summary

We are looking for a motivated Lead AI/Agentic Identity Engineer ready to take us to the next level! If you have deep expertise in identity architecture, AI agent security, OAuth/OIDC, workload identity, and Zero Trust principles, and are looking for your next career move.

Job Description

We are looking for a Lead AI/Agentic Identity Engineer to lead the design and implementation of an enterprise identity architecture for AI agents, autonomous workflows, and other non-human identities. The Lead AI/Agentic Identity Engineer will establish enterprise standards, governance models, and implementation blueprints that enable AI agents to operate as secure, auditable, and governed digital identities across cloud, hybrid, internal, and guest-facing environments.

This position will be a contract and remote with occasional travel to Miami, FL.

Due to the specific legal and contractual requirements associated with this position, this role will be direct employment with CAI. This position does not offer work authorization sponsorship now or in the future.

What You'll Do
  • Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability
  • Design operational models for governed non-human identities, including ownership, lifecycle management, registration, approval, attestation, recertification, and retirement
  • Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and attribution
  • Lead architecture design across identity providers, CI/CD pipelines, agent platforms, secrets management systems, API gateways, service meshes, and cloud-native workload identity services
  • Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE, mTLS, certificate-based authentication, short-lived credentials, and key lifecycle management
  • Define authorization frameworks utilizing OAuth 2.0/2.1, OIDC, token exchange, delegated authority models, audience-bound tokens, and just-in-time access controls
  • Establish architecture standards for Model Context Protocol (MCP), Agent2

    Agent (A2A), multi-agent orchestration, and secure tool-calling systems
  • Design policy decision and enforcement models across APIs, services, workloads, and AI runtimes
  • Guide implementation of runtime guardrails, including human-in-the-loop approvals, step-up authentication, revocation controls, rate limiting, transaction thresholds, and emergency stop capabilities
  • Partner with security, infrastructure, platform, and application teams to align AI identity controls with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering programs
  • Define telemetry, logging, audit, and traceability requirements across user, agent, sub-agent, tool, and data access interactions
  • Lead architecture reviews, threat modeling exercises, design workshops, and implementation planning sessions
  • Develop executive-facing roadmaps, architecture decision records, implementation guidance, control mappings, and knowledge transfer materials
What You'll Need

Required:

  • 10+ years of experience in enterprise security architecture, IAM architecture, cloud security, platform security, or application security
  • Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity solutions at scale
  • Deep expertise in identity providers, OAuth/OIDC, service-to-service authentication, token security, API security, and cloud authorization frameworks
  • Strong knowledge of Zero Trust architecture, least privilege principles, privileged access management, identity governance, access certification, and policy-based access control
  • Experience designing secure architectures for distributed systems, APIs, microservices, containers, service meshes, and hybrid or multi-cloud environments
  • Ability to design deterministic security controls for autonomous and AI-enabled systems
  • Familiarity with agentic AI security concepts, AI agent runtimes, delegated authority, tool-calling frameworks, and AI-specific risks such as prompt injection, excessive agency, unsafe tool usage, and autonomous process escalation
  • Experience leading cross-functional architecture workshops and translating business, security, risk, and compliance requirements into technical solutions
  • Strong written and verbal communication skills with experience…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary