AVP, IAM AI Engineer

LPL Financial - Fort Mill, SC

Hiring: AVP, IAM AI Engineer Company: LPL Financial Location: Fort Mill, SC Job Posted Time: 2026-09-03 11:14:36 Target Skills & Keywords : AWS, Azure, CI/CD, CyberArk, Embedded Systems, GCP, IAM, Kubernetes, LLM, OAuth, OAuth2, OIDC, Python, REST, SIEM, SOC, Sentry, Terraform, Vault, Wealth Management About the job Experience: •5+ years in identity & access management or information security, including hands-on engineering. •5+ years with Ping Identity (PingFederate / PingOne / PingAccess) or a comparable access-management / federation platform. •5+ years with SailPoint (IdentityIQ / Identity Security Cloud) or a comparable identity governance & administration (IGA) platform. •3+ years with Idira (CyberArk, formerly Conjur) / HashiCorp Vault or a comparable secrets-management platform. Required Skills: •Identity runtime controls. Operationalize and automate identity runtime controls across human and non-human identities, including real-time authentication, authorization, and policy enforcement. •NHI & agentic governance. Design, build, and automate governance controls for AI agents and non-human identities — covering the full lifecycle: provisioning, entitlement, rotation, certification/attestation, and deprovisioning. •Secrets management for AI. Develop and automate secrets-manager workflows for AI systems and agents, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery to workloads. •Least privilege & policy-as-code. Define and enforce fine-grained, least-privilege authorization models for agents and workloads, expressed as policy-as-code wherever possible. •Reference architecture & standards. Establish standards and reference patterns for how identity flows through agentic systems — user-to-agent, agent-to-agent (A2A), and workload-to-service authentication and authorization. •Embedded in AI development. Partner with engineering and data science teams on all new AI application development, ensuring identity, AuthN/AuthZ, and secrets handling are designed in from the start. •End-user IAM deployment. Support the deployment and adoption of IAM controls for end users where required. •Monitoring & response. Integrate identity telemetry with SIEM/SOC tooling; build monitoring and anomaly detection for NHI/agent behavior; support incident response for compromised or misused credentials. Qualifications: •Demonstrated experience building and/or leading technical teams. •Solid functional working knowledge of identity and authorization for both users and agents: user-to-agent and agent-to-agent (A2A) patterns, OIDC and OAuth 2.0/2.1 tokens, and API keys, across both authentication (AuthN) and authorization (AuthZ). •Strong automation and engineering skills: proficiency in a scripting/programming language (e.g., Python), infrastructure-as-code (e.g., Terraform), CI/CD pipelines, and REST API integration. •Operational familiarity with workload-identity and machine-identity standards: SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation. •Working understanding of AI/agentic systems: LLMs, agent frameworks, tool-calling, and emerging authentication patterns such as the Model Context Protocol (MCP). •Relevant certifications, e.g., CISSP, CyberArk (Defender/Sentry), SailPoint, Ping, or a major cloud security certification. •Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. Compensation: •$122,570 - $204,249 / year •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!