Job Description
- Central identity federated to the priority downstream systems through a canonical role model, with automated provisioning and end-to-end audit in place.
\n
- Baseline continuous vulnerability scanning live across edge nodes and containers, with risk-scored findings flowing to the event bus.
\n
- The edge security-telemetry pipeline designed and piloted on a representative node set — local visibility layer collecting and forwarding to the SIEM, with store-and-forward proven.
\n
\n
By the second half of the engagement
\n
- Just-in-time elevation, the central policy engine, and access recertification running in production; standing administrative access eliminated.
\n
- Agent workload identity, tool-invocation authorization, delegation, and human-approval workflows operational for sensitive actions.
\n
- Vulnerability coverage extended across the full fleet, and identity-correlated SIEM detections live — every alert resolving to a verifiable principal.
\n
- Documentation, runbooks, and standards handed over so the platform remains fully operable beyond the engagement.
\n
\n
Required qualifications
\n
\n
- [8+] years in security engineering, including [3+] years architecting identity and access management at scale.
\n
- Deep, hands-on identity federation: enterprise identity providers, OIDC, SAML, standards-based provisioning, and mapping federated identity into downstream systems' native authorization models.
\n
- Strong command of OAuth2/OIDC internals — scopes, audiences, token exchange, audience restriction — and common failure modes such as confused-deputy and token passthrough.
\n
- Demonstrated implementation of an authorization policy model (RBAC plus at least one of ABAC / ReBAC) using an externalized policy engine.
\n
- Cloud IAM depth and centralized secrets management, including automated rotation.
\n
- Container-orchestration and container security fundamentals; able to deliver production-quality code — this role builds, not only advises.
\n
- A track record of shipping least-privilege, just-in-time, and fully auditable access systems.
\n
\n
Preferred qualifications
\n
\n
- Securing AI agents / LLM-based systems and automated tool-invocation interfaces; prompt-injection and tool-boundary threat modeling.
\n
- Workload identity frameworks and machine-to-machine credentialing.
\n
- Security telemetry pipelines and SIEM integration at scale — collection, normalization, retention, and detection/correlation engineering.
\n
- Vulnerability-management program delivery — continuous scanning, SBOM tooling, CVE correlation, and risk-based prioritization.
\n
- Security observability on edge, IoT, or intermittently connected devices — lightweight host-based telemetry agents, store-and-forward under constrained bandwidth, and tamper-evident delivery.
\n
- Zero-trust infrastructure access architectures; PKI, certificate lifecycle, mutual TLS, and device attestation.
\n
- Event-driven platform security and secure CI/CD (artifact signing, infrastructure-as-code scanning, automated security gates).
\n
- Relevant security-architecture certifications (advantageous, not required).
\n
