Role overview
Act as the subject matter expert for enterprise identity and access management, driving secure authentication, authorization, and identity governance across applications, APIs, and AI/agent-based systems.
Key responsibilities
- Design and implement IAM solutions across Okta, Ping Identity, and enterprise identity platforms
- Define and enforce authentication and authorization using SAML, OAuth2, and OpenID Connect
- Lead SSO, federation, and identity provider integrations across cloud and SaaS applications
- Establish RBAC, least-privilege access, and identity governance frameworks
- Drive identity lifecycle management including provisioning, de-provisioning, and access certifications
- Implement and optimize MFA, conditional access, and Zero Trust identity controls
- Collaborate with cloud, security, and application teams to onboard and integrate applications into IAM platforms
- Architect identity and access controls for AI/agentic systems including user, service, and agent identities
- Define identity models for agentic workflows covering permissions, ownership, delegation, and lifecycle
- Enable secure agent-to-system interactions via APIs, tokens, and service identities
- Ensure governance, audit readiness, and compliance alignment (SOX, ISO, etc.)
- Monitor, troubleshoot, and enhance identity security posture across environments
Required experienc
- e7+ years in IAM / Identity Security / Access Management role
- sStrong hands-on experience with Okta and Ping Identity (PingFederate, PingAccess, etc.
- )Deep expertise in SAML 2.0, OAuth 2.0, OpenID Connect, and identity federatio
- nExperience designing SSO integrations and identity provider architecture
- sStrong understanding of RBAC, ABAC, identity governance, and access lifecycle managemen
- tExposure to AI/ML or agent-based systems and identity considerations for non-human identitie
- sExperience securing APIs, microservices, and cloud-native application
s
Good to ha
- veExperience with Agentic AI platforms or multi-agent syste
- msExposure to Zero Trust architecture and modern security framewor
- ksExperience with IAM tools such as SailPoint, CyberArk, or Azure
- ADScripting or automation experience (Python, PowerShel
- l)IAM certifications (Okta, Ping, SailPoint, CISSP, etc
.)