LPL Financial logo
LPL FinancialPosted 2 weeks ago

AVP, IAM AI Engineer

$122,570–$204,249 year

On-siteAustin, Texas, United States or San Diego, California, United States

Full TimeLarge

Job Summary

Operationalize and automate identity runtime controls across human and non-human identities, including real-time authentication, authorization, and policy enforcement. Design governance controls for AI agents and non-human identities covering the full lifecycle, while developing secrets-manager workflows for AI systems. Define fine-grained, least-privilege authorization models expressed as policy-as-code and establish reference patterns for identity flows through agentic systems. Partner with engineering teams on new AI application development to ensure identity and secrets handling are designed in from the start. Integrate identity telemetry with SIEM/SOC tooling to build monitoring and anomaly detection for agent behavior. Recruit, mentor, and lead a team to support these workstreams while partnering with GRC stakeholders to ensure regulatory compliance.

Required Qualifications

  • 5+ years in identity & access management or information security, including hands-on engineering
  • Demonstrated experience building and/or leading technical teams
  • 5+ years with Ping Identity (PingFederate / PingOne / PingAccess) or a comparable access-management / federation platform
  • 5+ years with SailPoint (IdentityIQ / Identity Security Cloud) or a comparable identity governance & administration (IGA) platform
  • 3+ years with Idira (CyberArk, formerly Conjur) / HashiCorp Vault or a comparable secrets-management platform
  • Working knowledge of identity and authorization for both users and agents: user-to-agent and agent-to-agent (A2A) patterns, OIDC and OAuth 2.0/2.1 tokens, and API keys, across both authentication (AuthN) and authorization (AuthZ)
  • Strong automation and engineering skills: proficiency in a scripting/programming language (e.g., Python), infrastructure-as-code (e.g., Terraform), CI/CD pipelines, and REST API integration
  • Experience applying IAM in cloud environments (AWS, Azure, and/or GCP) and in containerized / Kubernetes workloads
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience

Desired Qualifications

  • Familiarity with workload-identity and machine-identity standards: SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation
  • Working understanding of AI/agentic systems: LLMs, agent frameworks, tool-calling, and emerging authentication patterns such as the Model Context Protocol (MCP)
  • Experience in a regulated industry (financial services, healthcare, etc.) and with associated compliance regimes
  • Relevant certifications, e.g., CISSP, CyberArk (Defender/Sentry), SailPoint, Ping, or a major cloud security certification

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce