Comcast logo
ComcastPosted 1 month ago

Security Engineer, Agentic AI & Identity

$104,959–$157,438 year

On-siteMount Laurel, New Jersey, United States

Full TimeEnterprise

Job Summary

Architect, deploy, and maintain Microsoft Entra ID Conditional Access Policies, including risk-based access controls, workload identities, and Zero Trust security controls. Develop and manage secure identity solutions for users, applications, APIs, workloads, and AI agents across hybrid and multi-cloud environments. Design and implement Agent Identity frameworks utilizing Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, and machine-to-machine authentication mechanisms. Partner with security, platform, and application teams to integrate identity controls into Agentic AI solutions leveraging MCP, RAG, and LLMs. Establish and enforce Zero Trust security principles across enterprise applications, APIs, cloud workloads, and AI-driven systems. Evaluate, troubleshoot, and resolve complex authentication, authorization, federation, and application access issues across enterprise environments. Implement IAM automation and operational efficiencies through PowerShell, Python, Microsoft Graph APIs, and Terraform. Collaborate with cloud engineering teams to integrate identity platforms across Azure, AWS, and GCP environments. Create technical documentation, workflows, architecture diagrams, and knowledge articles using Markdown and Mermaid. Monitor emerging technologies within Identity Security and Agentic AI, driving adoption of innovative capabilities. Participate in security reviews, threat modeling exercises, and architecture governance processes to ensure compliance with enterprise security requirements.

Required Qualifications

  • 5+ years of IAM experience
  • strong focus on authentication, federation, application onboarding, access management, and identity security in enterprise environments
  • Hands-on experience designing, implementing, and troubleshooting Microsoft Entra ID Conditional Access Policies
  • including workload identities and risk-based access controls
  • Strong experience onboarding and integrating enterprise applications using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern authentication architectures
  • Solid understanding of Agentic AI technologies including MCP, RAG, A2A communication, LLMs, Agent SDKs, LangChain, LangGraph, Semantic Kernel, and related frameworks
  • Strong knowledge of Agent Identity concepts, including Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, SSI, service principals, and machine-to-machine authentication
  • Experience applying Zero Trust principles across users, applications, APIs, workloads, and AI Agents
  • Good understanding of application architecture, API security, token-based authentication, and secure application design
  • Experience working in multi-cloud environments (Azure, AWS, GCP) and integrating identity services across platforms
  • Ability to troubleshoot complex authentication, authorization, and application access issues in large-scale enterprise environments
  • Bachelor's Degree
  • 5-7 Years

Desired Qualifications

  • Experience with IAM automation using PowerShell, Python, Microsoft Graph APIs, REST APIs, and Infrastructure as Code tools such as Terraform
  • Soft Skills
  • Ability to quickly learn and adapt to emerging technologies, particularly within Identity, Security, and Agentic AI domains
  • Strong communication and presentation skills, with the ability to explain technical concepts to both technical and non-technical audiences
  • Experience creating and maintaining technical documentation, architecture diagrams, and workflows using Markdown, Mermaid, and related tools
  • Strong analytical, problem-solving, and collaboration skills, with the ability to work effectively across security, engineering, and business teams
  • Demonstrated ownership, accountability, and ability to drive technical initiatives from design through production support
  • Adaptability
  • AI Agent Security
  • Critical Thinking
  • Identity Access Management (IAM)
  • Microsoft Entra ID (Azure Active Directory)
  • OpenID Connect
  • Zero Trust Architecture
  • While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience
  • Certifications (if applicable)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce