Senior Security Engineer, Identity & Machine Access
On-siteBengaluru, Karnataka, India or Chennai, Tamil Nadu, India
Job Summary
Own the non-human identity program by inventorying, governing, and securing service accounts, workload identities, API keys, tokens, and certificates for AI agents and MCP servers. Drive machine access toward least-privilege, short-lived, and fully auditable credentials while defining authorization models for agent tool access. Manage Privileged Access Management across engineering environments through vaulting, just-in-time access, and session control, alongside centralizing secret rotation and embedding hygiene into CI/CD pipelines. Architect least-privilege IAM across the multi-cloud estate including AWS and Rackspace, partnering with DevOps to automate identity controls in Infrastructure as Code. Support IT on corporate endpoint and email security baselines while creating documentation for all identity and privileged-access processes.
Required Qualifications
- 5 to 7 years of hands-on Identity and Access Management engineering experience
- Expert-level proficiency securing machine and non-human identity: service accounts, workload identity (e.g., AWS IAM roles, OIDC federation, or equivalent), API keys and tokens, and certificate and secrets management (e.g., HashiCorp Vault, cloud secret managers)
- Deep understanding of service-to-service authentication and authorization such as OAuth 2.0, OIDC, JWT, mTLS, and workload authentication patterns
- Hands-on experience deploying and operating a Privileged Access Management (PAM) solution in engineering environments, with just-in-time and least-privilege models
- Strong grasp of authorization models (RBAC, ABAC, least privilege) and identity governance
Desired Qualifications
- Deep, mandatory experience securing resources with AWS IAM and multi-cloud identity is a strong plus
- Experience securing identity for AI, ML, LLM, or agentic systems, including non-human identity, agent credentials, and MCP or tool-access authorization at scale
- Scripting for automation (Python, PowerShell) and Infrastructure as Code (Terraform) for identity resources
- Hands-on with workload-identity and secrets tooling such as HashiCorp Vault, cloud secret managers, certificate lifecycle, and SPIFFE/SPIRE or equivalent workload identity
- Experience with secrets and certificate lifecycle automation
- Relevant certifications (e.g., CISSP) and a degree in Computer Science, Information Security, or a related field
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.