Haystack
← Back to Jobs
Technology
CR

Security Engineer / Architect Identity, Authorization & Platform Security

Cyber Resource Provider LLCDenver, CO🇺🇸United StatesPosted Sep 23, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Denver, CO, United States
Posted
Yesterday
SAMLSSOIoTJWTLLMPKIZero Trust

Job Description

Security Engineer / Architect Identity, Authorization & Platform Security

Location: Denver, CO 100% Onsite
Job Type: Contract
Duration: Contract / Long-Term Engagement

Position Overview

We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform.

The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security.

This is a builder's role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions.

Key Responsibilities

Identity & Access Management / RBAC

  • Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.
  • Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning.
  • Build automated user/group/role provisioning and lifecycle management.
  • Implement access recertification and governance processes.
  • Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
  • Establish SSO and API authentication across services.
  • Implement consistent organization and tenant isolation across identity and downstream platforms.

Authorization & Policy Engineering

  • Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
  • Implement an externalized policy-decision engine and manage policies as code.
  • Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
  • Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction.
  • Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.

AI Agent & Tool Security

  • Design authorization models for AI agents and automated tool invocation.
  • Establish agent workload identities and delegated authorization.
  • Implement per-agent cryptographic identities and on-behalf-of authorization.
  • Define tool-level permissions based on users, agents, tenants, resources, and actions.
  • Implement human-in-the-loop approval workflows for sensitive operations.
  • Maintain complete, tamper-evident audit trails for agent and tool activity.
  • Apply security controls against prompt injection and unauthorized tool execution.

Secrets & Cloud Security

  • Implement centralized secrets management and automated credential rotation.
  • Design secure cloud IAM architectures and least-privilege access.
  • Implement secure credential management for applications, workloads, agents, and infrastructure.
  • Support secure execution environments and sandboxing for sensitive tool calls.

Vulnerability Management

  • Implement continuous vulnerability scanning across:
    • Edge compute nodes
    • Containers and container images
    • Operating systems
    • Application dependencies
    • Container-orchestration platforms
    • Third-party libraries
    • Device firmware where applicable
  • Implement SBOM generation, tracking, and vulnerability correlation.
  • Correlate CVEs with asset exposure and exploitability.
  • Develop risk-based vulnerability prioritization and remediation workflows.
  • Build operational and executive vulnerability dashboards.
  • Integrate vulnerability findings with event platforms and ticketing workflows.

Security Telemetry & SIEM

  • Deploy security telemetry capabilities across edge environments.
  • Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
  • Normalize security events into a common schema.
  • Integrate security telemetry with centralized SIEM platforms.
  • Implement store-and-forward capabilities for intermittently connected edge environments.
  • Design bandwidth-aware event batching and reliable event delivery.
  • Implement tamper-evident and mutually authenticated telemetry pipelines.
  • Maintain tenant isolation throughout the telemetry pipeline.
  • Develop SIEM detection and correlation rules that associate security events with verified identities.
  • Route actionable security alerts into event buses and on-call workflows.

Platform Security Integration

  • Establish security standards for event-platform authentication and authorization.
  • Implement message signing and secure service-to-service communication.
  • Support edge-device identity, mTLS, PKI, and certificate lifecycle management.
  • Integrate security controls into CI/CD pipelines.
  • Implement security gates including artifact signing, IaC scanning, and automated security validation.
  • Partner with engineering teams to establish reusable security primitives and standards.

Required Qualifications

  • 8+ years of experience in security engineering.
  • 3+ years of experience architecting and implementing Identity & Access Management at scale.
  • Strong hands-on experience with enterprise Identity Providers and identity federation.
  • Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning.
  • Experience mapping federated identities to downstream authorization models.
  • Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
  • Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
  • Experience with externalized authorization/policy engines.
  • Strong cloud IAM experience.
  • Hands-on experience with centralized secrets management and automated credential rotation.
  • Experience with containers and container orchestration.
  • Ability to develop production-quality code and implement security solutions hands-on.
  • Demonstrated experience implementing least-privilege and Just-in-Time access.
  • Experience building fully auditable access-control systems.

Preferred Qualifications

  • Experience securing AI agents, LLM applications, and automated tool-invocation interfaces.
  • Knowledge of prompt-injection and AI tool-boundary security.
  • Experience with workload identity and machine-to-machine authentication.
  • Experience building security telemetry pipelines and SIEM integrations.
  • Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
  • Experience securing edge, IoT, or intermittently connected environments.
  • Experience with lightweight host-based security telemetry agents.
  • Knowledge of Zero Trust architecture.
  • Experience with PKI, mTLS, certificate lifecycle management, and device attestation.
  • Experience with event-driven security architectures.
  • Experience implementing secure CI/CD and automated security gates.
  • Security architecture certifications are a plus but not required.

Similar jobs