Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Dallas, TX, United States
Posted
Yesterday
SAFeAWSOAuthOWASPAgileAzureLDAPVaultZero Trust
Job Description
(Hybrid – 3 days a Week Onsite)
Job Summary:
- We are seeking an experienced Cybersecurity Architect to design integrated authorization architecture and governance model for AI applications and agents across SWA within the Identity and Access Management space; evaluate and recommend new and/or existing capabilities and tools that integrate with SWA infrastructure, including emerging technologies; and to serve as Subject Matter Expert to Cybersecurity Teams on identity governance for AI systems, building durable capabilities.
WORK ACTIVITIES/CONTEXT:
- Define the enterprise target-state architecture and governance model for identities, delegated authority, and authorization across AI applications, agents, tools, APIs, and human users.
- Establish reusable authorization patterns for user-to-agent, agent-to-tool, machine-to-machine, and agent-to-agent interactions.
- Design policy enforcement approaches that support least privilege, ZSP, separation of duties, context-aware access, runtime decisioning, and human-in-the-loop guardrails.
- Define lifecycle governance for AI agents and other non-human identities, including registration, sponsorship, ownership, credential issuance, rotation, recertification, suspension, deprovisioning, and evidence retention.
- Develop standards for OAuth 2.0, OIDC, token exchange, workload identity, delegated authorization, service accounts, and short-lived credentials.
- Evaluate vendor and native platform capabilities; document options, tradeoffs, integration impacts, risks, and recommendations for Southwest.
- Partner with IAM, IGA, PAM, Enterprise Access Management, Cloud Security, Application Security, AI Engineering, AI Governance, Enterprise Architecture, and platform teams to align controls and operating
Responsibilities.
- Create reference architectures, design principles, control requirements, decision records, implementation roadmaps, and adoption guidance.
- Support solution reviews and threat-informed design decisions for AI use cases, MCP servers, agent tools, data access paths, and autonomous actions.
- Define logging, traceability, audit evidence, and monitoring requirements that connect an agent action to the agent identity, sponsoring owner, delegated user or system, authorization decision, and affected resource.
- Provide technical leadership and consultation to Cyber teams; translate complex IAM and AI security concepts into clear decisions for engineers, product teams, leaders, and governance forums.
- Track relevant market and technology developments and recommend updates to architecture standards and strategic roadmaps
- Must be able to meet any physical ability requirements listed on this description.
- May perform other job duties as directed by Employee’s Leaders.
WORK EXPERIENCE:
- Must have a minimum 3 years’ experience solving complex problems and driving multiple stakeholders towards implementable solutions; prefer 5 years of experience
- Minimum 3 years’ experience developing communication strategies for buy-in and acceptance preferred; prefer 5 years of experience
- Minimum 3 years working in a cross-functional environment within technology domain; prefer 5 years of experience
- 2 years or more of experience in Cybersecurity Identity and Access Management domain preferred
- Experience and solid knowledge of strategic and financial analysis and issues/risk management and project change requests.
- Ability to influence diverse customer groups to align on strategic goals and decisions
- Prefer at least 1 year working in a Scaled Agile Framework (SAFe) environment.
- Consulting experience (highly desired)
SKILLS/ABILITIES/KNOWLEDGE/WORK STYLE:
- Built and maintained communication strategy for diverse user group (highly desired)
- Must have the ability to assume a high-level responsibility and to provide direction in a cross-functional, team-oriented environment
- Ability to quickly ramp up when placed in new areas business (proactively engage all levels the organization to expand functional understanding.
- Proficiency in Agile methodologies, collaborating effectively with cross-functional teams.
- Deep expertise in enterprise Identity and Access Management (IAM) architecture and integration patterns for AI systems and agent-based environments
- Understanding of best practices for authorization enforcement across AI agents, tools, APIs, and human identities
- Knowledge of core authorization principles such as least privilege access, Zero Standing Privilege (ZSP), policy enforcement, auditability, and runtime governance
- Technology expertise: AWS AgentCore, SailPoint Identity Security Cloud, Ping Identity Platform, CyberArk
- Experience designing OAuth 2.0 / OIDC flows for machine-to-machine and agent-to-agent communication
- Understanding of AI agent lifecycle governance — registration, credential rotation, deprovisioning, and auditability of autonomous actions
- Technology expertise: Ping Agent IAM Core module, SailPoint Entro Security, CyberArk Idira, CrowdStrike, Microsoft Foundry, Microsoft EntraID
- Experience with secrets management and credential vaulting (e.g., CyberArk, HashiCorp Vault, AWS Secrets Manager)
- Familiarity with AI safety/governance frameworks (NIST AI RMF, OWASP Top 10 for LLMs) and regulatory/compliance considerations for autonomous systems
- Strong communication and cross-team collaboration skills; ability to translate complex IAM concepts for engineering and leadership audiences
Strong hands-on knowledge of:
- Privileged Access Management (PAM)
- Directory services (AD, eDirectory, LDAP)
- Workforce/Enterprise IAM
- CIAM platforms and patterns
- Experience with IAM tools such as CyberArk, BeyondTrust, Ping, Azure AD, SailPoint, or similar
- Experience in cloud-based IAM (AWS, Azure, hybrid environments)
- Ensure IAM solutions align with Zero Trust, least privilege, and identity-first security principles.
- Exceptional attention to detail, with strong documentation skills.
- Self-motivated, proactive, and committed to driving tasks to completion.
- Ability to connect how and programs integrate with company objectives.
- Experience solving complex problems (Business and Technical) and identifying options for solutions.
- Experience supporting (or leading) Executive-level communication (e.g. project status updates, presentations requesting approval,
- Multiyear Roadmaps, Financial health etc.)
- Ability to digest significant amount of detail and summarize relevant information for the appropriate stakeholder (e.g., Managers, Directors, VPs, etc.)
- Experience with or thorough understanding the process for gathering business requirements for an implementation project.
- Understands how to translate business needs into releases that strategically deliver business value.
- Ability to translate business process into strategy and drive innovation that builds capabilities.
- Understands how to read market landscape and implement best practices to remain competitive.
- Ability to lead discussions with stakeholders from multiple backgrounds who have conflicting priorities; act as mediator if Teams are not aligned and drive towards a recommendation or solution.
- Ability to use critical thinking to identify, analyze and interpret trends and patterns in complex data sets to solve problems, and develop recommendations based on findings.
- Strong oral communication and presentation delivery skills when facilitating discussions at the Executive level.
- Skilled influencer, negotiator, consensus-builder, and change agent.
- Display ability to recognize inefficiencies with processes/procedures and proactively offer suggestions for improvements – ability to take items a step further, not just follow defined path (continue process because it is the same as it is today).
- Must be able to work remain flexible and work in the grey as priorities may shift to meet enterprise objectives.
- Must be able to comply with Company attendance standards as described in established guidelines.
Similar jobs
- BA
Senior DevOps Engineer
Booz Allen Hamilton
Washington, DC🇺🇸$99k - $225k/yrOn-site4 days agoDockerShellAWS+4Technology - PA
Software Engineer Co-Op - TS/SCI with Security Clearance
NewParsons
Centreville, VA🇺🇸$23 - $40/hrHybridYesterdayDockerMicroservicesMongoDB+19Technology - LT
Integration/Test Engineering with Security Clearance
NewL3Harris Technologies
Clifton, NJ🇺🇸$76.5k - $141.5k/yrHybridYesterdayTechnology - LE
Senior Cyber Specialist - ISSO with Security Clearance
NewLeidos
Odenton, MD🇺🇸$131.3k - $237.3k/yrHybridYesterdayTechnology - HM
Network Engineer (SkillBridge Intern) - 30611 with Security Clearance
NewHII Mission Technologies
San Antonio, TX🇺🇸HybridYesterdayGCPAWSAnsible+3Technology - AS
Integration and Test Engineer with Security Clearance
NewAstrion
Albuquerque, NM🇺🇸On-siteYesterdayTechnology - RT
Naval Radar - Systems Engineer II with Security Clearance
NewRTX
Woburn, MA🇺🇸HybridYesterdayMATLABC++PythonTechnology - LM
Systems Engineering Field Tech Support Sr - (EXPAT - Guam) with Security Clearance
NewLockheed Martin
Moorestown, NJ🇺🇸HybridYesterdayTechnology - RT
Senior Principal RF Systems Engineer (Onsite) with Security Clearance
NewRTX
Alexandria, VA🇺🇸HybridYesterdayMATLABPythonTechnology - PE
Cybersecurity / Compliance Engineer with Security Clearance
NewPeraton
Chantilly, VA🇺🇸$112k - $179k/yrOn-siteYesterdayAWSEncryptionKubernetes+1Technology - LM
Systems Engineer Sr - E3 (Level 3 Junior Release Train Engineer) with Security Clearance
NewLockheed Martin
Fort Worth, TX🇺🇸HybridYesterdayTableauAgileJiraTechnology - GO
SIEM Content Developer with Security Clearance
NewGoldbelt Inc
Columbus, OH🇺🇸$99k - $175k/yrHybridYesterdayPowerShellPythonTechnology