Haystack
← Back to Jobs
Engineering

AI/Agentic Identity Engineer

Techgroup America Inc.United States🇺🇸United StatesPosted 21 Jul 2026

Why This Role Stands Out

This role offers an exciting opportunity to shape the future of AI agent security, a high-impact area with significant growth potential. You'll thrive here if you have extensive experience in enterprise IAM and a passion for designing innovative security control planes for distributed systems, with the flexibility of a hybrid work model. Apply now to be at the forefront of this cutting-edge initiative!

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Agentic Identity Engineer

Remote - with occasional travel to the Miami office 

6 months 

Notes

  • Looking for a senior-level Security Engineer to support a strategic initiative to establish an identity and access management (IAM) program for AI agents
    • They will treat each agent as a governed non-human identity (NHI) with a tracked owner, a pre-approved permission set (persona), and strong workload identity.
    • This includes both consumer-facing and internal agentic services
  • They will design and operationalize runtime guardrails, identity-aware authorization, and policy enforcement across both guest-facing and internal systems.
  • Design and implement security control planes for agentic AI systems
  • Support human-in-the-loop workflows for sensitive or high-risk AI-initiated actions
  • Ensure end-to-end attribution across user → agent → tool execution chains
  • Implement SPIFFE/SPIRE (or equivalent) for cryptographic agent identity.
  •  Implement OAuth 2.0/2.1, OIDC, On-Behalf-Of (RFC 8693) token exchange, and audience-bound tokens (RFC 8707); enforce least privilege and temporal / just-in-time constraints.
  • 8+ years of experience in security engineering, application security, or platform security
  • Proven experience delivering enterprise IAM / non-human identity solutions.
  • Experience designing fine-grained least-privilege access models for distributed systems
  • Experience working with AI-enabled or automation-heavy systems
  • Familiarity with risks unique to agentic or autonomous systems
  • Deep working knowledge of OAuth 2.0/2.1, OIDC, token exchange (OBO), and modern token security (PKCE, audience binding, short-lived tokens).
  • Experience with workload identity: SPIFFE/SPIRE, mTLS, and PKI/certificate-based authentication.
  • Experience with secrets management and eliminating static/long-lived credentials.
  • Solid grasp of Zero Trust, least privilege, and identity lifecycle/recertification.
  • Experience with AI/LLM security risks (e.g., OWASP Top 10 for LLM Applications, agentic threat models).

Similar jobs