Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
LPL Financial

AVP, IAM AI Engineer

LPL Financial

AVP, IAM AI Engineer building secure identity, secrets, and governance controls for AI agents at LPL Financial, a U.S. wealth management firm.

Posted 8/11/2026full-timeFort Mill • California, New York, Texas • 🇺🇸 United StatesLead💰 $122,570 - $204,249 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in identity and access management, focusing on the automation and governance of identity controls for AI agents and non-human identities. Proficient in implementing fine-grained authorization models and integrating IAM solutions across various cloud platforms.

Highest-signal resume keywords
Identity And Access ManagementPing Identity (PingFederate, PingOne, PingAccess)SailPoint (IdentityIQ, Identity Security Cloud)Secrets Management (CyberArk, HashiCorp Vault)Scripting/Programming (Python)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Identity And Access ManagementAuthenticationAuthorizationPolicy EnforcementSecrets ManagementInfrastructure-As-Code (Terraform)CI/CD PipelinesREST API IntegrationCloud IAM (AWS, Azure, GCP)Containerization (Kubernetes)
Soft Skills
Team LeadershipMentoringCollaboration
Tools & Technologies
Ping IdentitySailPointCyberArkHashiCorp VaultSIEM/SOC Tools
Certifications & Qualifications
CISSPCyberArk Defender/SentrySailPoint CertificationPing CertificationCloud Security Certification
Industry Keywords
Regulated IndustryCompliance RegimesAI Application DevelopmentGovernance ControlsIdentity Telemetry

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformKubernetesPythonTerraformVault

About the role

Key responsibilities & impact
  • Design, operationalize, and automate identity controls governing human and non-human actors, with a focus on AI agents and non-human identities.
  • Build runtime controls, secrets workflows, and governance guardrails for safe AI adoption.
  • Embed identity, authentication, and authorization into new AI application development from the earliest design stages.
  • Operationalize and automate real-time authentication, authorization, and policy enforcement.
  • Design and automate governance controls across the lifecycle of AI agents and non-human identities, including provisioning, entitlement, rotation, certification/attestation, and deprovisioning.
  • Develop and automate secrets-manager workflows, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery.
  • Define and enforce fine-grained least-privilege authorization models using policy-as-code.
  • Establish identity-flow standards and reference patterns for user-to-agent, agent-to-agent, and workload-to-service authentication and authorization.
  • Partner with engineering and data science teams on AI application development.
  • Support deployment and adoption of IAM controls for end users.
  • Integrate identity telemetry with SIEM/SOC tooling and build monitoring and anomaly detection for NHI and agent behavior.
  • Support incident response for compromised or misused credentials.
  • Partner with GRC, risk, and audit stakeholders to satisfy regulatory and internal requirements and produce audit evidence.
  • Recruit, build, mentor, and lead a team; set technical direction and roadmap for NHI and agentic IAM.

Requirements

What you’ll need
  • 5+ years in identity and access management or information security, including hands-on engineering
  • Demonstrated experience building and/or leading technical teams
  • 5+ years with Ping Identity (PingFederate, PingOne, or PingAccess) or a comparable access-management/federation platform
  • 5+ years with SailPoint (IdentityIQ or Identity Security Cloud) or a comparable IGA platform
  • 3+ years with Idira (CyberArk, formerly Conjur), HashiCorp Vault, or a comparable secrets-management platform
  • Working knowledge of identity and authorization for users and agents, including user-to-agent and agent-to-agent patterns
  • Knowledge of OIDC and OAuth 2.0/2.1 tokens and API keys across authentication and authorization
  • Proficiency in a scripting/programming language such as Python
  • Experience with infrastructure-as-code such as Terraform
  • Experience with CI/CD pipelines and REST API integration
  • Experience applying IAM in AWS, Azure, and/or GCP
  • Experience with containerized and Kubernetes workloads
  • Familiarity with SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation
  • Working understanding of LLMs, agent frameworks, tool-calling, and authentication patterns such as MCP
  • Experience in a regulated industry and associated compliance regimes
  • Relevant certifications such as CISSP, CyberArk Defender/Sentry, SailPoint, Ping, or a major cloud security certification
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience

Benefits

Comp & perks
  • 401K matching
  • Health benefits
  • Employee stock options
  • Paid time off
  • Volunteer time off
  • Competitive LPL Total Rewards package
  • Collaborative environment
  • Freedom to make an impact
  • Benefits designed to support success at work, at home, and at play