FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

AVP, IAM AI Engineer
LPL FinancialAVP, IAM AI Engineer building secure identity, secrets, and governance controls for AI agents at LPL Financial, a U.S. wealth management firm.
Posted 8/11/2026full-timeFort Mill • California, New York, Texas • 🇺🇸 United StatesLead💰 $122,570 - $204,249 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in identity and access management, focusing on the automation and governance of identity controls for AI agents and non-human identities. Proficient in implementing fine-grained authorization models and integrating IAM solutions across various cloud platforms.
Highest-signal resume keywords
Identity And Access ManagementPing Identity (PingFederate, PingOne, PingAccess)SailPoint (IdentityIQ, Identity Security Cloud)Secrets Management (CyberArk, HashiCorp Vault)Scripting/Programming (Python)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Identity And Access ManagementAuthenticationAuthorizationPolicy EnforcementSecrets ManagementInfrastructure-As-Code (Terraform)CI/CD PipelinesREST API IntegrationCloud IAM (AWS, Azure, GCP)Containerization (Kubernetes)
Soft Skills
Team LeadershipMentoringCollaboration
Tools & Technologies
Ping IdentitySailPointCyberArkHashiCorp VaultSIEM/SOC Tools
Certifications & Qualifications
CISSPCyberArk Defender/SentrySailPoint CertificationPing CertificationCloud Security Certification
Industry Keywords
Regulated IndustryCompliance RegimesAI Application DevelopmentGovernance ControlsIdentity Telemetry
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformKubernetesPythonTerraformVault
About the role
Key responsibilities & impact- Design, operationalize, and automate identity controls governing human and non-human actors, with a focus on AI agents and non-human identities.
- Build runtime controls, secrets workflows, and governance guardrails for safe AI adoption.
- Embed identity, authentication, and authorization into new AI application development from the earliest design stages.
- Operationalize and automate real-time authentication, authorization, and policy enforcement.
- Design and automate governance controls across the lifecycle of AI agents and non-human identities, including provisioning, entitlement, rotation, certification/attestation, and deprovisioning.
- Develop and automate secrets-manager workflows, including secret rotation, just-in-time and ephemeral credentials, and secure secret delivery.
- Define and enforce fine-grained least-privilege authorization models using policy-as-code.
- Establish identity-flow standards and reference patterns for user-to-agent, agent-to-agent, and workload-to-service authentication and authorization.
- Partner with engineering and data science teams on AI application development.
- Support deployment and adoption of IAM controls for end users.
- Integrate identity telemetry with SIEM/SOC tooling and build monitoring and anomaly detection for NHI and agent behavior.
- Support incident response for compromised or misused credentials.
- Partner with GRC, risk, and audit stakeholders to satisfy regulatory and internal requirements and produce audit evidence.
- Recruit, build, mentor, and lead a team; set technical direction and roadmap for NHI and agentic IAM.
Requirements
What you’ll need- 5+ years in identity and access management or information security, including hands-on engineering
- Demonstrated experience building and/or leading technical teams
- 5+ years with Ping Identity (PingFederate, PingOne, or PingAccess) or a comparable access-management/federation platform
- 5+ years with SailPoint (IdentityIQ or Identity Security Cloud) or a comparable IGA platform
- 3+ years with Idira (CyberArk, formerly Conjur), HashiCorp Vault, or a comparable secrets-management platform
- Working knowledge of identity and authorization for users and agents, including user-to-agent and agent-to-agent patterns
- Knowledge of OIDC and OAuth 2.0/2.1 tokens and API keys across authentication and authorization
- Proficiency in a scripting/programming language such as Python
- Experience with infrastructure-as-code such as Terraform
- Experience with CI/CD pipelines and REST API integration
- Experience applying IAM in AWS, Azure, and/or GCP
- Experience with containerized and Kubernetes workloads
- Familiarity with SPIFFE/SPIRE, OAuth token exchange (RFC 8693), mTLS, and cloud workload-identity federation
- Working understanding of LLMs, agent frameworks, tool-calling, and authentication patterns such as MCP
- Experience in a regulated industry and associated compliance regimes
- Relevant certifications such as CISSP, CyberArk Defender/Sentry, SailPoint, Ping, or a major cloud security certification
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience
Benefits
Comp & perks- 401K matching
- Health benefits
- Employee stock options
- Paid time off
- Volunteer time off
- Competitive LPL Total Rewards package
- Collaborative environment
- Freedom to make an impact
- Benefits designed to support success at work, at home, and at play