Corporate Vice President - Lead AI Engineer, Identity & Access Management
About the role
The Lead AI Engineer, Identity & Access Management is a senior, hands-on technical role that blends deep Identity & Access Management expertise with modern AI engineering capability. This is not a purely advisory or architectural position. We are looking for a builder and a leader: someone who can design, develop, and deliver production-grade agentic systems while also setting the technical direction, mentoring others, and representing the CISO organization at the enterprise level.
Responsibilities
Own the engineering and enterprise adoption of New York Life’s IAM Orchestration and MCP Identity Gateway capability. This includes driving onboarding of internal teams and AI agents, governing authentication, delegation, authorization, and policy enforcement across human and non-human access patterns, and leading integration efforts across the enterprise identity stack.
Serve as the primary AI engineer and technical lead responsible for building and delivering the Cyber Multi-Agent Ecosystem Vision. This is the core of the role: architecting and developing a centralized, governed, agentic platform that transforms Cyber and IAM operations through intelligent automation, orchestrated AI agents, MCP tooling, and a unified identity and data layer, deployed on Google Cloud Platform (Gemini Enterprise Agent Platform, FKA Vertex AI) and/or Amazon AgentCore.
Represent the CISO organization on the Enterprise Security Review Board for all AI-related submissions. The engineer will assess AI system proposals, evaluate agentic and non-human identity risks, and provide authoritative security guidance to ensure all AI deployments meet enterprise governance and compliance requirements.
Requirements
Strong software and systems engineering foundation
Hands-on experience building agentic and AI systems on Gemini Enterprise Agent Platform (FKA Vertex) and/or Amazon AgentCore
Leadership presence to drive cross-functional delivery and represent Cybersecurity at the enterprise level
Qualifications
Bachelor’s degree in Computer Science, Information Systems, Engineering, or equivalent practical experience
10+ years of combined experience in identity & access management, security engineering, and/or AI/software engineering — with a demonstrated track record of both hands-on development and technical leadership
Hands-on experience building and deploying AI agents and agentic pipelines on Google Cloud Platform (GCP), with specific expertise in Gemini Enterprise Agent Platform (FKA Vertex)
Experience securing agentic systems against prompt injection, privilege escalation, execution boundary violations, and unsafe automation, embedding these controls into the development lifecycle
7+ years of IAM domain experience across Identity Governance & Administration (IGA), Privileged Access Management (PAM), Web Access Management (WAM), and/or Directory Services
Proven experience managing non-human identities (service accounts, APIs, workloads, autonomous agents) using least privilege and lifecycle governance principles
Deep understanding of identity and access protocols: OAuth 2.0, OpenID Connect (OIDC), SAML, LDAP, and modern token-based authorization models
Strong software engineering and automation skills (Python, PowerShell, Java or equivalent)
Skills
Agentic AI Engineering
Strong hands-on experience with agent frameworks such as LangGraph, ADK (Agent Development Kit), AutoGen, or equivalent programmatic agent frameworks
Experience designing and building multi-agent systems, including planning, tool execution, and orchestration patterns
Memory & State Management
Strong understanding of conversation/session state management and persistence strategies
Familiarity with state stores such as Redis, Firestore, Postgres, or equivalent
Tooling, MCP & API Engineering
Experience building agent-consumable tools and function interfaces using schema-driven APIs
Understanding of Model Context Protocol (MCP) and tool abstraction patterns
Experience designing and exposing secure, identity-aware APIs using OAuth2, mTLS, service accounts, and secrets management
Cloud & Platforms
Strong hands-on experience with Google Cloud Platform (Gemini Enterprise Agent Platform (FKA Vertex)) preferred
Experience with Amazon AgentCore or AWS Bedrock Agents is a plus
Security, Identity & Threat Domain
Deep IAM expertise across IGA, PAM, WAM, Active Directory, and LDAP
Hands-on experience with SailPoint IIQ, CyberArk, PingIdentity, and directory services
Strong understanding of SIEM platforms and identity-related threat patterns, including privilege escalation, anomalous access, and insider risk
Pay
TBD
Schedule
Hybrid - 3 days per quarter