Senior AI Identity Platform Engineer
About the role
LTS is seeking a Senior AI Identity Platform Engineer to design and build the identity foundation that enables AI agents, enterprise applications, cloud services, and users to interact securely and intelligently. The position involves designing and implementing identity services, authentication, authorization, credential management, and identity services for autonomous AI systems.
Responsibilities
Design AI Identity Architecture
Establish secure identities for AI agents, enterprise services, users, and external integrations.
Define identity lifecycles for AI agents, including provisioning, credential management, rotation, and decommissioning.
Build reusable identity capabilities that scale across the AI platform.
Design and implement modern authentication and authorization frameworks for AI agents and platform services.
Implement OAuth 2.0, OpenID Connect (OIDC), JWT, service principals, mutual TLS (mTLS), and delegated authorization models.
Apply least-privilege and Zero Trust principles throughout AI workflows.
Build fine-grained authorization models controlling AI access to enterprise data, APIs, tools, and services.
Integrate AI platforms with enterprise identity providers such as Microsoft Entra ID, Okta, Active Directory, and other IAM solutions.
Enable secure identity federation across cloud and on-premises environments.
Design secure service-to-service authentication supporting distributed AI architectures.
Collaborate with enterprise security teams to align AI identity with organizational security standards.
Design secure frameworks governing how AI agents discover, authenticate to, and invoke enterprise APIs, databases, and external tools.
Build authorization models controlling agent capabilities and delegated permissions.
Protect sensitive enterprise resources through policy-driven access controls.
Implement secure credential handling and secrets management across AI workflows.
Develop reusable identity services, SDKs, APIs, and libraries supporting secure AI application development.
Automate identity provisioning, credential lifecycle management, and authorization policies.
Improve developer productivity through standardized identity services and secure engineering patterns.
Partner with platform engineers to integrate identity services into the AI platform architecture.
Ensure every AI action is authenticated, authorized, attributable, and auditable.
Implement identity-aware logging, traceability, and policy enforcement.
Support compliance and governance requirements for highly regulated environments.
Partner closely with AI Security Engineers to establish secure-by-design AI development practices.
Requirements
Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, or a related technical discipline (or equivalent professional experience).
7+ years of software engineering, platform engineering, identity engineering, or cloud security experience.
Experience designing authentication and authorization architectures for enterprise applications.
Strong knowledge of OAuth 2.0, OpenID Connect (OIDC), JWT, SAML, PKI, and modern identity protocols.
Experience integrating enterprise identity providers such as Microsoft Entra ID, Okta, Active Directory, or similar IAM platforms.
Experience building secure REST APIs, microservices, and distributed systems.
Knowledge of Zero Trust Architecture, RBAC, ABAC, delegated authorization, and identity federation.
Experience with cloud platforms (Azure, AWS, or Google Cloud).
Strong programming skills in Python plus experience with Go, Java, or TypeScript.
Excellent communication, analytical, and problem-solving skills.
Experience designing secure systems that enable innovation rather than restrict it.
Expertise in identity and access management.
Hands-on experience with cloud-native architecture and modern authentication frameworks.
Strong ability to stay current with emerging AI technologies and evolving identity standards.
Ability to collaborate effectively across software engineering, security, and AI disciplines.
Willing and able to take ownership of difficult technical challenges and build elegant, innovative solutions.
Qualifications
Nice to have:
Experience developing AI platforms, Agentic AI systems, or Large Language Model (LLM) applications.
Experience securing Retrieval-Augmented Generation (RAG) systems and AI tool integrations.
Familiarity with Model Context Protocol (MCP) and secure AI tool invocation.
Experience with HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, or similar secrets management platforms.
Experience implementing identity services in Kubernetes and cloud-native environments.
Experience with AI governance, Responsible AI, or AI platform security.
Familiarity with LangGraph, LangChain, CrewAI, Semantic Kernel, AutoGen, or similar AI orchestration frameworks.
Experience supporting Federal Government or healthcare environments.
Identity or cloud certifications such as Microsoft Identity and Access Administrator, CISSP, Security+, CCSP, or cloud security certifications are a plus.
Benefits
The opportunity to support high-visibility federal missions, a culture that values innovation, growth, and collaboration, access to cutting-edge tools and technologies, comprehensive benefits for you and your family, and a career path that rewards ambition and performance.