Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Identity Security Architect

Openkyber

Security Engineer / Architect Identity, Authorization & Platform Security Location: Denver, CO 100% Onsite



Job Type: Contract



Duration: Contract / Long-Term Engagement



Position Overview

We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform. The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security . This is a builder's role , requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions.

Key Responsibilities



Identity & Access Management / RBAC
  • Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.
  • Implement identity federation using OIDC, SAML, OAuth2 , and standards-based provisioning.
  • Build automated user/group/role provisioning and lifecycle management.
  • Implement access recertification and governance processes.
  • Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
  • Establish SSO and API authentication across services.
  • Implement consistent organization and tenant isolation across identity and downstream platforms.
Authorization & Policy Engineering
  • Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
  • Implement an externalized policy-decision engine and manage policies as code.
  • Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
  • Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction .
  • Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.
AI Agent & Tool Security
  • Design authorization models for AI agents and automated tool invocation .
  • Establish agent workload identities and delegated authorization.
  • Implement per-agent cryptographic identities and on-behalf-of authorization.
  • Define tool-level permissions based on users, agents, tenants, resources, and actions.
  • Implement human-in-the-loop approval workflows for sensitive operations.
  • Maintain complete, tamper-evident audit trails for agent and tool activity.
  • Apply security controls against prompt injection and unauthorized tool execution.
Secrets & Cloud Security
  • Implement centralized secrets management and automated credential rotation.
  • Design secure cloud IAM architectures and least-privilege access.
  • Implement secure credential management for applications, workloads, agents, and infrastructure.
  • Support secure execution environments and sandboxing for sensitive tool calls.
Vulnerability Management
  • Implement continuous vulnerability scanning across: Edge compute nodes, Containers and container images, Operating systems, Application dependencies, Container-orchestration platforms, Third-party libraries, Device firmware where applicable
  • Implement SBOM generation, tracking, and vulnerability correlation .
  • Correlate CVEs with asset exposure and exploitability.
  • Develop risk-based vulnerability prioritization and remediation workflows.
  • Build operational and executive vulnerability dashboards.
  • Integrate vulnerability findings with event platforms and ticketing workflows.
Security Telemetry & SIEM
  • Deploy security telemetry capabilities across edge environments.
  • Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
  • Normalize security events into a common schema.
  • Integrate security telemetry with centralized SIEM platforms.
  • Implement store-and-forward capabilities for intermittently connected edge environments.
  • Design bandwidth-aware event batching and reliable event delivery.
  • Implement tamper-evident and mutually authenticated telemetry pipelines.
  • Maintain tenant isolation throughout the telemetry pipeline.
  • Develop SIEM detection and correlation rules that associate security events with verified identities.
  • Route actionable security alerts into event buses and on-call workflows.
Platform Security Integration
  • Establish security standards for event-platform authentication and authorization.
  • Implement message signing and secure service-to-service communication.
  • Support edge-device identity, mTLS, PKI, and certificate lifecycle management .
  • Integrate security controls into CI/CD pipelines.
  • Implement security gates including artifact signing, IaC scanning, and automated security validation.
  • Partner with engineering teams to establish reusable security primitives and standards.
Required Qualifications
  • 8+ years of experience in security engineering.
  • 3+ years of experience architecting and implementing Identity & Access Management at scale.
  • Strong hands-on experience with enterprise Identity Providers and identity federation.
  • Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning .
  • Experience mapping federated identities to downstream authorization models.
  • Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
  • Hands-on experience implementing RBAC and at least one of ABAC or ReBAC .
  • Experience with externalized authorization/policy engines.
  • Strong cloud IAM experience.
  • Hands-on experience with centralized secrets management and automated credential rotation.
  • Experience with containers and container orchestration.
  • Ability to develop production-quality code and implement security solutions hands-on.
  • Demonstrated experience implementing least-privilege and Just-in-Time access .
  • Experience building fully auditable access-control systems.
Preferred Qualifications
  • Experience securing AI agents, LLM applications, and automated tool-invocation interfaces .
  • Knowledge of prompt-injection and AI tool-boundary security.
  • Experience with workload identity and machine-to-machine authentication.
  • Experience building security telemetry pipelines and SIEM integrations.
  • Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
  • Experience securing edge, IoT, or intermittently connected environments .
  • Experience with lightweight host-based security telemetry agents.
  • Knowledge of Zero Trust architecture .
  • Experience with PKI, mTLS, certificate lifecycle management, and device attestation .
  • Experience with event-driven security architectures.
  • Experience implementing secure CI/CD and automated security gates.
  • Security architecture certifications are a plus but not required.

For applications and inquiries, contact:View email address on us.fitly.work

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Identity Security Architect. Be the first to apply!