Corporate Vice President - Lead AI Engineer, Identity & Access Management
$147.5k - $211kNew York Life Insurance Co
Location Designation: Hybrid - 3 days per quarter
Role Overview
The Lead AI Engineer, Identity & Access Management is a senior, hands-on technical role that blends deep Identity & Access Management expertise with modern AI engineering capability. This is not a purely advisory or architectural position. We are looking for a builder and a leader: someone who can design, develop, and deliver production-grade agentic systems while also setting the technical direction, mentoring others, and representing the CISO organization at the enterprise level.
This individual will own three critical, interconnected bodies of work that are central to New York Life’s Cybersecurity strategy:
• IAM Orchestration & MCP Gateway: Own the engineering and enterprise adoption of New York Life’s IAM Orchestration and MCP Identity Gateway capability. This includes driving onboarding of internal teams and AI agents, governing authentication, delegation, authorization, and policy enforcement across human and non-human access patterns, and leading integration efforts across the enterprise identity stack.
• Cyber Multi-Agent Ecosystem – Engineering & Delivery: Serve as the primary AI engineer and technical lead responsible for building and delivering the Cyber Multi-Agent Ecosystem Vision. This is the core of the role: architecting and developing a centralized, governed, agentic platform that transforms Cyber and IAM operations through intelligent automation, orchestrated AI agents, MCP tooling, and a unified identity and data layer, deployed on Google Cloud Platform (Gemini Enterprise Agent Platform, FKA Vertex AI) and/or Amazon AgentCore.
• AI Security Review Board (SRB) Representation: Represent the CISO organization on the Enterprise Security Review Board for all AI-related submissions. The engineer will assess AI system proposals, evaluate agentic and non-human identity risks, and provide authoritative security guidance to ensure all AI deployments meet enterprise governance and compliance requirements.
Successful candidates will have a strong software and systems engineering foundation, hands-on experience building agentic and AI systems on Gemini Enterprise Agent Platform (FKA Vertex) and/or Amazon AgentCore, and the leadership presence to drive cross-functional delivery and represent Cybersecurity at the enterprise level. This role is as much about building the future as it is about securing it.
What You'll Do:
1. IAM Orchestration & MCP Gateway – Engineering & Adoption
• Own the engineering, configuration, and ongoing operation of the enterprise IAM Orchestration and MCP Identity Gateway platform.
• Drive onboarding and adoption across internal teams, applications, and AI agents, serving as the primary technical point of contact for integration efforts.
• Engineer and maintain the gateway as the centralized enforcement layer for OAuth 2.0-based authentication, token delegation, and policy-driven authorization (via OPA) across human and non-human access patterns.
• Design and implement MCP integrations that expose backend enterprise systems as standardized, secure tool endpoints consumable by AI agents.
• Ensure the platform provides robust rate limiting, quota management, kill-switch controls, and full audit logging in alignment with enterprise risk and compliance requirements.
• Collaborate with identity platform teams (IDP, PAM, IGA, Directory Services) to maintain seamless identity orchestration across the enterprise stack.
• Define and execute an integration roadmap to extend gateway capabilities, including human-in-the-loop controls and cross-cloud identity flows.
2. Cyber Multi-Agent Ecosystem – AI Engineering & Technical Leadership
This is the primary and most critical body of work for this role. The engineer will serve as both hands-on builder and technical lead for New York Life’s Cyber Multi-Agent Ecosystem. This is a strategic transformation from traditional, UI-driven IAM systems to an agentic, API-first architecture that enables intelligent automation, real-time decisioning, and near-zero manual intervention across Cyber operations.
• Lead the design, development, and phased delivery of the Cyber Multi-Agent Ecosystem, functioning as the primary AI engineer and technical lead for the initiative.
• Architect and implement a centralized, multi-agent platform on Gemini Enterprise Agent Platform (FKA Vertex) and/or Amazon AgentCore, integrating MCP tooling, vector databases, and retrieval-augmented generation (RAG) architectures for intelligent Cyber and IAM automation.
• Develop and operationalize AI agents across Cyber sub-domains including Identity Governance (UAG), Privileged Access Management (PAM), Web Access Management (WAM), Active Directory, and LDAP enabling end-to-end workflow automation and near real-time SLAs.
• Design and implement Agent Card standards, a Central Agent Registry, and Agent-to-Agent (A2A) communication protocols to support a governed, extensible multi-agent operating model.
• Build an OPA-based policy engine for runtime authorization, Separation of Duties (SoD) enforcement, and governance across all agents and pipelines.
• Establish AI inventory and lifecycle management practices to ensure all deployed agents are registered, governed, audited, and compliant with enterprise security standards.
• Define and enforce Secure Development & Deployment (SDD) guardrails for the agentic ecosystem, including controls for prompt injection mitigation, execution isolation, and unsafe automation prevention.
• Partner with AI platform, data engineering, and cloud infrastructure teams to architect and finalize the unified data layer (databases, vector stores, caching) that underpins the agentic ecosystem.
• Provide technical leadership and mentorship to sub-domain teams (UAG, PAM, WAM, AD, LDAP), enabling each team to contribute agents and tools aligned to central standards.
• Maintain strong delivery governance — managing the linkage between Jira backlog, agent development, and production execution to ensure traceability and accountability end-to-end.
• Drive POC-first, incrementally scaled rollout across IAM domains, building reusable agentic components centrally for re-use across the ecosystem.
3. AI Security Review Board (SRB) – CISO Representation
• Serve as the CISO organization’s designated representative on the Enterprise Security Review Board (SRB), providing authoritative security assessment and approval recommendations for all AI-related submissions.
• Assess AI system and agentic workflow proposals for security risk, including prompt injection, privilege escalation, unauthorized data access, synthetic identity abuse, and unsafe automation patterns.
• Evaluate proposed AI architectures for alignment with enterprise IAM, zero trust, and cloud security standards prior to production approval.
• Provide clear, actionable security guidance and remediation requirements to AI development and product teams during the SRB process.
• Maintain and evolve the enterprise AI security governance framework, contributing to standards, guardrails, and reference architectures leveraged across the organization.
• Represent the CISO organization credibly across cross-functional governance forums, including Architecture Review Boards and enterprise AI working groups.
4. Core IAM Engineering
• Design and implement identity, authentication, and authorization solutions for both traditional and AI-enabled systems, treating AI agents as first-class non-human identities.
• Define and enforce lifecycle management, access controls, and revocation for autonomous agents, machine identities, and service accounts using least-privilege principles.
• Implement delegated and “on-behalf-of” authorization patterns to distinguish human-initiated from agent-initiated actions for audit and compliance purposes.
• Apply least-privilege and scope-limiting controls to prevent privilege escalation in automated and multi-agent workflows.
• Design and support enterprise IAM solutions across Identity Governance & Administration (IGA), Privileged Access Management (PAM), Web Access Management (WAM), and Directory Services.
• Integrate IAM controls across hybrid and cloud environments, with strong hands-on experience in GCP and AWS.
• Implement modern authentication and authorization frameworks including OAuth 2.0, MFA, and password less authentication.
Key Skills
1. Agentic AI Engineering
· Strong hands-on experience with agent frameworks such as LangGraph, ADK (Agent Development Kit), AutoGen, or equivalent programmatic agent frameworks
· Experience designing and building multi-agent systems, including planning, tool execution, and orchestration patterns
· Strong prompt engineering and evaluation skills for production-grade systems
2. Memory & State Management
· Experience designing short-term and long-term memory architectures for AI agents
· Strong understanding of conversation/session state management and persistence strategies
· Hands-on experience with vector databases and retrieval-based memory systems
· Familiarity with state stores such as Redis, Firestore, Postgres, or equivalent
3. Tooling, MCP & API Engineering
· Experience building agent-consumable tools and function interfaces using schema-driven APIs
· Strong understanding of Model Context Protocol (MCP) and tool abstraction patterns
· Experience designing and exposing secure, identity-aware APIs using OAuth2, mTLS, service accounts, and secrets management
4. Cloud & Platforms
· Strong hands-on experience with Google Cloud Platform (Gemini Enterprise Agent Platform (FKA Vertex) preferred)
· Experience with Amazon AgentCore or AWS Bedrock Agents is a plus
5. Security, Identity & Threat Domain
· Deep IAM expertise across IGA, PAM, WAM, Active Directory, and LDAP
· Hands-on experience with SailPoint IIQ, CyberArk, PingIdentity, and directory services
Strong understanding of SIEM platforms and identity-related threat patterns, including privilege escalation, anomalous access, and insider risk
What You'll Bring:
• Bachelor’s degree in Computer Science, Information Systems, Engineering, or equivalent practical experience.
• 10+ years of combined experience in identity & access management, security engineering, and/or AI/software engineering — with a demonstrated track record of both hands-on development and technical leadership.
• Strong hands-on experience building and deploying AI agents and agentic pipelines on Google Cloud Platform (GCP), with specific expertise in Gemini Enterprise Agent Platform (FKA Vertex).
• Hands-on experience with Amazon AgentCore or equivalent managed agentic AI frameworks (e.g., AWS Bedrock Agents) for deploying and securing AI agent workflows at scale.
• Demonstrated experience as an AI engineer or AI developer: writing production code, building agent frameworks, integrating LLMs into operational systems, and designing multi-agent orchestration architectures.
• Working knowledge of multi-agent orchestration patterns, retrieval-augmented generation (RAG) architectures, vector databases, MCP tooling, and Agent-to-Agent (A2A) communication protocols.
• Experience building or operating an IAM Orchestration or MCP Identity Gateway platform, with hands-on knowledge of OAuth 2.0 token flows, policy-as-code enforcement (OPA or equivalent), and identity-aware API gateway patterns.
• Experience securing agentic systems against prompt injection, privilege escalation, execution boundary violations, and unsafe automation, embedding these controls into the development lifecycle.
• 7+ years of IAM domain experience across Identity Governance & Administration (IGA), Privileged Access Management (PAM), Web Access Management (WAM), and/or Directory Services.
• Proven experience managing non-human identities (service accounts, APIs, workloads, autonomous agents) using least privilege and lifecycle governance principles.
• Deep understanding of identity and access protocols: OAuth 2.0, OpenID Connect (OIDC), SAML, LDAP, and modern token-based authorization models.
• Strong software engineering and automation skills (Python, PowerShell, Java or equivalent) with demonstrated ability to deliver production systems, not just prototypes.
• Experience with enterprise IAM platforms such as SailPoint (IGA), CyberArk (PAM), PingFederate/PingIdentity (WAM/Federation), and directory services (Active Directory, LDAP).
• Demonstrated ability to lead cross-functional technical delivery, mentor engineers, and drive alignment across organizational boundaries.
• Strong communication skills and able to articulate complex AI and security concepts clearly to both technical teams and executive or governance audiences.
Preferred Qualifications
• Familiarity with machine and workload identity standards (e.g., SPIFFE/SPIRE, workload identity federation, secrets management).
• Experience designing Agent Card standards, Central Agent Registries, and governed A2A communication frameworks in a multi-agent environment.
• Experience establishing AI inventory and lifecycle management practices for autonomous agents in enterprise production environments.
• Exposure to policy-as-code and fine-grained authorization models beyond OPA (e.g., Cedar, attribute-based access control frameworks).
• Experience supporting Zero Trust architectures and cloud-native security patterns.
• Prior experience serving on or supporting a Security Review Board or Architecture Review Board, particularly for AI or cloud system proposals.
• Prior experience in a large enterprise or regulated financial services environment.
• Relevant certifications (e.g., Google Professional Cloud Security Engineer, Google Professional ML Engineer, AWS Security Specialty, AWS Machine Learning Specialty, SailPoint, CyberArk, CISSP, CISM).
Pay Transparency
Salary Range: $147,500-$211,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities—inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you’ll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what’s next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees – and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work. Click here to discover more about our comprehensive benefit options or visit our NYL Benefits Site .
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life’s leadership in this space.
Recognized as one of Fortune’s World’s Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation . We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of .
Visit our LinkedIn to see how our employees and agents are leading the industry and impacting communities.
Visit our Newsroom to learn more about how our company is constantly evolving to meet our clients' and employees’ needs.
Job Requisition ID: 94015
$125.76k - $188.64k
...ProfessionalCompany: CitiCiti, the leading global bank, has... ...consumers, corporations, governments, and... ..., and wealth management.As a bank with a... ...for a Lead AI/GenAI Engineer to drive the design... ...-level program.Access to enterprise AI... ...orientation, gender identity, national origin,...SuggestedFull timeWork at officeRemote work$217k - $303.9k
Role Description As a Staff Software Engineer within our SPACE org (Security, Privacy, Assurance, and Corporate Engineering), you will play a critical role on the Identity & Access Management (IAM) team. In this role, you will design, deliver, and support the lifecycle...SuggestedFull timeFlexible hours$147.5k - $211k
...Hybrid - 3 days per week The AI / ML Security Operations Engineer is a hands-on senior... ...requirements to ML platform and identity decisions owned by... ...risk, audit, and model risk management stakeholders.What You'll... ...employees and agents are leading the industry and...SuggestedLocal area3 days per week$147.5k - $211k
...days per quarter The Full Stack Engineering Lead will report to the DevSecOps Center for... ...using emerging technologies such as AI, advanced automation, and modern data platforms... ...enterprise platforms such as content management systems, low-code platforms, or...SuggestedLocal area$230k - $368k
...simple, smart and accessible. Our technology and... ...Title and SummaryVice President, Corporate TreasuryVice... ...agency relationship management, foreign exchange risk... ...a highly motivated Vice President to lead the Capital Planning... ...to gender, gender identity, sexual orientation...SuggestedFull timePart timeWorldwideFlexible hours$279.6k
...started when engineer Fred Luddy wrote... ...is the AI control tower... ...looking for a Vice President of Corporate and Product Public... ...Relations to lead all earned... ...crisis and issues management for the... ...compelling, accessible stories for business... ..., gender identity or expression...Work at officeImmediate startRemote workFlexible hours$143.7k - $194.4k
The Amazon Web Services (AWS) Identity team builds, operates, and... ...help customers set appropriate access controls across all their AWS... ...seeking a software developer engineer to be part of our team to build... ...features such as access management and sign on, cryptography, console...InternshipFlexible hours$160k - $240k
Senior Software Engineer - Identity & Privileged Access Management Location New York Business Area Engineering and CTO Ref # 10047610... ...security engineering and infrastructure-as-code practices.Lead architectural and design discussions, mentor junior engineers...Temporary workFor contractorsWork experience placementRemote work$100.1k - $166.9k
...products, and services that make quality care more accessible and affordable. Here, we focus on the health,... ...to hear from you.We are seeking a Software Engineer with deep interest and experience in Identity & Access Management (IAM) to help design, build, and secure...Full time$135.96k - $226.6k
Lead with Purpose, Unlock Your Team’s PassionAt LPL, people leaders hold the key... ...today.Job Overview:The VP, Product Manager - Identity & Access Management (IAM) leads the strategy,... ...operates at the intersection of product, engineering, cybersecurity, risk, and operations...Full timeWork from home- ...next. Whether you're engineering advanced materials... ...technologies, or leading strategic... ...lead for Agentic AI delivery across Supply... ...tool calling, memory management, and agent coordination... ...teams to access insights and take... ...orientation, gender identity, veteran or military...Remote workWorldwide
$75k - $230k
...The Basics The Corporate AI Engineer is a hands ‑ on technical role responsible... ...accuracy, and appropriate access Own operational... ...data engineering, application management, or a similar hands-on technical... ...Many of the world’s leading organizations trust Tanium’...Full timeLive inWork at officeWorldwideFlexible hours3 days per week$200.4k - $343.5k
...data analytics and AI to cybersecurity... ...together. The Vice President, AI Engineering, sets the... ...Strategy, and Product Management. This role serves... ...across corporate functionsTranslate... ...LeadershipBuild and lead a multidisciplinary... ..., gender identity, disability, or...Minimum wageFull timeWork experience placementWork at officeLocal areaRemote work- Job SummaryAs a Senior Lead AI Security Engineer in our Cybersecurity team, you... ...defenses).Graph ML for identity/threat detection; anomaly... ...the world’s most prominent corporate, institutional and government... ...processing and asset management. We offer a competitive total...Work at office
$175k - $190k
...Infrastructure & User Enablement, the VP, Lead Engineer - Infrastructure Operations is a... ...-hosted server environments, endpoint management, identity services, and network operations. This... ...operations across enterprise firewall, remote access, SD-WAN, switching, wireless, and...Full timeTemporary workWork at officeRemote work- ...depends on secure, reliable access to the right tools at... ...next generation of our identity and access platform,... ...we need an exceptional engineer to help us get there. You... ...: ~Login ~Session management ~Permissions ~... ...afterthought. ~Leverage AI tools to move faster —...Full timeWork at officeLocal areaRemote work
$209.6k - $349.3k
...every digital interaction. As Managing Director of Identity and Access Management, this role defines how... ...accountable for the strategy, engineering, and operation of enterprise-wide... ...compliance, and accelerating AI adoption.This role leads the IAM engineering function responsible...Full timeFor contractorsLocal areaWork from homeShift work$300k
Vice President, Corporate Communications|Wonderful Agency# Vice President... ..., crisis and issues management, executive engagement... ...and media outlets.* Lead crisis communication... ...orientation, gender identity, national origin,... ...Wellness Community:** Access to top-notch medical...Full timeWork at officeLocal areaRemote workWorldwide$125.76k - $188.64k
...CitiCiti, the leading global bank, has... ...provides consumers, corporations, governments,... ..., and wealth management.As a bank with... ...Microservice Integration Engineer to serve as the... ...within the AI Automation... ...platforms, identity/auth services (... ...engineering organization.Access to continuous...Full timeContract workWork at officeRemote workWorldwide$185k - $260k
Role Description We are looking for a Staff Software Engineer, Identity & Access Management , to serve as the technical authority for identity, authentication... ...systems are secure, scalable, and maintainable. ~Lead the design and development of Keycloak-based identity...Full time$125.6k - $188.4k
...Digital Software Engineering,... ...Senior Technical Lead, Full-Stack Engineering... ...and AI-assisted development... ...development. In this Vice President-level role,... ...and Risk Management: Effectively communicate... ...scale with access to complex,... ...orientation, gender identity, national...Full timeWork at officeRemote work$208k - $333k
...simple, smart and accessible. Our technology... ...and Summary Vice President, AI Software Engineering Overview:... ...role you will be leading a highly agile,... ...emerging technology, managing new products... ...gender, gender identity, sexual... ...email promptly. Corporate Security Responsibility...Full timeWorldwide$250k - $350k
...that expands access to homeownership... ...Vice President, Corporate Real Estate &... ...facility asset management and operations... ...VP, they will lead a large team (... ...intelligence (AI) to enhance workplace... ...legal, or civil engineering/construction management... ..., gender identity/gender expression...Full timeWork experience placementWork at officeRemote workHome office$145k - $175k
...professional to join the Corporate Finance team. This... ...and quarterly management reporting duties, including... ...business and department Leads to enhance decision... ...Controller, Senior Vice President.ResponsibilitiesSupport... ...orientation, gender identity, age, status as a protected...Full timeWork at officeRemote work- OverviewThe Vice President, IT Strategy & Business Operationsis... ..., contracting, vendor management, governance,... ...clinical, operational, and corporate stakeholders. The position... ...initiatives.Lead IT communications and... ...sexual orientation, gender identity or expression or HIV status...Full timeContract workLocal areaFlexible hours
$119k - $170k
..., NYL.com Product Management, Institutional AudiencesDept... ...mission, building AI-enabled, next-... ...a traditional corporate website into a... ...owned experience engine across human and AI... ...solutions pages and lead flows, and gated/authenticated... ...content access for credentialed...Local areaHome officeShift work3 days per week- ...a future team member for the role of Vice President, Corporate Actions to join our GCO team. This role... ...redemption, etc.Also responsible for managing and controlling high levels of risk and... ...for-performance philosophy. We provide access to flexible global resources and tools...Permanent employmentWork experience placementFlexible hours
$156.16k - $234.24k
...hands-on Senior .Net Lead to contribute to... ...of our engineering frameworks, with a... ...Drive the adoption of AI-powered quality practices... ..., thread management, and memory profiling... ...engineering team with access to state-of-the-art... ...orientation, gender identity, national origin,...Full time$171k - $240k
...combining global corporate cards and banking... ...with intuitive spend management, bill pay, and... ...effortlessly. Brex’s AI-native automation... ...career.AI at BrexAI Engineering at Brex is... ...permissions, read/write access, and acting on behalf... ...experience with identity, authentication, and...Work at officeRemote workWork from homeShift work- ...intelligent agreement management, Docusign unleashes... ...What you'll do As an AI Agentic Engineer on the Platform AI... ...compliance and protection of corporate assetsMonitor agent... ...and remote work. Access to an office location... ...orientation, gender identity, gender expression, genetic...Permanent employmentFull timeContract workWork at officeLocal areaRemote work2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Corporate Vice President - Lead AI Engineer, Identity & Access Management. Be the first to apply!
- vice president information technology Remote
- vice president real estate development Remote
- vice president research Remote
- vp hr Remote
- vice president healthcare Remote
- vice president product development Remote
- vp internal audit Remote
- vice president business solutions Remote
- vice-president human resources Remote
- vice president shared services Remote




