Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AI Security & Identity Lead

Rimini Street

Security & Identity Lead - Agentic ERP Platform

The Security & Identity Lead owns the security architecture, identity management, and compliance posture of Rimini Street's Agentic ERP Platform. This role is responsible for ensuring that AI agent interactions, data access, and system integrations meet enterprise security standards — designing authentication, authorization, and data isolation frameworks that protect customer environments — and for producing the audit evidence, compliance reporting, and customer-facing security posture that make those controls defensible to auditors and client security teams.

Reporting to the VP, Platform Engineering, this leader builds and runs the Malaysia-based security and compliance observability function — partnering with Platform Engineering, Operations, and Delivery across all three hubs. The ideal candidate combines deep security engineering expertise with practical experience securing cloud-native, multi-tenant platforms, and brings the leadership maturity to grow a small team and represent platform security to executive, audit, and customer audiences.

Essential Duties & Responsibilities

Security Architecture

  • Design and implement the platform's security architecture, covering authentication, authorization, encryption, and audit logging.
  • Define trust boundaries and access control policies that govern agent-to-system and user-to-agent interactions.
  • Establish data isolation and multi-tenancy security patterns that protect customer data across all platform layers.
  • Conduct threat modelling and security risk assessments for new platform features and integrations, including AI-specific risks (prompt injection, indirect injection, RAG corpus contamination).
  • Define and enforce security standards for API endpoints, data storage, inter-service communication, and air-gap deployment scenarios.

Identity & Access Management

  • Design and implement IAM solutions including SSO, OAuth 2.0, OIDC, and SAML integrations for enterprise customers.
  • Build role-based access control (RBAC) and attribute-based access control (ABAC) frameworks for platform users and agents, including policy-as-code (OPA/Rego) authoring and review.
  • Implement token management, session handling, and credential lifecycle policies.
  • Design customer identity federation patterns that integrate with enterprise identity providers.
  • Establish service-to-service authentication and authorization for internal platform components, including mTLS and HashiCorp Vault-managed secrets.

Compliance, Audit & Observability

  • Own platform compliance posture against relevant security frameworks (SOC 2, ISO 27001, GDPR, and industry-specific requirements).
  • Lead operational and security observability that turns platform telemetry into compliance evidence, customer-facing posture reports, and audit artefacts.
  • Establish data classification policies and implement appropriate controls for each classification level.
  • Coordinate with Rimini Street's corporate security and compliance teams to align platform security with organizational policies.
  • Produce security documentation, including architecture decision records, threat models, and audit-ready compliance evidence.
  • Support the Indemnification Control Owner with integrated quarterly configuration audit reports covering monitored vendor indemnification conditions.
  • Own client-facing audit and security response: produce evidence packages on demand for client audits, regulatory reviews, and security questionnaires.

Security Operations

  • Implement security scanning and vulnerability management for platform code, dependencies, and infrastructure (PII detection via Microsoft Presidio or equivalent).
  • Align platform incident response with Rimini Street's corporate security incident process.
  • Conduct security code reviews and establish secure coding guidelines for engineering teams across all three delivery hubs.
  • Monitor and respond to security advisories affecting platform dependencies and infrastructure.
  • Perform periodic security assessments and coordinate penetration testing.

Team Leadership

  • Lead the Malaysia-based security and compliance observability function, including direct management of the Observability & Governance Engineer.
  • Grow the function over time as the platform scales — hiring, mentoring, and developing security and observability talent.
  • Establish team processes for evidence production, audit response, and compliance reporting that balance rigour with delivery velocity.
  • Represent platform security to executive, audit, customer, and partner audiences — translating technical controls into business-language posture reports.
  • Partner with the Security & Identity Lead's peers across hubs: Platform Engineering (security control implementation), AI/ML Lead (LLM observability integration), DevOps (CI/CD security), and Delivery (client security evidence).

Experience

  • 8+ years of security engineering experience, with at least 3 years in a lead or management role.
  • Proven experience designing security architectures for cloud-native, multi-tenant platforms.
  • Hands-on experience implementing IAM solutions (SSO, OAuth 2.0, OIDC, SAML) in enterprise environments.
  • Track record of producing audit evidence for SOC 2, ISO 27001, SOX, or equivalent regulatory frameworks.
  • Experience leading security initiatives across distributed engineering teams and managing small direct-report teams.
  • Background in enterprise software, ERP systems, or B2B platforms preferred.

Technical Skills

Required

  • Identity protocols: OAuth 2.0, OpenID Connect, SAML 2.0, and JWT/JWS/JWE.
  • Authentication and authorization frameworks: Keycloak, Auth0, Okta, or equivalent.
  • Policy-as-code: OPA/Rego authoring, review, and integration with platform services.
  • Secrets management: HashiCorp Vault or equivalent enterprise secret store.
  • Application security: OWASP Top 10, secure coding practices, and security code review.
  • AI-specific security: prompt injection defence, indirect injection mitigations, RAG corpus integrity, model access controls.
  • PII detection and data masking (Microsoft Presidio or equivalent).
  • Encryption: TLS/mTLS, data-at-rest encryption, key management, and certificate lifecycle.
  • API security: rate limiting, input validation, CORS, and API gateway security patterns.
  • Cloud security: AWS or Azure security services, IAM policies, VPC networking, and secrets management.
  • Air-gap and disconnected deployment security: secrets distribution, certificate lifecycle, update propagation.
  • Python and/or Java for security tooling and integration development.
  • Git version control and CI/CD security integration (SAST, DAST, SCA).

Preferred

  • Experience with PostgreSQL security: row-level security, encryption extensions, and audit logging.
  • Knowledge of container and Kubernetes security (pod security policies, network policies, service mesh).
  • Familiarity with infrastructure-as-code security (Terraform, CloudFormation scanning).
  • Experience with LLM observability tooling (LangFuse or equivalent) and operational telemetry interpretation for AI systems.
  • Experience with security information and event management (SIEM) tools.
  • Exposure to Zero Trust architecture principles and implementation.
  • Experience with hardware security modules (HSM) or cloud KMS.
  • Familiarity with AI assurance frameworks (AIUC-1 or equivalent).
  • Experience with third-party MCP / agent security models or LLM gateway security patterns (rate limiting at the model layer, prompt firewall, output filtering).

Skills & Competencies

  • Security-first mindset; designs systems with defence-in-depth and least-privilege principles.
  • Evidence-oriented; understands that compliance is about producing defensible records, not just collecting data.
  • Strong people leadership; able to grow and retain a small, high-performing security and observability team.
  • Customer-facing maturity; can represent platform security to external auditors, client security teams, and executive audiences.
  • Strong analytical skills; able to assess complex systems for security risks and design proportionate controls.
  • Collaborative; works effectively with engineering teams to integrate security without impeding delivery velocity.
  • Pragmatic; balances security rigour with business needs and development speed.
  • Clear communicator; able to articulate security risks, trade-offs, and compliance posture to technical and
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the AI Security & Identity Lead in United States vacancy
  • A leading cybersecurity firm is seeking a B2B Product Marketing role focused on identity security. You will create competitive strategies, write sales enablement content, and develop customer case studies using AI tools for rapid production. The ideal candidate should have... 
    Suggested

    Medium

    San Francisco, CA
    3 days ago
  • $150k - $225k

    DRW Holdings, LLC., based in Chicago, is seeking a Platform Security Team Lead to lead a team responsible for securing core systems. This hands-on leadership role requires a strong engineering background, experience in infrastructure or security engineering, and the ability... 
    Suggested

    DRW Holdings, LLC.

    Chicago, IL
    3 days ago
  • DRW is seeking a Platform Security Team Lead in Chicago to guide a team responsible for securing key systems. This role combines hands-on leadership with strategic oversight, requiring engagement in technical architecture and security engineering. Strong communication... 
    Suggested

    P2P

    Chicago, IL
    2 days ago
  • $160k - $180k

     ...Customer Identity & Access Management (CIAM) Security Architecture Lead IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and...  ...Java, Go, etc.) Experience applying analytics or AI/ML to identity security or anomaly detection What... 
    Suggested
    Local area
    Remote work
    Worldwide
    Relocation

    IDEXX Laboratories

    United States
    4 days ago
  • $180k - $276k

     ...AI Adoption & Enablement Lead Addison, TX (Hybrid); Bellevue, WA (Hybrid); Durham, NC (Hybrid); Emeryville...  ...Tanium Autonomous IT empowers IT and security teams to make their organizations...  ..., sex, national origin, age, gender identity, sexual orientation, disability, protected... 
    Suggested
    Full time
    Live in
    Work at office
    Worldwide
    Flexible hours
    3 days per week

    Tanium

    Emeryville, CA
    1 day ago
  •  ...Regional Channel Lead (Security & Identity) - West Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that role. At SecureW... 
    Remote work

    SecureW2

    United States
    2 days ago
  •  ...The AI Platform Lead owns the definition, creation, and ongoing management of ULS’s enterprise...  ...roadmap; prioritizing platform reliability, security, governance, and scale; and ensuring...  ...of Azure cloud architecture, including identity/security, networking, containers/... 
    Local area
    Remote work
    Flexible hours
    Shift work

    UL Solutions

    New York, NY
    4 days ago
  •  ...Role : Agentic AI Lead (Python) — Vertex AI RAG + Graph/Vector Datastores Location...  ...cost/performance optimization, CI/CD, and security best practice s.Must-have skil...  ...pregnancy, sexual orientation, or gender identity), national origin, citizenship status, age... 
    Full time

    Galent

    Berkeley Heights, NJ
    1 day ago
  •  ...experience with Python, Java, DataStage & AWS. Our client is a leading Financial Industry, and we are currently interviewing to fill...  ...genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal... 
    Full time
    Contract work
    Local area
    Immediate start

    Pyramid Consulting

    McLean, VA
    3 days ago
  •  ...admired brands, Toyota is growing and leading the future of mobility through innovative...  ...environment. Forward Deployed AI Security Lead Location: Plano, Texas Excited...  ...EDR/XDR, cloud security, API security, identity, vulnerability management) Architect... 

    Toyota

    Plano, TX
    2 days ago
  •  ...A remote job platform is seeking an Identity Security Project Lead & Enablement Manager. The role involves strategic management of projects related to Identity Security, requiring over 8 years of relevant experience and a degree in the applicable field. Candidates must... 
    Remote work

    Remote Jobs

    New York, NY
    2 days ago
  • $125k - $170k

     ...Lead Identity and Access Management Architect – National Security Remote - US Overview Hybrid remote opportunity - Candidates must be geographically located within the contiguous United States with a willingness to travel up to 20%. As an IAM Lead Technical... 
    Contract work
    Local area
    Remote work

    ePlus

    United States
    1 day ago
  •  ...Senior Lead Architect Shape secure digital experiences and drive Customer Identity and Access Management strategy and customer security. If you are excited about shaping the future of technology and driving significant business impact in financial services, we are... 

    Chase

    Jersey City, NJ
    3 days ago
  • $196.5k - $291.5k

     ...shopping simple, personalized, and secure, PayPal empowers consumers and...  ...This role drives agentic AI product strategy aligned with...  ...research and market analysis. Leads workstreams to include...  ...pregnancy, sexual orientation, gender identity and/or expression, genetic... 
    Work at office
    Local area
    Immediate start
    Worldwide
    Flexible hours

    PayPal

    San Jose, CA
    1 day ago
  •  ...and artificial intelligence (AI) across the Department of War...  ...capability for DoW support in national security, and the CDAO executes that...  ...for Autonomy, you will lead critical programs focused on developing...  ...(including pregnancy, gender identity, and sexual orientation),... 
    For contractors
    Work at office
    Trial period
    Relocation package
    Afternoon shift

    DoW Chief Digital and Artificial Intelligence Office (CDAO)

    Washington DC
    2 days ago
  • Okta is hiring a Corporate Development Manager in San Francisco to identify and execute acquisitions that will enhance our identity security platform. This role demands a market expert with a strong background in deal execution, ideally within enterprise software or security... 

    Okta

    San Francisco, CA
    22 hours ago
  • Ernst & Young Advisory Services Sdn Bhd based in Dallas is looking for a Digital Identity & Authentication SME. In this role, you will design and implement identity solutions using technologies like Microsoft Entra and Okta. Candidates should have a Bachelor's degree,... 

    Ernst & Young Advisory Services Sdn Bhd

    Dallas, TX
    4 days ago
  • A leading insurance firm is seeking an Identity Security Posture Management Specialist in Jacksonville, FL. Responsibilities include managing identity security posture, coordinating remediation with system owners, and producing audit-ready reports. Ideal candidates should... 

    Kemper

    Jacksonville, FL
    3 days ago
  • A leading specialized insurer is seeking an Identity Security Posture Management Specialist to manage the organization's identity security posture. This hybrid role located in Dallas, TX, requires strong analytical and communication skills, with 7+ years of experience in... 

    Kemper

    Dallas, TX
    3 days ago
  •  ...for a Sales Exec - Business Development in Shakopee, Minnesota. This role involves managing strategic partnerships to enhance identity security in the U.S. financial services market. Candidates should have a Bachelor’s degree and 4+ years in business development, with experience... 

    Entrust

    Shakopee, MN
    3 days ago
  •  ...Lead Enterprise Architect NTT DATA Services is currently seeking...  ...design within a complex, secure federal environment. This role...  ...commercial, hybrid, private), network, identity, and application domains...  ...are one of the world's leading AI and digital infrastructure... 

    Sierra Systems, An Ntt Data Company

    Arlington, VA
    3 days ago
  • $140k - $170k

    Oleria Security in San Francisco seeks an experienced Customer Success Manager to drive enterprise client success. You will oversee the...  ...success within B2B enterprise SaaS, strong hands-on experience with identity platforms, and a passion for customer outcomes. Compensation... 

    Oleria Security

    San Francisco, CA
    4 days ago
  •  ...managing cloud-based solutions within a Microsoft Azure environment. This role requires strong expertise in identity management, cloud infrastructure, and security practices to maintain secure enterprise systems. Ideal candidates will have a Bachelor's degree in a... 
    Full time

    Kids For The Future

    New York, NY
    4 days ago
  • $196.5k - $291.5k

     ...shopping simple, personalized, and secure, PayPal empowers consumers and...  ...Job Summary: This role drives AI product strategy aligned with...  ...and market analysis. ~ Leads workstreams to include analytics...  ..., sexual orientation, gender identity and/or expression, genetic information... 
    Work at office
    Local area
    Immediate start
    Flexible hours

    PayPal

    San Jose, CA
    4 days ago
  •  ...trust and risk management for AI by owning the organization's end...  ...AI, model risk management, AI security, privacy, and compliance....  ...Management & Lifecycle Oversight Lead model risk assessments, validation...  ..., sexual orientation, gender identity, national origin, age,... 
    Work experience placement
    Immediate start
    Remote work

    CareFirst BlueCross BlueShield

    Baltimore, MD
    22 hours ago
  •  ...initiatives. * Evaluates performance, security, reliability, operations, technology and...  ...Experiencein designing and developing AI/ML solutions. This role may require...  ...ethnicity, gender, gender expression, gender identity, genetic information, marital status, national... 
    Flexible hours

    Unisys

    Houston, TX
    4 days ago
  • $119k - $206k

     ...Lead Architect Wells Fargo is back in the office collaborating...  ...shape how core SaaS platforms are securely onboarded and operated across...  ...Identify and account for AI model limitations, security risks...  ...(e.g., STRIDE, ATT&CK) Identity and access management (SSO, federation... 
    Work experience placement
    Work at office
    Visa sponsorship
    3 days per week

    Wells Fargo

    Charlotte, NC
    3 days ago
  • $132.23k - $176.31k

     ...connected ecosystem. We enable secure, highperformance connectivity across cloud, edge, and AI workloads for enterprises, governments...  ...and technically adept Senior Lead Data Architect to lead high-...  ...gender, sexual orientation, gender identity, gender expression, marital... 
    Temporary work
    Remote work

    Lumen Inc

    United States
    2 days ago
  • $92.41k - $128.34k

     ...Senior BI Developer / BI Team Lead - Remote to join our team in...  ...use of workspaces, appropriate security models and a managed self-service...  ...one of the world's leading AI and digital infrastructure providers...  ..., sexual orientation, gender identity, national origin, disability... 
    Work at office
    Remote work
    Flexible hours

    NTT America

    United States
    1 day ago
  • $99k - $225k

     ...R0226901 Network Engineer, Lead The Opportunity: A well-...  ...critical national and global security missions. Join us. The world...  ...days from the Posting Date. Identity Statement As part of the...  ...and prevent fraud. Candidate AI Usage Policy AI is a part... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Worldwide

    Booz Allen Hamilton

    San Diego, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AI Security & Identity Lead. Be the first to apply!