AI Security & Identity Lead
Rimini Street
Security & Identity Lead - Agentic ERP Platform
The Security & Identity Lead owns the security architecture, identity management, and compliance posture of Rimini Street's Agentic ERP Platform. This role is responsible for ensuring that AI agent interactions, data access, and system integrations meet enterprise security standards — designing authentication, authorization, and data isolation frameworks that protect customer environments — and for producing the audit evidence, compliance reporting, and customer-facing security posture that make those controls defensible to auditors and client security teams.
Reporting to the VP, Platform Engineering, this leader builds and runs the Malaysia-based security and compliance observability function — partnering with Platform Engineering, Operations, and Delivery across all three hubs. The ideal candidate combines deep security engineering expertise with practical experience securing cloud-native, multi-tenant platforms, and brings the leadership maturity to grow a small team and represent platform security to executive, audit, and customer audiences.
Essential Duties & Responsibilities
Security Architecture
- Design and implement the platform's security architecture, covering authentication, authorization, encryption, and audit logging.
- Define trust boundaries and access control policies that govern agent-to-system and user-to-agent interactions.
- Establish data isolation and multi-tenancy security patterns that protect customer data across all platform layers.
- Conduct threat modelling and security risk assessments for new platform features and integrations, including AI-specific risks (prompt injection, indirect injection, RAG corpus contamination).
- Define and enforce security standards for API endpoints, data storage, inter-service communication, and air-gap deployment scenarios.
Identity & Access Management
- Design and implement IAM solutions including SSO, OAuth 2.0, OIDC, and SAML integrations for enterprise customers.
- Build role-based access control (RBAC) and attribute-based access control (ABAC) frameworks for platform users and agents, including policy-as-code (OPA/Rego) authoring and review.
- Implement token management, session handling, and credential lifecycle policies.
- Design customer identity federation patterns that integrate with enterprise identity providers.
- Establish service-to-service authentication and authorization for internal platform components, including mTLS and HashiCorp Vault-managed secrets.
Compliance, Audit & Observability
- Own platform compliance posture against relevant security frameworks (SOC 2, ISO 27001, GDPR, and industry-specific requirements).
- Lead operational and security observability that turns platform telemetry into compliance evidence, customer-facing posture reports, and audit artefacts.
- Establish data classification policies and implement appropriate controls for each classification level.
- Coordinate with Rimini Street's corporate security and compliance teams to align platform security with organizational policies.
- Produce security documentation, including architecture decision records, threat models, and audit-ready compliance evidence.
- Support the Indemnification Control Owner with integrated quarterly configuration audit reports covering monitored vendor indemnification conditions.
- Own client-facing audit and security response: produce evidence packages on demand for client audits, regulatory reviews, and security questionnaires.
Security Operations
- Implement security scanning and vulnerability management for platform code, dependencies, and infrastructure (PII detection via Microsoft Presidio or equivalent).
- Align platform incident response with Rimini Street's corporate security incident process.
- Conduct security code reviews and establish secure coding guidelines for engineering teams across all three delivery hubs.
- Monitor and respond to security advisories affecting platform dependencies and infrastructure.
- Perform periodic security assessments and coordinate penetration testing.
Team Leadership
- Lead the Malaysia-based security and compliance observability function, including direct management of the Observability & Governance Engineer.
- Grow the function over time as the platform scales — hiring, mentoring, and developing security and observability talent.
- Establish team processes for evidence production, audit response, and compliance reporting that balance rigour with delivery velocity.
- Represent platform security to executive, audit, customer, and partner audiences — translating technical controls into business-language posture reports.
- Partner with the Security & Identity Lead's peers across hubs: Platform Engineering (security control implementation), AI/ML Lead (LLM observability integration), DevOps (CI/CD security), and Delivery (client security evidence).
Experience
- 8+ years of security engineering experience, with at least 3 years in a lead or management role.
- Proven experience designing security architectures for cloud-native, multi-tenant platforms.
- Hands-on experience implementing IAM solutions (SSO, OAuth 2.0, OIDC, SAML) in enterprise environments.
- Track record of producing audit evidence for SOC 2, ISO 27001, SOX, or equivalent regulatory frameworks.
- Experience leading security initiatives across distributed engineering teams and managing small direct-report teams.
- Background in enterprise software, ERP systems, or B2B platforms preferred.
Technical Skills
Required
- Identity protocols: OAuth 2.0, OpenID Connect, SAML 2.0, and JWT/JWS/JWE.
- Authentication and authorization frameworks: Keycloak, Auth0, Okta, or equivalent.
- Policy-as-code: OPA/Rego authoring, review, and integration with platform services.
- Secrets management: HashiCorp Vault or equivalent enterprise secret store.
- Application security: OWASP Top 10, secure coding practices, and security code review.
- AI-specific security: prompt injection defence, indirect injection mitigations, RAG corpus integrity, model access controls.
- PII detection and data masking (Microsoft Presidio or equivalent).
- Encryption: TLS/mTLS, data-at-rest encryption, key management, and certificate lifecycle.
- API security: rate limiting, input validation, CORS, and API gateway security patterns.
- Cloud security: AWS or Azure security services, IAM policies, VPC networking, and secrets management.
- Air-gap and disconnected deployment security: secrets distribution, certificate lifecycle, update propagation.
- Python and/or Java for security tooling and integration development.
- Git version control and CI/CD security integration (SAST, DAST, SCA).
Preferred
- Experience with PostgreSQL security: row-level security, encryption extensions, and audit logging.
- Knowledge of container and Kubernetes security (pod security policies, network policies, service mesh).
- Familiarity with infrastructure-as-code security (Terraform, CloudFormation scanning).
- Experience with LLM observability tooling (LangFuse or equivalent) and operational telemetry interpretation for AI systems.
- Experience with security information and event management (SIEM) tools.
- Exposure to Zero Trust architecture principles and implementation.
- Experience with hardware security modules (HSM) or cloud KMS.
- Familiarity with AI assurance frameworks (AIUC-1 or equivalent).
- Experience with third-party MCP / agent security models or LLM gateway security patterns (rate limiting at the model layer, prompt firewall, output filtering).
Skills & Competencies
- Security-first mindset; designs systems with defence-in-depth and least-privilege principles.
- Evidence-oriented; understands that compliance is about producing defensible records, not just collecting data.
- Strong people leadership; able to grow and retain a small, high-performing security and observability team.
- Customer-facing maturity; can represent platform security to external auditors, client security teams, and executive audiences.
- Strong analytical skills; able to assess complex systems for security risks and design proportionate controls.
- Collaborative; works effectively with engineering teams to integrate security without impeding delivery velocity.
- Pragmatic; balances security rigour with business needs and development speed.
- Clear communicator; able to articulate security risks, trade-offs, and compliance posture to technical and
- A leading cybersecurity firm is seeking a B2B Product Marketing role focused on identity security. You will create competitive strategies, write sales enablement content, and develop customer case studies using AI tools for rapid production. The ideal candidate should have...Suggested
$150k - $225k
DRW Holdings, LLC., based in Chicago, is seeking a Platform Security Team Lead to lead a team responsible for securing core systems. This hands-on leadership role requires a strong engineering background, experience in infrastructure or security engineering, and the ability...Suggested- DRW is seeking a Platform Security Team Lead in Chicago to guide a team responsible for securing key systems. This role combines hands-on leadership with strategic oversight, requiring engagement in technical architecture and security engineering. Strong communication...Suggested
$160k - $180k
...Customer Identity & Access Management (CIAM) Security Architecture Lead IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and... ...Java, Go, etc.) Experience applying analytics or AI/ML to identity security or anomaly detection What...SuggestedLocal areaRemote workWorldwideRelocation$180k - $276k
...AI Adoption & Enablement Lead Addison, TX (Hybrid); Bellevue, WA (Hybrid); Durham, NC (Hybrid); Emeryville... ...Tanium Autonomous IT empowers IT and security teams to make their organizations... ..., sex, national origin, age, gender identity, sexual orientation, disability, protected...SuggestedFull timeLive inWork at officeWorldwideFlexible hours3 days per week- ...Regional Channel Lead (Security & Identity) - West Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that role. At SecureW...Remote work
- ...The AI Platform Lead owns the definition, creation, and ongoing management of ULS’s enterprise... ...roadmap; prioritizing platform reliability, security, governance, and scale; and ensuring... ...of Azure cloud architecture, including identity/security, networking, containers/...Local areaRemote workFlexible hoursShift work
- ...Role : Agentic AI Lead (Python) — Vertex AI RAG + Graph/Vector Datastores Location... ...cost/performance optimization, CI/CD, and security best practice s.Must-have skil... ...pregnancy, sexual orientation, or gender identity), national origin, citizenship status, age...Full time
- ...experience with Python, Java, DataStage & AWS. Our client is a leading Financial Industry, and we are currently interviewing to fill... ...genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal...Full timeContract workLocal areaImmediate start
- ...admired brands, Toyota is growing and leading the future of mobility through innovative... ...environment. Forward Deployed AI Security Lead Location: Plano, Texas Excited... ...EDR/XDR, cloud security, API security, identity, vulnerability management) Architect...
- ...A remote job platform is seeking an Identity Security Project Lead & Enablement Manager. The role involves strategic management of projects related to Identity Security, requiring over 8 years of relevant experience and a degree in the applicable field. Candidates must...Remote work
$125k - $170k
...Lead Identity and Access Management Architect – National Security Remote - US Overview Hybrid remote opportunity - Candidates must be geographically located within the contiguous United States with a willingness to travel up to 20%. As an IAM Lead Technical...Contract workLocal areaRemote work- ...Senior Lead Architect Shape secure digital experiences and drive Customer Identity and Access Management strategy and customer security. If you are excited about shaping the future of technology and driving significant business impact in financial services, we are...
$196.5k - $291.5k
...shopping simple, personalized, and secure, PayPal empowers consumers and... ...This role drives agentic AI product strategy aligned with... ...research and market analysis. Leads workstreams to include... ...pregnancy, sexual orientation, gender identity and/or expression, genetic...Work at officeLocal areaImmediate startWorldwideFlexible hours- ...and artificial intelligence (AI) across the Department of War... ...capability for DoW support in national security, and the CDAO executes that... ...for Autonomy, you will lead critical programs focused on developing... ...(including pregnancy, gender identity, and sexual orientation),...For contractorsWork at officeTrial periodRelocation packageAfternoon shift
- Okta is hiring a Corporate Development Manager in San Francisco to identify and execute acquisitions that will enhance our identity security platform. This role demands a market expert with a strong background in deal execution, ideally within enterprise software or security...
- Ernst & Young Advisory Services Sdn Bhd based in Dallas is looking for a Digital Identity & Authentication SME. In this role, you will design and implement identity solutions using technologies like Microsoft Entra and Okta. Candidates should have a Bachelor's degree,...
- A leading insurance firm is seeking an Identity Security Posture Management Specialist in Jacksonville, FL. Responsibilities include managing identity security posture, coordinating remediation with system owners, and producing audit-ready reports. Ideal candidates should...
- A leading specialized insurer is seeking an Identity Security Posture Management Specialist to manage the organization's identity security posture. This hybrid role located in Dallas, TX, requires strong analytical and communication skills, with 7+ years of experience in...
- ...for a Sales Exec - Business Development in Shakopee, Minnesota. This role involves managing strategic partnerships to enhance identity security in the U.S. financial services market. Candidates should have a Bachelor’s degree and 4+ years in business development, with experience...
- ...Lead Enterprise Architect NTT DATA Services is currently seeking... ...design within a complex, secure federal environment. This role... ...commercial, hybrid, private), network, identity, and application domains... ...are one of the world's leading AI and digital infrastructure...
$140k - $170k
Oleria Security in San Francisco seeks an experienced Customer Success Manager to drive enterprise client success. You will oversee the... ...success within B2B enterprise SaaS, strong hands-on experience with identity platforms, and a passion for customer outcomes. Compensation...- ...managing cloud-based solutions within a Microsoft Azure environment. This role requires strong expertise in identity management, cloud infrastructure, and security practices to maintain secure enterprise systems. Ideal candidates will have a Bachelor's degree in a...Full time
$196.5k - $291.5k
...shopping simple, personalized, and secure, PayPal empowers consumers and... ...Job Summary: This role drives AI product strategy aligned with... ...and market analysis. ~ Leads workstreams to include analytics... ..., sexual orientation, gender identity and/or expression, genetic information...Work at officeLocal areaImmediate startFlexible hours- ...trust and risk management for AI by owning the organization's end... ...AI, model risk management, AI security, privacy, and compliance.... ...Management & Lifecycle Oversight Lead model risk assessments, validation... ..., sexual orientation, gender identity, national origin, age,...Work experience placementImmediate startRemote work
- ...initiatives. * Evaluates performance, security, reliability, operations, technology and... ...Experiencein designing and developing AI/ML solutions. This role may require... ...ethnicity, gender, gender expression, gender identity, genetic information, marital status, national...Flexible hours
$119k - $206k
...Lead Architect Wells Fargo is back in the office collaborating... ...shape how core SaaS platforms are securely onboarded and operated across... ...Identify and account for AI model limitations, security risks... ...(e.g., STRIDE, ATT&CK) Identity and access management (SSO, federation...Work experience placementWork at officeVisa sponsorship3 days per week$132.23k - $176.31k
...connected ecosystem. We enable secure, highperformance connectivity across cloud, edge, and AI workloads for enterprises, governments... ...and technically adept Senior Lead Data Architect to lead high-... ...gender, sexual orientation, gender identity, gender expression, marital...Temporary workRemote work$92.41k - $128.34k
...Senior BI Developer / BI Team Lead - Remote to join our team in... ...use of workspaces, appropriate security models and a managed self-service... ...one of the world's leading AI and digital infrastructure providers... ..., sexual orientation, gender identity, national origin, disability...Work at officeRemote workFlexible hours$99k - $225k
...R0226901 Network Engineer, Lead The Opportunity: A well-... ...critical national and global security missions. Join us. The world... ...days from the Posting Date. Identity Statement As part of the... ...and prevent fraud. Candidate AI Usage Policy AI is a part...Full timeContract workPart timeWork at officeLocal areaRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AI Security & Identity Lead. Be the first to apply!

