Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
LPL Financial

AVP, IAM AI Architect, Cyber Security

LPL Financial

. Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs .

Posted 10/2/2026full-timeUnited StatesLead💰 $122,673 - $204,455 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Identity and Access Management (IAM) with a focus on designing and implementing secure identity solutions for AI workloads, including OAuth/OIDC flows and API integrations. Proven ability to lead IAM initiatives, mentor engineers, and ensure compliance with security standards.

Highest-signal resume keywords
IAM Architecture DesignOAuth 2.0 / OIDC TroubleshootingPingOne AIC / Microsoft Entra IDAPI Gateway IntegrationCISSP / CCSP Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
IAMOAuth 2.0OIDCSAMLJWTToken ExchangeIdentity DesignSecrets ManagementAPI IntegrationIdentity Lifecycle Management
Soft Skills
Strong Communication Skills
Tools & Technologies
PingOne AICMicrosoft Entra IDSailPointCyberArkAuth0KongOasis SecurityAstrix SecurityAkeylessHashiCorp Vault
Certifications & Qualifications
CISSPCCSPEntraPingSailPointAWS
Industry Keywords
Identity Threat DetectionZero TrustAI/ML PlatformsMicroservicesBFF ArchitecturesIAM ModernizationM&A ProgramsNon-Human Identity

Tech Stack

Tools & technologies
AWSMicroservicesVault

About the role

Key responsibilities & impact
  • Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs
  • Assess SSO, MFA, federation, and API authorization models and identify gaps
  • Design enterprise IAM patterns and OAuth/OIDC client models
  • Define standards for securing agent tools, data access, and cross-domain integrations
  • Produce architecture artifacts and reference implementations
  • Lead and build IAM proofs of concept, including end-to-end flows, token exchange, gateway enforcement, and delegated agent access
  • Configure and test identity flows; troubleshoot tokens, scopes, and integrations
  • Implement or guide IAM integrations across gateways, BFFs, agent orchestration, and observability
  • Evaluate and implement Non-Human Identity and secrets-management solutions for agents and autonomous workloads
  • Design and implement agent identity at the gateway, including token validation, scope enforcement, and policy-driven access control
  • Automate agent onboarding workflows, identity registration, entitlement assignment, and IAM/PAM integration
  • Define entitlement and data enforcement patterns for authorized access to tools, APIs, and datasets
  • Ensure production-scale reliability, observability, and operational readiness
  • Design and test MCP-enabled identity integration flows
  • Enable secure external developer, agent, and MCP access through federation, scoped credentials, and gateway controls
  • Transition validated patterns to IAM engineering for production rollout
  • Define agent identity lifecycle, including registration, credential rotation, revocation, and environment separation
  • Integrate IAM across AI platform components and support CI/CD and IaC for IAM configurations
  • Establish human-in-the-loop controls, break-glass access, and rate limiting
  • Maintain documentation, decision records, diagrams, and runbooks
  • Deliver POC summaries, evaluations, and implementation guidance; communicate risks and dependencies
  • Ensure regulatory compliance and partner on threat modeling and controls
  • Serve as IAM subject matter expert for AI initiatives and mentor engineers
  • Deliver production-ready IAM patterns and reduce identity risk across AI workloads

Requirements

What you’ll need
  • 6+ years in IAM, security architecture, or platform engineering with significant IAM scope
  • 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows, including Auth Code + PKCE, refresh tokens, client credentials, token exchange, and OBO
  • 2+ years with PingOne AIC and/or Microsoft Entra ID
  • Hands-on experience designing identity for APIs, microservices, and BFF architectures
  • Experience integrating IAM with API gateways, AI/ML platforms, and modern application stacks
  • Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns
  • Familiarity with agent/tool identity models and secure integration patterns
  • Ability to translate AI requirements into secure identity designs
  • Strong communication skills
  • Experience delivering AI/ML agents or copilots to production (preferred)
  • Experience with SailPoint, CyberArk/Delinea, or Auth0/CIAM (preferred)
  • Experience with NHI or secrets-management solutions such as Oasis Security, Astrix Security, Entro Security, Akeyless, CyberArk/Conjur, or HashiCorp Vault (preferred)
  • Knowledge of AI-aware API gateways such as Kong (preferred)
  • Experience with IAM modernization or M&A programs (preferred)
  • Relevant certifications such as CISSP, CCSP, Entra, Ping, SailPoint, or AWS (preferred)
  • Familiarity with zero trust and identity threat detection (preferred)

Benefits

Comp & perks
  • 401K matching
  • Health benefits
  • Employee stock options
  • Paid time off
  • Volunteer time off
  • Competitive LPL Total Rewards package