FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

AVP, IAM AI Architect, Cyber Security
LPL Financial. Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Identity and Access Management (IAM) with a focus on designing and implementing secure identity solutions for AI workloads, including OAuth/OIDC flows and API integrations. Proven ability to lead IAM initiatives, mentor engineers, and ensure compliance with security standards.
Highest-signal resume keywords
IAM Architecture DesignOAuth 2.0 / OIDC TroubleshootingPingOne AIC / Microsoft Entra IDAPI Gateway IntegrationCISSP / CCSP Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
IAMOAuth 2.0OIDCSAMLJWTToken ExchangeIdentity DesignSecrets ManagementAPI IntegrationIdentity Lifecycle Management
Soft Skills
Strong Communication Skills
Tools & Technologies
PingOne AICMicrosoft Entra IDSailPointCyberArkAuth0KongOasis SecurityAstrix SecurityAkeylessHashiCorp Vault
Certifications & Qualifications
CISSPCCSPEntraPingSailPointAWS
Industry Keywords
Identity Threat DetectionZero TrustAI/ML PlatformsMicroservicesBFF ArchitecturesIAM ModernizationM&A ProgramsNon-Human Identity
Tech Stack
Tools & technologiesAWSMicroservicesVault
About the role
Key responsibilities & impact- Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs
- Assess SSO, MFA, federation, and API authorization models and identify gaps
- Design enterprise IAM patterns and OAuth/OIDC client models
- Define standards for securing agent tools, data access, and cross-domain integrations
- Produce architecture artifacts and reference implementations
- Lead and build IAM proofs of concept, including end-to-end flows, token exchange, gateway enforcement, and delegated agent access
- Configure and test identity flows; troubleshoot tokens, scopes, and integrations
- Implement or guide IAM integrations across gateways, BFFs, agent orchestration, and observability
- Evaluate and implement Non-Human Identity and secrets-management solutions for agents and autonomous workloads
- Design and implement agent identity at the gateway, including token validation, scope enforcement, and policy-driven access control
- Automate agent onboarding workflows, identity registration, entitlement assignment, and IAM/PAM integration
- Define entitlement and data enforcement patterns for authorized access to tools, APIs, and datasets
- Ensure production-scale reliability, observability, and operational readiness
- Design and test MCP-enabled identity integration flows
- Enable secure external developer, agent, and MCP access through federation, scoped credentials, and gateway controls
- Transition validated patterns to IAM engineering for production rollout
- Define agent identity lifecycle, including registration, credential rotation, revocation, and environment separation
- Integrate IAM across AI platform components and support CI/CD and IaC for IAM configurations
- Establish human-in-the-loop controls, break-glass access, and rate limiting
- Maintain documentation, decision records, diagrams, and runbooks
- Deliver POC summaries, evaluations, and implementation guidance; communicate risks and dependencies
- Ensure regulatory compliance and partner on threat modeling and controls
- Serve as IAM subject matter expert for AI initiatives and mentor engineers
- Deliver production-ready IAM patterns and reduce identity risk across AI workloads
Requirements
What you’ll need- 6+ years in IAM, security architecture, or platform engineering with significant IAM scope
- 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows, including Auth Code + PKCE, refresh tokens, client credentials, token exchange, and OBO
- 2+ years with PingOne AIC and/or Microsoft Entra ID
- Hands-on experience designing identity for APIs, microservices, and BFF architectures
- Experience integrating IAM with API gateways, AI/ML platforms, and modern application stacks
- Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns
- Familiarity with agent/tool identity models and secure integration patterns
- Ability to translate AI requirements into secure identity designs
- Strong communication skills
- Experience delivering AI/ML agents or copilots to production (preferred)
- Experience with SailPoint, CyberArk/Delinea, or Auth0/CIAM (preferred)
- Experience with NHI or secrets-management solutions such as Oasis Security, Astrix Security, Entro Security, Akeyless, CyberArk/Conjur, or HashiCorp Vault (preferred)
- Knowledge of AI-aware API gateways such as Kong (preferred)
- Experience with IAM modernization or M&A programs (preferred)
- Relevant certifications such as CISSP, CCSP, Entra, Ping, SailPoint, or AWS (preferred)
- Familiarity with zero trust and identity threat detection (preferred)
Benefits
Comp & perks- 401K matching
- Health benefits
- Employee stock options
- Paid time off
- Volunteer time off
- Competitive LPL Total Rewards package