Security Engineer Architect — Identity, Authorization & Platform Security
Denver, CO - USA
Job Summary
Location: Denver CO 100% Onsite
Job Type: Contract
Duration: Contract / Long-Term Engagement
We are seeking a hands-on Security Engineer / Architect to design build and implement a unified policy-driven security layer across the platform.
The primary focus will be on Identity & Access Management (IAM) RBAC authorization cloud security secrets management vulnerability management security telemetry SIEM integration and platform security.
This is a builders role requiring strong hands-on engineering experience. The selected candidate will own the architecture deliver reference implementations establish security standards and work closely with engineering teams to implement production-ready security solutions.
- Design a canonical identity entitlement and role model across infrastructure cloud IAM applications containers and other downstream systems.
- Implement identity federation using OIDC SAML OAuth2 and standards-based provisioning.
- Build automated user/group/role provisioning and lifecycle management.
- Implement access recertification and governance processes.
- Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
- Establish SSO and API authentication across services.
- Implement consistent organization and tenant isolation across identity and downstream platforms.
- Design and implement centralized authorization using RBAC ABAC and/or ReBAC models.
- Implement an externalized policy-decision engine and manage policies as code.
- Define fine-grained authorization boundaries for users applications agents services and tools.
- Implement OAuth2/OIDC concepts including scopes audiences token exchange JWTs and audience restriction.
- Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.
- Design authorization models for AI agents and automated tool invocation.
- Establish agent workload identities and delegated authorization.
- Implement per-agent cryptographic identities and on-behalf-of authorization.
- Define tool-level permissions based on users agents tenants resources and actions.
- Implement human-in-the-loop approval workflows for sensitive operations.
- Maintain complete tamper-evident audit trails for agent and tool activity.
- Apply security controls against prompt injection and unauthorized tool execution.
- Implement centralized secrets management and automated credential rotation.
- Design secure cloud IAM architectures and least-privilege access.
- Implement secure credential management for applications workloads agents and infrastructure.
- Support secure execution environments and sandboxing for sensitive tool calls.
- Implement continuous vulnerability scanning across:
- Edge compute nodes
- Containers and container images
- Operating systems
- Application dependencies
- Container-orchestration platforms
- Third-party libraries
- Device firmware where applicable
- Implement SBOM generation tracking and vulnerability correlation.
- Correlate CVEs with asset exposure and exploitability.
- Develop risk-based vulnerability prioritization and remediation workflows.
- Build operational and executive vulnerability dashboards.
- Integrate vulnerability findings with event platforms and ticketing workflows.
- Deploy security telemetry capabilities across edge environments.
- Capture authentication authorization process execution network connections file integrity configuration changes secret access and agent/tool activity.
- Normalize security events into a common schema.
- Integrate security telemetry with centralized SIEM platforms.
- Implement store-and-forward capabilities for intermittently connected edge environments.
- Design bandwidth-aware event batching and reliable event delivery.
- Implement tamper-evident and mutually authenticated telemetry pipelines.
- Maintain tenant isolation throughout the telemetry pipeline.
- Develop SIEM detection and correlation rules that associate security events with verified identities.
- Route actionable security alerts into event buses and on-call workflows.
- Establish security standards for event-platform authentication and authorization.
- Implement message signing and secure service-to-service communication.
- Support edge-device identity mTLS PKI and certificate lifecycle management.
- Integrate security controls into CI/CD pipelines.
- Implement security gates including artifact signing IaC scanning and automated security validation.
- Partner with engineering teams to establish reusable security primitives and standards.
- 8 years of experience in security engineering.
- 3 years of experience architecting and implementing Identity & Access Management at scale.
- Strong hands-on experience with enterprise Identity Providers and identity federation.
- Deep knowledge of OAuth2 OIDC SAML JWT SSO and standards-based provisioning.
- Experience mapping federated identities to downstream authorization models.
- Strong understanding of OAuth2/OIDC scopes audiences token exchange and audience restrictions.
- Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
- Experience with externalized authorization/policy engines.
- Strong cloud IAM experience.
- Hands-on experience with centralized secrets management and automated credential rotation.
- Experience with containers and container orchestration.
- Ability to develop production-quality code and implement security solutions hands-on.
- Demonstrated experience implementing least-privilege and Just-in-Time access.
- Experience building fully auditable access-control systems.
- Experience securing AI agents LLM applications and automated tool-invocation interfaces.
- Knowledge of prompt-injection and AI tool-boundary security.
- Experience with workload identity and machine-to-machine authentication.
- Experience building security telemetry pipelines and SIEM integrations.
- Experience with vulnerability-management programs SBOM tools CVE correlation and risk prioritization.
- Experience securing edge IoT or intermittently connected environments.
- Experience with lightweight host-based security telemetry agents.
- Knowledge of Zero Trust architecture.
- Experience with PKI mTLS certificate lifecycle management and device attestation.
- Experience with event-driven security architectures.
- Experience implementing secure CI/CD and automated security gates.
- Security architecture certifications are a plus but not required.