AI Identity Architect

Okta Okta · Enterprise · San Francisco, CA · Sec - IAM-185

This role focuses on architecting and implementing Okta's enterprise identity strategy for autonomous AI agents. The AI Identity Architect will act as Customer Zero, validating identity patterns at production scale, influencing product roadmaps, and partnering with business units to secure the AI lifecycle. Responsibilities include defining roadmaps for Non-Human Identities, architecting cross-app access and delegated authority for agents, and integrating Okta identity into AI orchestration layers like LangChain and model providers.

What you'd actually do

  1. Drive the Roadmap: Act as a primary stakeholder for Okta’s product teams. Translate your real-world experience securing agents into prioritized feature requests and product requirements.
  2. Define a multi-year roadmap for Non-Human Identities (NHIs) and AI Agents aligned with Zero Trust (NIST 800-207) and Okta’s Secure Identity Commitment.
  3. Use ISPM (Identity Security Posture Management) to discover unmanaged AI agents and eliminate "Identity Debt" across the enterprise.
  4. Architect secure Cross-App Access patterns where agents act as intermediaries between enterprise systems.
  5. Refine how user identity is "brokered" to an agent (e.g. OAuth2 Token Exchange), ensuring the agent never has more power than the human user who triggered it.

Skills

Required

  • 7+ years in IAM/Security Architecture
  • strategy work across workforce, customer, and Non-Human Identities (NHIs)
  • Deep knowledge of the core protocols OAuth2/OIDC (especially Token Exchange), SAML, mTLS, JWT, and Model Context Protocol (MCP)
  • Hands-on experience with Modern Identity framework SPIFFE/SPIRE
  • Ability to author Architecture Decision Records (ADR) and influence at the VP/CTO level

Nice to have

  • Prior work shaping identity strategy for autonomous/agent systems, multi-agent delegation, or brokered access patterns
  • Exposure to policy-as-code (OPA/Cedar) and service-mesh identity
  • Certifications such as CISSP-ISSAP, CCSP, or TOGAF

What the JD emphasized

  • securing autonomous agents at scale
  • seen how traditional OAuth flows break under agentic pressure
  • felt the pain of "Secret Zero" in a LangChain loop
  • know exactly where the industry’s current tools fall short
  • Proven track record of securing AI agents and non-human identities in a production environment
  • deep understanding of the "identity gaps" in current AI frameworks

Other signals

  • architecting and stress-testing internal AI security frameworks
  • implement Okta on Okta—validating identity patterns at production scale
  • translate your real-world experience securing agents into prioritized feature requests and product requirements