Principal Cyber Security Engineer - Agentic Identity and Security

NVIDIA NVIDIA · Semiconductors · Santa Clara, CA

This Principal Cyber Security Engineer role focuses on building core agentic identity and security capabilities for AI agents within NVIDIA's internal ecosystem. The role involves architecting and prototyping solutions for agent use cases across various environments, developing reusable tools and APIs, and collaborating with multiple teams to ensure secure and reliable agent operations. It requires strong software engineering, security, and identity expertise, with an emphasis on practical, production-ready systems.

What you'd actually do

  1. Architect and build agent identity security features for agent use cases across cloud, on-premises, and hybrid environments. Apply relevant standards and patterns where possible. Rapidly prototype, validate, and iterate on innovative ways when gaps remain, such as credential brokering, token exchange, delegation, workload identity, and lifecycle management.
  2. Rapidly identify the highest-value MVP for ambiguous security and identity problems, prototype solutions, validate them with partner teams, and iterate toward production-ready services.
  3. Build reusable skills, CLI tools, APIs, and integration patterns that help internal teams embrace secure agent identity approaches across enterprise tools and platforms.
  4. Partner closely with teams across Enterprise Security, Product Security, Enterprise AI, Enterprise Product and relevant platform teams to align architecture with real workflow needs and operational constraints.
  5. Contribute to architectural direction, reviews, and engineering standards for agentic identity and related security infrastructure across the company.

Skills

Required

  • Bachelor’s degree or Master’s degree or equivalent experience in Computer Science or a related field.
  • 15+ years in software engineering, security engineering, identity, distributed systems, or related areas, including significant hands-on technical leadership.
  • Proven track record to frame sophisticated problem spaces, define an MVP, prototype quickly, and evolve ideas into reliable production systems.
  • Strong software engineering skills, including crafting and building backend services, APIs, automation, or platform components in programming environments.
  • Experience in offensive security, adversarial thinking, red teaming, or attack-path analysis, capable of applying that perspective to architecture decisions and security tradeoffs.
  • Experience with device trust, endpoint posture, or hardware-backed trust signals, and an understanding of how device identity and device state can strengthen access decisions for agentic, workload, and human-to-agent workflows.
  • Ability to collaborate across organizational boundaries, balance security with usability and adoption, and drive pragmatic technical outcomes through influence.
  • Hands-on experience with container technologies (Docker, containerd, or equivalent), network infrastructure (proxies, routing, firewalls, VPNs), and general cloud service provider (CSP) environments (AWS, Azure, or GCP)
  • Good understanding of existing and emerging identity and access concepts such as OAuth 2.0/2.1, OIDC, SCIM, mTLS, SPIFFE, MCP, AuthZen, certificate lifecycle management, and secrets management.

Nice to have

  • Strong full-stack or software engineering instincts, including the ability to build reusable frameworks, APIs, and tooling that improve engineering velocity and consistency.
  • Experience with agentic or AI-adjacent systems, such as tool-using applications, workflow orchestration, evaluation loops, policy controls, memory/context services, or trust and discovery systems.
  • Familiarity with AI-specific security risks such as prompt injection, tool misuse, unauthorized access expansion, data exfiltration, or unsafe delegation patterns.

What the JD emphasized

  • Proven track record to frame sophisticated problem spaces, define an MVP, prototype quickly, and evolve ideas into reliable production systems.
  • Experience in offensive security, adversarial thinking, red teaming, or attack-path analysis, capable of applying that perspective to architecture decisions and security tradeoffs.
  • Hands-on experience with container technologies (Docker, containerd, or equivalent), network infrastructure (proxies, routing, firewalls, VPNs), and general cloud service provider (CSP) environments (AWS, Azure, or GCP)
  • Good understanding of existing and emerging identity and access concepts such as OAuth 2.0/2.1, OIDC, SCIM, mTLS, SPIFFE, MCP, AuthZen, certificate lifecycle management, and secrets management.

Other signals

  • AI agents accessing tools, calling APIs, and participating in multi-step operations
  • Define and build core agentic identity capabilities
  • Enable trusted AI agents across NVIDIA’s internal ecosystem
  • Hands-on engineering role for someone who can turn complex problems into practical designs, quickly prototype solutions, and work across identity, security, platform, and application teams to bring the right infrastructure into production.