Sr. Principal Iam Security Engineer

Autodesk Autodesk · Enterprise · AMER - United States - California - Offsite +7 · Remote

This role focuses on defining and implementing secure identity and access management (IAM) strategies for human, non-human, and AI/agentic identities within an enterprise. It involves designing and building controls, defining secure patterns for AI acting on behalf of users or services, and embedding AI/ML capabilities into IAM platforms for automated governance and threat detection. The role also includes fine-tuning AI models for identity-specific security tasks and ensuring AI identity behaviors are measurable and governable.

What you'd actually do

  1. Define the enterprise and platform IAM strategy for human identities, NHI, and AI/agent identities, including lifecycle, authentication, authorization, and auditing standards.
  2. Build and operationalize controls for service identities, workload identities, API identities, bots, and automation accounts across cloud, CI/CD, and runtime environments.
  3. Define secure patterns for AI acting on behalf of users or services, including delegated authorization, scoped tokens, and least-privilege access models.
  4. Design, build, and deploy purpose-built AI agents and ML-powered security systems that autonomously execute IAM functions — including identity lifecycle management, entitlement reviews, and real-time response to identity-based threats.
  5. Embed AI and machine learning capabilities into IAM platforms and security tooling to enable intelligent, automated identity governance — including access decisioning, anomaly detection, and agent behavior monitoring.

Skills

Required

  • 10+ years in IAM / security engineering, including designing identity architectures at enterprise scale.
  • Proven experience securing non-human identities across cloud, CI/CD, and production runtimes.
  • Deep knowledge of auth standards: OAuth2, OIDC, SAML, JWT, token exchange, federation, and modern workload identity patterns.
  • Strong authorization design experience: modeling permissions, least privilege, policy enforcement, and access governance.
  • Experience designing or securing systems where software agents act on behalf of users/services (delegation, impersonation, tool access, constrained execution).
  • Ability to define guardrails for agentic actions: approval gates, scoped permissions, auditable trails, and containment strategies.
  • Strong software engineering fundamentals (APIs, distributed systems, logging/telemetry); ability to review designs and code.
  • Experience with cloud IAM ecosystems and platform primitives (identity federation, workload identity, secretless patterns, KMS/HSM integration).
  • Experience building identity “paved roads” and internal developer platforms (IDP) patterns for identity.
  • Experience with privileged access management and tiering models for admin access.
  • Familiarity with CI/CD identity, signing, and provenance controls (build identities, artifact trust, token hardening).
  • Drives measurable risk reduction and adoption across orgs.
  • Sets standards others follow; resolves ambiguous identity problems; leads through influence.

What the JD emphasized

  • lead the strategy and execution for modern Identity and Access Management
  • emerging AI/agentic identity patterns
  • design and drive scalable, secure-by-default identity guardrails
  • Zero Trust enforcement
  • Non-Human Identity (NHI) governance
  • automation of identity workflows
  • Define the enterprise and platform IAM strategy
  • AI/agent identities
  • Build and operationalize controls for service identities, workload identities, API identities, bots, and automation accounts
  • Drive adoption of short-lived, federated credentials
  • reduce static secrets and unmanaged service accounts
  • Implement lifecycle governance for NHI
  • Define secure patterns for AI acting on behalf of users or services
  • Partner with AI platform teams to implement guardrails
  • Ensure AI identity behaviors are measurable and governable
  • Embed AI and machine learning capabilities into IAM platforms
  • Design, build, and deploy purpose-built AI agents and ML-powered security systems
  • Fine-tune and optimize existing AI models
  • Build/standardize authorization models
  • Drive consistent policy as code, access reviews, and privileged access workflows
  • Define standards for token scopes, claims, session constraints, step-up auth, and sensitive action protections
  • Improve detection/response for identity threats
  • Create metrics and reporting for identity posture and platform adoption
  • Lead identity-related investigations and post-incident improvements
  • Serve as a senior technical leader influencing engineering orgs, platform teams, and security
  • Translate risk into pragmatic engineering requirements
  • lead Autodesk’s enterprise identity posture
  • drive large-scale impact across teams
  • ensure our systems are secure, automated, and aligned with Zero Trust principles

Other signals

  • AI/agentic identity patterns
  • AI agents and ML-powered security systems
  • Fine-tune and optimize existing AI models