AI Identity Governance Engineer

Jobs via Dice • United State
Relocation
This Job is No Longer Active This position is no longer accepting applications
AI Summary

Lead IAM security architecture for enterprise AI initiatives, ensuring strict compliance with aerospace and corporate security standards. Develop and operate hybrid identity infrastructure, designing security guardrails for AI tools. Implement entitlement management and access reviews to control access to GenAI tools.

Key Highlights
Lead IAM security architecture for enterprise AI initiatives
Develop and operate hybrid identity infrastructure
Implement entitlement management and access reviews
Key Responsibilities
Implement entitlement management and access reviews to control access to GenAI tools
Secure and govern Service Principals, Managed Identities, and API tokens used by AI agents and automated workflows
Manage the lifecycle of Microsoft Entra ID and on-premise Active Directory
Technical Skills Required
Microsoft Entra ID (Azure AD) Active Directory Group Policy Microsoft Purview Data Lifecycle Management DLP PowerShell scripting Microsoft Graph API
Benefits & Perks
Target Salary: ~$115,000 + Performance-based Bonus
Full relocation package available
Nice to Have
Microsoft Certifications - Identity and Access Administrator (SC-300) or Information Protection Administrator (SC-401)
Experience configuring security controls for Microsoft 365 Copilot

Job Description


Dice is the leading career destination for tech experts at every stage of their careers. Our client, TriCom Technical Services, is seeking the following. Apply via Dice today!

Our client is seeking an AI Identity Governance Engineer to lead IAM security architecture for our enterprise AI initiatives. This is a pioneering role that bridges traditional Identity and Access Management (IAM) with the emerging world of Generative AI. Your mission is to ensure that both human and non-human identities (AI agents) interact only with authorized data, maintaining strict compliance with aerospace and corporate security standards.

You will be responsible for the development and operation of our hybrid identity infrastructure (Microsoft Entra ID and Active Directory) while specifically designing the security "guardrails" for AI tools like Microsoft Copilot and custom LLMs.

Role

  • Implement entitlement management and access reviews to control access to GenAI tools. Use Microsoft Purview sensitivity labels and DLP to prevent AI from ingesting or surfacing restricted internal data.
  • Secure and govern Service Principals, Managed Identities, and API tokens used by AI agents and automated workflows to prevent unauthorized privilege escalation.
  • Manage the lifecycle of Microsoft Entra ID and on-premise Active Directory, including trust relationships, schema extensions, and health monitoring.
  • Design and enforce Conditional Access policies that target high-risk sign-ins and restrict AI platform access based on device compliance and geography.
  • Enforce Privileged Identity Management (PIM) for Just-In-Time (JIT) administrative access and monitor for anomalous behavior involving AI applications.
  • Leverage PowerShell and Microsoft Graph API to automate identity provisioning and revocation workflows.

Qualifications

Candidates need to have four or more years of progressive IAM experience in a Microsoft environment.

Required

  • Deep expertise in Microsoft Entra ID (Azure AD), Active Directory, and Group Policy.
  • Hands-on experience with Microsoft Purview (Information Protection, Data Lifecycle Management) and DLP.
  • Solid understanding of how to secure non-human/workload identities and govern LLM access within an enterprise environment.
  • Proficiency in PowerShell scripting and Microsoft Graph API.
  • Strong grasp of DNS, DHCP, and VPN as they relate to authentication flows.

referred

  • Microsoft Certifications - Identity and Access Administrator (SC-300) or Information Protection Administrator (SC-401).
  • Experience configuring security controls for Microsoft 365 Copilot.
  • Experience with Entra Verified ID or decentralized identity standards.

Job Details

  • Location: 100% On-site in Duluth, MN or Knoxville, TN
  • Employment Type: Direct Hire (Permanent)
  • Target Salary: ~$115,000 + Performance-based Bonus
  • <span style="font-size: 10.
  • Relocation: Full relocation package available

  • Similar Jobs

    Explore other opportunities that match your interests

    Director of Global IT Infrastructure

    Networking
    •
    10h ago

    Premium Job

    Sign up is free! Login or Sign up to view full details.

    •••••• •••••• ••••••
    Job Type ••••••
    Experience Level ••••••

    Conservation International

    United State

    Network Communications Engineer

    Networking
    •
    11h ago

    Premium Job

    Sign up is free! Login or Sign up to view full details.

    •••••• •••••• ••••••
    Job Type ••••••
    Experience Level ••••••

    Northrop Grumman

    United State

    Senior IT Support Engineer - Identity and Access Management

    Networking
    •
    13h ago

    Premium Job

    Sign up is free! Login or Sign up to view full details.

    •••••• •••••• ••••••
    Job Type ••••••
    Experience Level ••••••

    MrBeast

    United State

    Subscribe our newsletter

    New Things Will Always Update Regularly