AI IAM Architect

LPL Financial Holdings, Inc.$153K — $255K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in IAM, security architecture, or platform engineering with significant IAM scope.
  • 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows.
  • 2+ years with PingOne AIC and/or Microsoft Entra ID.
  • Hands-on experience designing identity for APIs, microservices, and BFF architectures.
  • Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns.

Responsibilities

  • Discover AI/agent identity requirements across users, services, and APIs.
  • Assess existing SSO, MFA, and API authorization models; identify gaps.
  • Design enterprise IAM patterns and OAuth/OIDC client models.
  • Define standards for securing agent tools and cross-domain integrations.
  • Produce architecture artifacts and reference implementations.
  • Lead and build IAM POCs and configure/test identity flows.
  • Integrate IAM across AI platform components and support CI/CD for IAM configurations.

Benefits

  • 401K matching
  • Health benefits
  • Employee stock options
  • Paid time off
  • Volunteer time off
Full Job Description

Job Overview:


We are seeking an experienced Identity and Access Management (IAM) Architect with a strong AI and agent-integration focus to lead the design, proof-of-concept (POC), and hands-on implementation of identity patterns for AI workloads, conversational agents, and AI platform integrations across the enterprise. The ideal candidate combines deep IAM architecture expertise with practical engineering skills—building POCs, configuring OAuth/OIDC flows, and partnering directly with AI engineering teams to secure agent runtimes, tool access, and human-in-the-loop experiences.

This role owns IAM architecture for AI use cases, including delegated and service-to-service access, API gateway/BFF token flows, scoped credentials, and governance alignment. You will design and validate OAuth/OIDC patterns (Auth Code + PKCE, OBO, token exchange, client credentials) across identity providers (PingOne AIC, Entra ID), gateways, and agent platforms. The AI IAM Architect partners across AI/platform engineering, IAM, security, and enterprise architecture to define reusable, secure, and production-ready identity standards for agents.

Key Responsibilities:

  • Discover AI/agent identity requirements across users, services, runtimes, tools, and APIs.

  • Assess existing SSO, MFA, federation, and API authorization models; identify gaps in delegation, token lifecycle, scopes, secrets, and auditability.

  • Design enterprise IAM patterns (user context propagation, delegation chains, BFF sessions, least-privilege access) and OAuth/OIDC client models.

  • Define standards for securing agent tools, data access, and cross-domain integrations; align to zero trust and regulatory controls.

  • Produce architecture artifacts (CAD/HLD/PSS) and reference implementations.

  • Lead and build IAM POCs (end-to-end flows, token exchange, gateway enforcement, delegated agent access).

  • Configure/test identity flows; troubleshoot tokens, scopes, and integrations.

  • Implement or guide IAM integrations across gateways, BFFs, agent orchestration, and observability.

  • Transition validated patterns to IAM engineering for production rollout.

  • Define agent identity lifecycle (registration, credential rotation, revocation, environment separation).

  • Integrate IAM across AI platform components; support CI/CD and IaC for IAM configurations.

  • Establish patterns for human-in-the-loop controls, break-glass access, and rate limiting.

  • Maintain documentation, decision records, diagrams, and runbooks.

  • Deliver POC summaries, evaluations, and implementation guidance; communicate risks and dependencies.

  • Ensure regulatory compliance; partner on threat modeling and controls (secrets, PAM, audit evidence).

  • Serve as IAM SME for AI initiatives; mentor engineers.

  • Deliver production-ready IAM patterns and reduce identity risk across AI workloads.

Requirements:

  • 10+ years in IAM, security architecture, or platform engineering with significant IAM scope.

  • 2+ years building IAM POCs and troubleshooting OAuth 2.0 / OIDC flows (Auth Code + PKCE, refresh tokens, client credentials, token exchange, OBO).

  • 2+ years with PingOne AIC and/or Microsoft Entra ID.

Core Competencies:

  • Hands-on experience designing identity for APIs, microservices, and BFF architectures.

  • Experience integrating IAM with API gateways, AI/ML platforms, and modern application stacks.

  • Strong knowledge of SAML, OAuth, OIDC, JWT, scopes, and authorization patterns.

  • Familiarity with agent/tool identity models and secure integration patterns.

  • Ability to translate AI requirements into secure identity designs; strong communication skills.

Preferences:

  • Experience delivering AI/ML agents or copilots to production.

  • Experience with SailPoint, CyberArk/Delinea, or Auth0/CIAM.

  • Knowledge of AI-aware API gateways (e.g., Kong).

  • Experience with IAM modernization or M&A programs.

  • Relevant certifications (CISSP, CCSP, Entra, Ping, SailPoint, AWS).

  • Familiarity with zero trust and identity threat detection.


Pay Range:

$153,470.00 - $255,749.00
 Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!
 

About LPL Financial Holdings, Inc.

LPL Financial Holdings, Inc. Careers

Joining LPL Financial Holdings, Inc. presents an unparalleled opportunity to become part of a leading team of professionals in the financial services industry. The company is renowned for its commitment to innovation, leadership, and professional growth, making it an ideal workplace for ambitious individuals looking to advance their careers.

Explore Job Opportunities

LPL Financial Holdings, Inc. offers a variety of job opportunities that cater to a range of skills and interests. From entry-level positions to senior leadership roles, each job opening provides a platform for personal and professional development. Candidates can expect a rigorous interview process that ensures each team member is not only a fit for the position but also aligns with the company's culture of excellence and integrity.

Internship Programs

For those starting their career journey, LPL Financial Holdings, Inc. provides robust internship programs designed to offer real-world experience in the financial sector. Internships are a cornerstone of the company's commitment to nurturing young talent, providing a foundation of knowledge and skills that are crucial for future employment in the industry.

Commitment to Diversity and Inclusion

Diversity and inclusion are at the heart of LPL Financial Holdings, Inc. The company believes in empowering all employees through diversity training and leadership opportunities that promote an inclusive workplace. This approach not only enhances team collaboration but also drives innovation and creativity.

Benefits and Culture

LPL Financial Holdings, Inc. is dedicated to supporting its employees with comprehensive benefits designed to promote a healthy work-life balance. Benefits include competitive health care options, retirement plans, and wellness programs. The company culture is built on a foundation of mutual respect and teamwork, encouraging networking and professional development across all levels of the organization.

Professional Growth and Development

Employees at LPL Financial Holdings, Inc. are encouraged to continuously enhance their professional skills and advance their careers within the company. Leadership development programs and continuous learning opportunities are readily available, allowing individuals to achieve their career goals and contribute effectively to their teams.

Join the LPL Financial Holdings, Inc. Team

LPL Financial Holdings, Inc. is actively hiring and looking for passionate, creative, and solution-driven team players. Explore open positions that match your skills and interests on the LPL Financial Holdings, Inc. careers page. Each position offers a chance to be part of a dynamic team that is instrumental in shaping the future of financial services.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights through the LPL Financial Holdings, Inc. careers blog. Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at LPL Financial Holdings, Inc.

SEARCH LPL FINANCIAL HOLDINGS, INC. JOBS

READ CAREERS BLOG

JOB ALERT EMAILS

Embark on a career path that fosters growth, embraces diversity, and rewards innovation. LPL Financial Holdings, Inc. is not just a company—it's a place where you can make a difference.
Learn more about LPL Financial Holdings, Inc.

Similar Jobs

More Jobs at LPL Financial Holdings, Inc.

More Information Technology Jobs

Find similar AI IAM Architect jobs: