Identity Access Management & AI Governance Engineer Sr. at Cirrus
Worldwide
$9149.346k - $1372.402k
<p style="margin-right: 1.0in;"><strong><span>Job Summary</span></strong></p> <p style="text-align: justify;"><span>This position is responsible for the development and operation of our hybrid identity infrastructure (Microsoft Entra ID and Active Directory) and the security governance of enterprise AI tools. You will configure authentication, access policies, and data protection standards to ensure that AI applications (such as Microsoft Copilot and custom LLMs) are accessed securely and interact only with authorized data. </span></p> <p><strong><span style="color: black;">Duties and Responsibilities/Essential Functions</span></strong></p> <ul> <li style="text-align: justify;"><span>Identity Infrastructure & Access Control</span></li> <li style="text-align: justify;"><span>Core IAM Operations: Manage and maintain Microsoft Entra ID (Azure AD) and on-premise Active Directory, including connect health, schema extensions, and trust relationships.<span> </span>Development of auditing and reporting to business partners and stakeholders.</span></li> <li style="text-align: justify;"><span>Conditional Access: Design and enforce Conditional Access policies that specifically target high-risk sign-ins and restrict access to AI platforms based on device compliance and user location.</span></li> <li style="text-align: justify;"><span>SSO & Federation: Configure Enterprise Applications and SAML/OIDC integrations, ensuring strict authentication standards for third-party AI tools and SaaS platforms.</span></li> <li style="text-align: justify;"><span>AI Security Governance & Data Protection</span></li> <li style="text-align: justify;"><span>AI Access Governance: Implement entitlement management and access reviews to strictly control which users and groups have access to generative AI tools (e.g., Microsoft Copilot, ChatGPT Enterprise).</span></li> <li style="text-align: justify;"><span>Non-Human Identity Management: Secure and govern Service Principals, Managed Identities, and API tokens used by AI agents and automated workflows to prevent unauthorized privilege escalation.</span></li> <li style="text-align: justify;"><span>Data Labeling (Purview): Configure Microsoft Purview sensitivity labels and Data Loss Prevention (DLP) policies to prevent AI tools from ingesting or surfacing Restricted/Confidential internal data.</span></li> <li style="text-align: justify;"><span>Privileged Access & Monitoring</span></li> <li style="text-align: justify;"><span>Privileged Identity Management (PIM): Enforce Just-In-Time (JIT) access for administrative roles and monitor for unauthorized elevation of privileges related to AI infrastructure.</span></li> <li style="text-align: justify;"><span>Audit & Compliance: Monitor sign-in logs and audit trails for anomalous behavior involving AI applications, ensuring compliance with internal security frameworks.</span></li> <li style="text-align: justify;"><span>Lifecycle Management: Automate provisioning and de-provisioning workflows to ensure immediate revocation of access to AI tools upon employee departure.</span></li> <li style="text-align: justify;"><span>Training and Best practices:</span></li> <li style="text-align: justify;"><span>Coach team members on best practices in identity and access management, fostering a culture of security awareness and compliance</span></li> </ul> <p><strong><span>Qualifications</span></strong></p> <p><span>To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions.</span></p> <ul> <li style="text-align: justify;"><span>Bachelor’s degree in Computer Science, Information Technology or related field; or equivalent combination of education and experience</span></li> <li style="text-align: justify;"><span>IAM Experience: 4+ years of engineering experience with Microsoft Entra ID, Active Directory Domain Services (AD DS), and Group Policy.</span></li> <li style="text-align: justify;"><span>Data Governance: Hands-on experience with Microsoft Purview (Information Protection, Data Lifecycle Management) and DLP.</span></li> <li style="text-align: justify;"><span>AI Security Knowledge: Understanding of how to secure non-human identities (workload identities) and govern access to Large Language Models (LLMs) within an enterprise.</span></li> <li style="text-align: justify;"><span>Technical Skills: Proficiency in PowerShell scripting for automation and Microsoft Graph API.</span></li> <li style="text-align: justify;"><span>Networking: Solid understanding of DNS, DHCP, and VPN as they relate to authentication flows.</span></li> </ul> <p style="text-align: justify;"><strong>Preferred Qualifications </strong></p> <ul> <li style="text-align: justify;"><span>Certifications: SC-300 (Identity and Access Administrator), SC-400 (Information Protection Administrator). </span></li> <li style="text-align: justify;"><span>Experience configuring "Entra Verified ID" or decentralized identity standards. </span></li> <li style="text-align: justify;"><span>Previous experience implementing guardrails for Microsoft 365 Copilot.</span></li> </ul> <p><strong><span>Other Duties</span></strong></p> <p><span>Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position.<span> </span>Duties, responsibilities and activities may change at any time with or without notice.<span> </span>Work beyond 40 hours per week may be required.<span> </span></span></p> <p><span>Cirrus is dedicated to a drug free work environment promoting equal employment opportunity. Qualified applicants will receive consideration for employment without regard to race, sex, national origin, color, age, disability, religion, pregnancy, veteran status, marital and family status, sexual orientation, receipt of public assistance, genetic information or any other characteristic protected by applicable law.</span><strong><span><br /></span></strong></p> <p><strong>Our Benefits</strong>: Cirrus provides a range of exciting benefits, including:<span style="color: black;"> </span><span> </span><em><span style="color: red;"> </span></em></p> <ul> <li><strong>401(k) Plan</strong>: Dollar-for-dollar match up to 5% after 90 days, with 100% vesting.</li> <li><strong>Employer-Paid Coverages</strong>: Group term life, short- and long-term disability insurance.</li> <li><strong>Comprehensive Health Coverage</strong>: Medical, vision, dental, with additional dependent coverage options.</li> <li><strong>Free Health Tracking</strong>: With rewards for meeting health goals.</li> <li><strong>Generous PTO</strong>: 120 hours accrued within the first year.</li> <li><strong>Employee Referral Bonus</strong>: For referring talented candidates.</li> <li><strong>Career Development</strong>: Tuition reimbursement and professional growth opportunities.</li> <li><strong>Exclusive Discounts</strong>: Access to partner and marketplace discounts.</li> <li><strong>Community & Engagement</strong>: Company and employee clubs at various locations.</li> </ul> <p><span style="color: #000000;">These benefits are designed to support your well-being, growth, and enjoyment at Cirrus!</span></p>
Apply Now