
Security & Identity Engineer
Posted 22 hours ago

Posted 22 hours ago
This is a fully remote position, open to applicants in United States.
• Collaborate with an external software development organization as a member of Inviso’s delivery team.
• Engage closely with client product, engineering, security, and business stakeholders.
• Assist in the design, security, and delivery of the foundational elements of an enterprise AI platform.
• Conduct threat modeling and implement findings into architecture, engineering, and delivery strategies.
• Develop and evaluate tenant isolation across control plane, data plane, application, and infrastructure boundaries.
• Establish identity, authorization, delegated access, token exchange, service identity, and least-privilege principles.
• Secure systems that execute untrusted content, code, tools, or agent actions.
• Promote secure CI/CD practices, including secrets management, scanning, policy enforcement, and secure release controls.
• Facilitate compliance-by-design through controls, evidence, data handling, and security documentation.
• Offer practical security guidance that balances security, speed, reliability, and business value.
• Assist client teams in deploying reliable, compliant, and secure platform capabilities.
• Elevate the security standards while empowering delivery teams to progress swiftly and responsibly.
• Be open to occasional travel based on client requirements.
• Proven experience in designing and securing production software platforms, preferably within multi-tenant or regulated environments.
• Strong knowledge of authentication, authorization, delegated access, token exchange, service identity, and least-privilege access patterns.
• Experience in defining or contributing to platform threat models and applying them to architecture, engineering, and delivery strategies.
• Capability to design and assess tenant isolation models across control plane, data plane, application, and infrastructure boundaries.
• Experience in securing systems that run untrusted content, code, tools, or agent actions.
• Familiarity with secure CI/CD practices including secrets management, scanning, policy enforcement, and secure release controls.
• Ability to support compliance-by-design methodologies including controls, evidence, data handling, and security documentation.
• Excellent communication skills and the capacity to collaborate with engineers, product leaders, client stakeholders, and customer security teams.
• Practical judgment with the ability to balance security, speed, reliability, and business value.
• Interest in responsible AI, secure AI systems, and controls for model, agent, and tool-based workflows.
• Experience in designing authentication and authorization mechanisms for a multi-tenant SaaS or platform environment.
• In-depth familiarity with OAuth, OIDC, SAML, Entra ID, cloud IAM, or similar identity technologies.
• Knowledge of compliance frameworks such as SOC 2, ISO 27001, GDPR, or similar standards.
• Experience securing AI, LLM, RAG, agentic, or tool-calling systems.
• Familiarity with enterprise-scale software, regulated delivery environments, or mission-critical systems.
• Experience utilizing AI-assisted development tools while maintaining rigorous review and security discipline.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• 401(k) plan with company matching.
• Annual training reimbursement.
• Paid time off.
• Paid holidays.
• Additional perks aimed at supporting well-being and long-term success.
VAILEXA
EverCommerce
NatWest Group
Inviso
Get handpicked remote jobs straight to your inbox weekly.