IAM Engineer - AI Security
Amex GBT · India
Free to search · AI fit score against your CV · tailor your résumé in one click
Amex GBT · India
Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. We need an IAM engineer who doesn't think like a traditional security engineer. This role sits at the intersection of IAM, AI/agentic systems, and product thinking, for someone who's as comfortable designing a scalable access model for AI agents as they are challenging why a control exists in the first place. We need someone who can look at how AI agents, copilots, and autonomous workflows are being adopted across the business, understand the actual product and business intent behind them, and build security and identity architecture that enables adoption safely rather than just implementing it. The IAM Engineer – AI Security's primary responsibilities are to implement security principles within the IAM IGA (Identity Governance & Administration) platform, with a specific focus on securing AI across the enterprise, including AI agents, MCPs, and the non-human identities and access pathways that support them, while maintaining rules and controls, least-privilege safeguards, and aligning GBT IAM policies to protect data and reduce risk. What You'll Do AI Security & Agent Guardrails • Design, implement, and maintain identity and access management solutions that secure AI usage across the organization, including AI agents, MCPs, service accounts, and applications, ensuring secure authentication and authorization across enterprise infrastructure. • Support the discovery, inventory, and governance of non-human identities and machine access used by AI agents and automated systems, including identifying unsanctioned or "shadow" AI usage. • Partner with security architecture and InfoSec teams to evaluate and deploy AI-aware access controls, including runtime authorization, contextual access boundaries, and data loss prevention for AI-driven workflows. • Support the evaluation and rollout of intent-aware authorization capabilities that assess AI agent behaviour against intended use before granting access to backend systems and data. • Contribute to the organization's transition of AI and machine workloads away from static credentials toward modern, credential-less authentication models (e.g., federated identity, token exchange, ephemeral credentials). • Implement and maintain security controls over Model Context Protocol (MCP) and similar model-connectivity integrations, ensuring safe data access, fail-closed behaviour, and least-privilege data boundaries. • Partner with InfoSec and AI Security teams on proof-of-concept evaluations and vendor assessments for AI and agent governance platforms. • Identify and assess security risks associated with AI adoption (e.g., unsanctioned AI usage, credential misuse, unintended agent behaviour); implement mitigation strategies and ensure compliance with industry regulations and emerging AI governance frameworks. • Support AI-assisted automation for IAM operations, including access request triage, entitlement anomaly detection, and audit evidence collection. • Assist the implementation of remediation processes for AI related risks and issues at stages of discovery, ownership assignment, and tracking. • Investigate and respond to security incidents involving AI systems and the identities and access tied to them. Core IAM & Governance • Design, implement, and manage IGA platform solutions (e.g., Saviynt) to ensure effective access controls, identity lifecycle management, and compliance; handle user provisioning, de-provisioning, and account modifications. • Configure and deploy IGA modules and connectors for various applications, platforms, and systems. • Execute access certification and review campaigns; perform entitlement clean-up and configure segregation-of-duties (SOD) rules. • Establish monitoring mechanisms for IAM activities and generate regular reports for audit and compliance purposes. • Work closely with customers and internal stakeholders to understand business requirements and translate them into IAM and AI security solutions. • Collaborate with other IAM team members, contributing to system support and knowledge sharing. • Execute reports and capture data for metrics; assist with tracking and producing IAM and AI governance KPIs. What We're Looking For • Minimum 5 years of professional, hands-on experience in IAM, including experience with an IGA platform (e.g., Saviynt, SailPoint IdentityNow/IdentityIQ, Oracle Identity Manager, or similar). • Working knowledge of AI agent and non-human identity governance concepts: discovery, credential lifecycle management, runtime authorization, intent/behavioural validation, and AI-specific compliance frameworks. • Familiarity with modern authentication protocols and credential-less architectures, federated identity, short-lived/ephemeral tokens, and workload identity models. • Exposure to Model Context Protocol (MCP) or similar machine/model connectivity standards is a plus. • Hands-on experience onboarding connected and disconnected applications, including request forms, dynamic attributes, mapping, and data types. • Hands-on experience with REST & SOAP connectors, including JSON building, mapping, reconciliation, and provisioning use cases. • General understanding of Single Sign-On, Multi-Factor Authentication (MFA), and Privileged Access Management (PAM) & cloud technologies and tools. • Familiarity with industry regulations and standards (e.g., SOC2, ISO, SOX, PCI) and emerging AI governance frameworks. • Ex