About this Senior AI Identity Platform Engineer role at LTS
Location: United States - Remote
Clearance: Ability to obtain and maintain a Public Trust
LTS is seeking a Senior AI Identity Platform Engineer to design and build the identity foundation that enables AI agents, enterprise applications, cloud services, and users to interact securely and intelligently. You'll establish authentication, authorization, credential management, and identity services that allow autonomous AI systems to operate safely across enterprise environments.
The Agentic AI platform is designed to help engineers understand, analyze, and modernize one of the most consequential legacy software systems still operating today.
Our platform enables engineers to ask questions in plain English and receive explainable, verifiable answers traced directly back to decades of production source code. Rather than replacing engineers, we're building AI that accelerates engineering through transparency, traceability, and intelligent reasoning.
We're building an AI-native engineering platform supporting the modernization of mission-critical healthcare systems serving millions of Veterans nationwide.
The platform is designed for deployment across federal enterprise environments and is being engineered to align with FedRAMP security controls, Zero Trust principles, and federal compliance requirements.
The product has executive sponsorship, committed users, and a customer investing in long-term modernization. Our engineering team is intentionally small, giving every engineer meaningful ownership and direct influence over product direction.
We don't simply build AI-powered software, we build software with AI. This is not another chatbot.
Using LLMs, AI agents, secure identity architectures, and AI-assisted development is simply how we engineer.
What You’ll Do:
Design AI Identity Architecture
- Design identity services supporting autonomous and multi-agent AI systems.
- Establish secure identities for AI agents, enterprise services, users, and external integrations.
- Define identity lifecycles for AI agents, including provisioning, credential management, rotation, and decommissioning.
- Build reusable identity capabilities that scale across the AI platform.
Authentication & Authorization
- Design and implement modern authentication and authorization frameworks for AI agents and platform services.
- Implement OAuth 2.0, OpenID Connect (OIDC), JWT, service principals, mutual TLS (mTLS), and delegated authorization models.
- Apply least-privilege and Zero Trust principles throughout AI workflows.
- Build fine-grained authorization models controlling AI access to enterprise data, APIs, tools, and services.
Enterprise Identity Integration
- Integrate AI platforms with enterprise identity providers such as Microsoft Entra ID, Okta, Active Directory, and other IAM solutions.
- Enable secure identity federation across cloud and on-premises environments.
- Design secure service-to-service authentication supporting distributed AI architectures.
- Collaborate with enterprise security teams to align AI identity with organizational security standards.
Secure Agent & Tool Access
- Design secure frameworks governing how AI agents discover, authenticate to, and invoke enterprise APIs, databases, and external tools.
- Build authorization models controlling agent capabilities and delegated permissions.
- Protect sensitive enterprise resources through policy-driven access controls.
- Implement secure credential handling and secrets management across AI workflows.
Platform Engineering
- Develop reusable identity services, SDKs, APIs, and libraries supporting secure AI application development.
- Automate identity provisioning, credential lifecycle management, and authorization policies.
- Improve developer productivity through standardized identity services and secure engineering patterns.
- Partner with platform engineers to integrate identity services into the AI platform architecture.
Governance & Auditability
- Ensure every AI action is authenticated, authorized, attributable, and auditable.
- Implement identity-aware logging, traceability, and policy enforcement.
- Support compliance and governance requirements for highly regulated environments.
- Partner closely with AI Security Engineers to establish secure-by-design AI development practices.
What We’re Looking For:
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, or a related technical discipline (or equivalent professional experience).
- 7+ years of software engineering, platform engineering, identity engineering, or cloud security experience.
- Experience designing authentication and authorization architectures for enterprise applications.
- Strong knowledge of OAuth 2.0, OpenID Connect (OIDC), JWT, SAML, PKI, and modern identity protocols.
- Experience integrating enterprise identity providers such as Microsoft Entra ID, Okta, Active Directory, or similar IAM platforms.
- Experience building secure REST APIs, microservices, and distributed systems.
- Knowledge of Zero Trust Architecture, RBAC, ABAC, delegated authorization, and identity federation.
- Experience with cloud platforms (Azure, AWS, or Google Cloud).
- Strong programming skills in Python plus experience with Go, Java, or TypeScript.
- Excellent communication, analytical, and problem-solving skills.
- Experience designing secure systems that enable innovation rather than restrict it.
- Expertise in identity and access management.
- Hands-on experience with cloud-native architecture and modern authentication frameworks.
- Strong ability to stay current with emerging AI technologies and evolving identity standards.
- Ability to collaborate effectively across software engineering, security, and AI disciplines.
- Willing and able to take ownership of difficult technical challenges and build elegant, innovative solutions.
Nice to Have:
- Experience developing AI platforms, Agentic AI systems, or Large Language Model (LLM) applications.
- Experience securing Retrieval-Augmented Generation (RAG) systems and AI tool integrations.
- Familiarity with Model Context Protocol (MCP) and secure AI tool invocation.
- Experience with HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, or similar secrets management platforms.
- Experience implementing identity services in Kubernetes and cloud-native environments.
- Experience with AI governance, Responsible AI, or AI platform security.
- Familiarity with LangGraph, LangChain, CrewAI, Semantic Kernel, AutoGen, or similar AI orchestration frameworks.
- Experience supporting Federal Government or healthcare environments.
- Identity or cloud certifications such as Microsoft Identity and Access Administrator, CISSP, Security+, CCSP, or cloud security certifications are a plus.
What’s In It for You?
- The Opportunity to support high-visibility federal missions
- A culture that values innovation, growth, and collaboration
- Access to cutting-edge tools and technologies
- Comprehensive benefits for you and your family
- A career path that rewards ambition and performance
If you’re ready to push boundaries, sharpen your skills, and join a team that is passionate about building what’s next, we’d love to meet you. Apply today and let’s build a future together!
LTS shares salary ranges to promote transparency. Compensation ranges are provided for informational purposes, and final compensation may vary based on experience, skills, location, and role requirements.
LTS is committed to offering eligible employees comprehensive benefits that will provide them with options intended to meet their needs and the needs of their family.