Demo

Security Engineer / Architect Identity, Authorization & Platform Security

Cyber Resource Provider LLC
Denver, CO Contractor | Full Time | Part Time
POSTED ON 9/25/2026
AVAILABLE BEFORE 10/25/2026

Security Engineer / Architect Identity, Authorization & Platform Security

Location: Denver, CO 100% Onsite

Job Type: Contract

Duration: Contract / Long-Term Engagement

Position Overview

We are seeking a hands-on Security Engineer / Architect to design, build, and implement a unified, policy-driven security layer across the platform.

The primary focus will be on Identity & Access Management (IAM), RBAC, authorization, cloud security, secrets management, vulnerability management, security telemetry, SIEM integration, and platform security.

This is a builder's role, requiring strong hands-on engineering experience. The selected candidate will own the architecture, deliver reference implementations, establish security standards, and work closely with engineering teams to implement production-ready security solutions.

Key Responsibilities

Identity & Access Management / RBAC

  • Design a canonical identity, entitlement, and role model across infrastructure, cloud IAM, applications, containers, and other downstream systems.
  • Implement identity federation using OIDC, SAML, OAuth2, and standards-based provisioning.
  • Build automated user/group/role provisioning and lifecycle management.
  • Implement access recertification and governance processes.
  • Design and implement Just-in-Time (JIT) and least-privilege access using short-lived credentials and on-demand elevation.
  • Establish SSO and API authentication across services.
  • Implement consistent organization and tenant isolation across identity and downstream platforms.

Authorization & Policy Engineering

  • Design and implement centralized authorization using RBAC, ABAC, and/or ReBAC models.
  • Implement an externalized policy-decision engine and manage policies as code.
  • Define fine-grained authorization boundaries for users, applications, agents, services, and tools.
  • Implement OAuth2/OIDC concepts including scopes, audiences, token exchange, JWTs, and audience restriction.
  • Address authorization risks such as confused-deputy scenarios and inappropriate token passthrough.

AI Agent & Tool Security

  • Design authorization models for AI agents and automated tool invocation.
  • Establish agent workload identities and delegated authorization.
  • Implement per-agent cryptographic identities and on-behalf-of authorization.
  • Define tool-level permissions based on users, agents, tenants, resources, and actions.
  • Implement human-in-the-loop approval workflows for sensitive operations.
  • Maintain complete, tamper-evident audit trails for agent and tool activity.
  • Apply security controls against prompt injection and unauthorized tool execution.

Secrets & Cloud Security

  • Implement centralized secrets management and automated credential rotation.
  • Design secure cloud IAM architectures and least-privilege access.
  • Implement secure credential management for applications, workloads, agents, and infrastructure.
  • Support secure execution environments and sandboxing for sensitive tool calls.

Vulnerability Management

  • Implement continuous vulnerability scanning across:
    • Edge compute nodes
    • Containers and container images
    • Operating systems
    • Application dependencies
    • Container-orchestration platforms
    • Third-party libraries
    • Device firmware where applicable
  • Implement SBOM generation, tracking, and vulnerability correlation.
  • Correlate CVEs with asset exposure and exploitability.
  • Develop risk-based vulnerability prioritization and remediation workflows.
  • Build operational and executive vulnerability dashboards.
  • Integrate vulnerability findings with event platforms and ticketing workflows.

Security Telemetry & SIEM

  • Deploy security telemetry capabilities across edge environments.
  • Capture authentication, authorization, process execution, network connections, file integrity, configuration changes, secret access, and agent/tool activity.
  • Normalize security events into a common schema.
  • Integrate security telemetry with centralized SIEM platforms.
  • Implement store-and-forward capabilities for intermittently connected edge environments.
  • Design bandwidth-aware event batching and reliable event delivery.
  • Implement tamper-evident and mutually authenticated telemetry pipelines.
  • Maintain tenant isolation throughout the telemetry pipeline.
  • Develop SIEM detection and correlation rules that associate security events with verified identities.
  • Route actionable security alerts into event buses and on-call workflows.

Platform Security Integration

  • Establish security standards for event-platform authentication and authorization.
  • Implement message signing and secure service-to-service communication.
  • Support edge-device identity, mTLS, PKI, and certificate lifecycle management.
  • Integrate security controls into CI/CD pipelines.
  • Implement security gates including artifact signing, IaC scanning, and automated security validation.
  • Partner with engineering teams to establish reusable security primitives and standards.

Required Qualifications

  • 8 years of experience in security engineering.
  • 3 years of experience architecting and implementing Identity & Access Management at scale.
  • Strong hands-on experience with enterprise Identity Providers and identity federation.
  • Deep knowledge of OAuth2, OIDC, SAML, JWT, SSO, and standards-based provisioning.
  • Experience mapping federated identities to downstream authorization models.
  • Strong understanding of OAuth2/OIDC scopes, audiences, token exchange, and audience restrictions.
  • Hands-on experience implementing RBAC and at least one of ABAC or ReBAC.
  • Experience with externalized authorization/policy engines.
  • Strong cloud IAM experience.
  • Hands-on experience with centralized secrets management and automated credential rotation.
  • Experience with containers and container orchestration.
  • Ability to develop production-quality code and implement security solutions hands-on.
  • Demonstrated experience implementing least-privilege and Just-in-Time access.
  • Experience building fully auditable access-control systems.

Preferred Qualifications

  • Experience securing AI agents, LLM applications, and automated tool-invocation interfaces.
  • Knowledge of prompt-injection and AI tool-boundary security.
  • Experience with workload identity and machine-to-machine authentication.
  • Experience building security telemetry pipelines and SIEM integrations.
  • Experience with vulnerability-management programs, SBOM tools, CVE correlation, and risk prioritization.
  • Experience securing edge, IoT, or intermittently connected environments.
  • Experience with lightweight host-based security telemetry agents.
  • Knowledge of Zero Trust architecture.
  • Experience with PKI, mTLS, certificate lifecycle management, and device attestation.
  • Experience with event-driven security architectures.
  • Experience implementing secure CI/CD and automated security gates.
  • Security architecture certifications are a plus but not required.

Salary.com Estimation for Security Engineer / Architect Identity, Authorization & Platform Security in Denver, CO
$118,540 to $148,179
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Engineer / Architect Identity, Authorization & Platform Security?

Sign up to receive alerts about other jobs on the Security Engineer / Architect Identity, Authorization & Platform Security career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cyber Resource Provider LLC

  • Cyber Resource Provider LLC Atlanta, GA
  • Job Summary (paragraph or summarized statement about the position): Under broad supervision, configures, customizes, enhances, and supports the Ivanti Neur... more
  • 1 Day Ago

  • Cyber Resource Provider LLC Washington, DC
  • SharePoint Applications Developer Washington, DC - Hybrid- 2 days remote Per Federal contract U.S. citizenship is required Must be able to Pass federal bac... more
  • 2 Days Ago

  • Cyber Resource Provider LLC Richmond, IN
  • A Day in the Life: The essential functions of this role are as follows: Administer initial and annual psychological assessments for all patients. Perform p... more
  • 2 Days Ago

  • Cyber Resource Provider LLC Richmond, VA
  • VDOT Senior Network Engineer - 812112 Job Title: Senior Network Engineer Job ID: 812112 Client: VDOT Location: 9120 Lockwood Boulevard, Richmond, Virginia ... more
  • 2 Days Ago


Not the job you're looking for? Here are some other Security Engineer / Architect Identity, Authorization & Platform Security jobs in the Denver, CO area that may be a better fit.

  • Janus Henderson Investors Denver, CO
  • Why work for us? A career at Janus Henderson is more than a job, it’s about investing in a brighter future together . Our Mission at Janus Henderson is to ... more
  • 9 Days Ago

  • trueanomalyinc Denver, CO
  • Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. OUR MISSION True Anomaly deli... more
  • 8 Days Ago

AI Assistant is available now!

Feel free to start your new journey!