Principal IAM AI Engineer

American Express Global Business Travel
•$104,300 - $193,700•Onsite

About The Position

Amex GBT is seeking a Principal IAM AI Engineer who brings an AI-first mindset rather than a traditional security-first lens to identity architecture. This role sits at the intersection of IAM, AI/agentic systems, and product thinking, for someone who's as comfortable designing a scalable access model for AI agents as they are challenging why a control exists in the first place. It also sits at the intersection of engineering, risk management, and the technical realities of running global travel technology: booking platforms, payment flows, traveler data protection, and extensive supplier integrations. We need someone who can look at how AI agents, copilots, and autonomous workflows are being adopted across the business, understand the actual product and business intent behind them, and build security and identity architecture that enables adoption safely rather than just implementing it. This is a technical and hands-on engineering position where you will construct the authentication and authorization infrastructure, credential management systems, and compliance frameworks that enable responsible AI deployment across the organization. Additionally, you will lead a technical team to maintain, expand, and evolve these capabilities. You will be integrated into AI initiative planning from inception, ensuring identity, access controls, and secrets management are embedded in the architecture from day one rather than implemented after deployment.

Requirements

  • Deep expertise in enterprise identity infrastructure: PAM (CyberArk or equivalent), Okta as IdP, and IGA platforms like Saviynt, including extending governance beyond human identities.
  • Strong AWS and cloud identity skills: IAM design, ephemeral credentials, OIDC federation, secrets/certificate management, and least-privilege at scale.
  • Mastery of core identity standards (OAuth, OIDC, SAML, SCIM, JWT, mTLS) and machine-to-machine/workload identity across on-prem, hybrid, and multi-cloud environments.
  • Proven ability to architect enterprise-scale identity security programs and govern non-human identities (inventory, ownership, certification, credential rotation, risk).
  • Strong cross-functional leadership and communication skills, with sound judgment for operating in an emerging, still-being-defined discipline.
  • 8+ years in IAM/cybersecurity, with 5+ years at architect or principal level owning target-state design for an enterprise security or identity domain.
  • Proven experience designing identity, access, and governance controls for non-human identities — service accounts, workload identities, and AI agents — at enterprise scale.
  • Strong AWS (or equivalent public cloud) identity and access design experience at multi-account scale.
  • Hands-on experience with Okta (or comparable access management/federation platform) and Saviynt (or comparable IGA platform).
  • Experience with privileged access management platforms such as Idira (formerly CyberArk) and HashiCorp Vault, or comparable tools.

Nice To Haves

  • Identity Threat Detection and Response (ITDR) and posture management
  • Experience with SPIFFE/SPIRE or service mesh identity patterns
  • Knowledge of emerging AI regulation and frameworks
  • Externalized authorization and policy orchestration expertise
  • Experience with Model Context Protocol (MCP) and agent-to-agent patterns
  • Kubernetes and container security with workload identity
  • Automation ability in Python, PowerShell or Terraform
  • Relevant certifications: CISSP, CISM, CCSP, CyberArk, Okta, AWS Security, or architecture certifications

Responsibilities

  • Deploy and automate identity controls at runtime for NHI identity — including immediate authentication verification, access authorization, and real-time rule application across the environment.
  • Build, deploy, and automate lifecycle governance for agents and machine identities — spanning discovery and registration, permission assignment, credential lifecycle, periodic access reviews, and secure retirement.
  • Construct and operationalize credential management systems for AI-driven applications and agents, encompassing automated secret cycling, short-lived credential issuance, and protected distribution to runtime environments.
  • Establish and implement fine-grained, zero-standing-privilege access models for agents and workloads, documented and managed through infrastructure-as-code and policy declaration frameworks.
  • Collaborate with application development and ML teams throughout all AI initiative phases, ensuring identity requirements, credential handling, and access controls are incorporated during design rather than retrofitted.
  • Facilitate implementation and adoption of identity governance controls for human users as required by organizational standards.
  • Work with compliance, risk and audit functions to confirm controls align with regulatory requirements and internal policies; facilitate audit evidence generation and regulatory reporting.
  • Lead an engineering team supporting these initiatives; establish technical direction, strategic priorities and delivery roadmap for machine identity and agent IAM programs.
  • Serve as a trusted advisor to senior leadership on machine and AI identity risk, and translate it into funded, sequenced remediation.
  • Partner with InfoSec and AI Security teams on proof-of-concept evaluations and vendor assessments for AI and agent governance platforms.
  • Mentor engineers and architects on non-human and agent identity patterns, and raise the organization’s overall fluency in machine identity security.

Benefits

  • health and welfare insurance plans
  • retirement programs
  • parental leave
  • adoption assistance
  • wellbeing resources
  • travel perks
  • access to over 20,000 courses on our learning platform
  • leadership courses
  • new job openings available to internal candidates first
  • global INclusion Groups
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service