- Location
- HQ_Baltimore MD Management Office, United States of America
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Master
- Source
- Workday
Description
Key Responsibilities
- Design and implement security controls that protect AI agents, machine identities, service accounts, and other non-human identities.
- Support governance frameworks and security controls for AI-enabled technologies, agentic workflows, and Model Context Protocol (MCP) integrations.
- Develop and enhance privileged access management capabilities that provide strong authentication, authorization, and access governance controls.
- Partner with cybersecurity architecture, infrastructure, engineering, and platform teams to embed security controls into enterprise technology solutions.
- Design and implement automated access certification, approval, attestation, monitoring, and audit workflows.
- Maintain comprehensive audit trails and control evidence supporting regulatory, risk, governance, and compliance requirements.
- Analyze emerging risks associated with AI technologies and recommend appropriate security controls and mitigation strategies.
- Contribute to security architecture reviews and provide technical guidance on identity security best practices.
- Support continuous improvement initiatives focused on automation, operational efficiency, and risk reduction.
- Share knowledge and mentor less experienced team members while contributing to team objectives and security program maturity.
Required Qualifications:
- Experience integrating IAM platforms such as Entra ID, Okta, CyberArk, or similar technologies into modern application architectures and cloud-based platforms.
- Demonstrated experience designing and implementing security controls that protect agentic AI solutions, machine identities, service accounts, API integrations, and other non-human identities including named ownership, scoped permissions, short-lived credentials, approval workflows, human-in-the-loop escalation, logging, monitoring, and access review requirements.
- Strong hands-on expertise across core IAM capabilities, including SSO, MFA, access lifecycle management, Just in Time (JIT) access, least privilege, and zero standing privileges.
- Ability to evaluate agentic AI and MCP-style integration designs for least privilege, separation of duties, credential handling, connector scope, data access boundaries, and operational auditability across on-premises and cloud security architectures in AWS and Azure environments.
- Ability to independently analyze complex security problems and deliver well-reasoned, effective solutions.
- Proven ability to collaborate with cross functional engineering and business partners and influence outcomes through expertise.
- Strong written and verbal communication skills, with the ability to document and explain security concepts to technical and non-technical audiences.
Preferred Qualifications
- Industry certifications such as CISSP, CCSP, CIAM, or comparable identity and cybersecurity certifications.
- Experience working within a highly regulated environment, with an understanding of how regulatory, risk, and compliance expectations influence security operations.
- Experience with identity security posture management, non-human identity governance, privileged access management, access graph or entitlement analytics, and AI agent security tooling.
Experience Requirements:
- Bachelor’s degree in Computer Science, Engineering, Information Security, or a related technical discipline.
- Minimum of 5 years of experience in the Cybersecurity field
OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.