EngineerJobs.io
← Back to all jobs

Job Description

Deloitte offers a collaborative space for engineers to advance identity and Gen AI security by designing, building, and securing generative AI solutions with identity, access, and governance at the core. This onsite role in Washington, DC emphasizes hands-on engineering, secure integration across enterprise and cloud environments, and ongoing enhancements to AI systems. The position carries a competitive compensation range of USD 105,400 to 207,800 per year.

Responsibilities

  • Build and integrate generative AI solutions, including large language model applications, retrieval-augmented generation, and AI agents, ensuring secure access to data and downstream systems.
  • Engineer authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities across enterprise and cloud environments.
  • Develop guardrails for agentic workflows with scoped permissions, least-privilege access, credential and secrets management, and runtime policy enforcement.
  • Establish logging, monitoring, and governance to provide traceability and accountability for AI system actions.
  • Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.
  • Create and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Ability to work onsite up to five days per week.
  • 3+ years of software engineering experience with Python or a comparable language.
  • 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as LLM applications, retrieval-augmented generation, or AI agents, including use of model APIs, orchestration frameworks, and AI development tools (examples include Claude Code, OpenAI Codex, GitHub Copilot, or Cursor).
  • Working knowledge of identity and access management concepts and protocols, including authentication, authorization, single sign-on, and standards such as OpenID Connect, SAML, OAuth, and JWT.
  • Ability to travel approximately 15% based on client needs and project active
  • Ability to obtain and maintain the necessary security clearance.
  • Legally authorized to work in the United States without employer sponsorship now or in the future.

Technologies and Tools

  • Python
  • Claude Code
  • OpenAI Codex
  • GitHub Copilot
  • Cursor
  • LangChain
  • LangGraph
  • Model Context Protocol
  • Open Policy Agent
  • Cedar
  • OpenFGA
  • HashiCorp Vault
  • CyberArk
  • SailPoint
  • Okta
  • Microsoft Entra ID
  • Terraform
  • Ansible
  • AWS
  • Microsoft Azure
  • OpenID Connect
  • SAML
  • OAuth
  • JWT

Similar Jobs