Senior Consultant, Strategy, Growth, and Transformation, Identity & Gen AI Engineer
Job Description
What we offer
Join Deloitte in an onsite Senior Consultant role based in Baltimore, MD, where you will shape secure GenAI solutions through identity, access, and governance controls. Collaborate with IAM, security architecture, and data teams to embed strong identity practices into AI delivery and operations, and help establish reusable architectures and reference patterns for scalable security. The compensation range for this position is USD 105,400 to USD 207,800 per year.
What you will do
- Build and integrate generative AI solutions, including LLM applications, retrieval augmented generation, and AI agents, with secure access to data and downstream systems.
- Engineer authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities across enterprise and cloud environments.
- Develop guardrails for agentic workflows, including scoped permissions, least-privilege access, credential and secrets management, and runtime policy enforcement.
- Implement logging, monitoring, and governance that provide traceability and accountability for AI system actions.
- Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.
- Create and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.
What you bring
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a similar technical field
- Ability to work onsite up to 5 days a week
- 3+ years of software engineering experience with Python or a comparable language
- 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as large language model applications, retrieval augmented generation, or AI agents, including use of model APIs, orchestration frameworks, and AI development tools such as Claude Code, OpenAI Codex, GitHub Copilot, or Cursor
- Working knowledge of identity and access management concepts and protocols, including authentication, authorization, single sign-on, and standards such as OpenID Connect, SAML, OAuth, and JSON Web Token
- Ability to travel 15 percent on average based on client needs
- Ability to obtain and maintain the necessary security clearance
- Must be legally authorized to work in the United States without the need for employer sponsorship now or in the future
Technology you will use
- Python, Claude Code, OpenAI Codex, GitHub Copilot, Cursor
- SailPoint, Okta, Microsoft Entra ID
- HashiCorp Vault, CyberArk
- LangChain, LangGraph, Model Context Protocol
- Open Policy Agent, Cedar, OpenFGA
- AWS, Microsoft Azure
- Terraform, Ansible
Benefits
- Discretionary annual incentive program