← Back to all jobs

Distinguished Engineer - Non Human & Agentic Identity

Citizens Financial Group · United States · Posted 2026-09-04

Apply on the company site →

Job description

DISTINGUISHED ENGINEER, AGENTIC IDENTITY & NON HUMAN IDENTITY SECURITY Position Summary Your role as Distinguished Engineer is to work with engineering teams and architecture to produce high quality technology solutions that enable Citizens' next generation identity, security, and AI capabilities. You will be given the autonomy to lead, design, and develop innovative solutions addressing some of the most complex challenges facing the banking industry as organizations evolve from human centric identity models toward AI driven, machine driven, and autonomous systems. As a Distinguished Engineer, you will serve as a peer leader and technical visionary responsible for defining and advancing the enterprise strategy for Agentic Identity, Non Human Identities (NHIs), machine identity governance, and secure AI enabled ecosystems. You will partner across engineering, architecture, security, and product organizations to establish secure identity frameworks that support APIs, workloads, AI agents, service accounts, and emerging autonomous technologies at enterprise scale. The breadth of Citizens operations ensures a diverse set of opportunities to shape the future of identity, security, and AI as the bank continues its transformation toward innovation and customer centric experiences. Responsibilities Technical Leadership & Engineering Excellence • Collaborate with engineering teams and architects to design innovative identity and security solutions that align with enterprise architecture principles and strategic business goals. • Lead the design, development, and implementation of modern software platforms, services, and security capabilities that support enterprise scale digital transformation initiatives. • Serve as a technical leader and trusted advisor across multiple engineering organizations, influencing strategic technology decisions and architectural direction. • Infuse scalability, reliability, resiliency, maintainability, and security into distributed systems and service based architectures. • Promote engineering excellence, innovation, and accountability through mentoring, technical leadership, and thought partnership. • Communicate complex technical concepts effectively to engineers, architects, executives, and business stakeholders. Agentic Identity & Non Human Identity Architecture • Design and champion enterprise architectures for Non Human Identities (NHIs), including AI agents, service accounts, workload identities, machine identities, APIs, autonomous systems, and cloud native workloads. • Define and implement identity security frameworks for AI agents, including authentication, authorization, secrets management, token governance, lifecycle management, and policy enforcement. • Lead the development of secure identity architectures supporting agentic systems across cloud, SaaS, hybrid, and on premises environments. • Establish enterprise standards for machine identity governance, workload identity management, credential security, and privileged access controls. • Design secure authentication and authorization models supporting autonomous interactions between AI agents, applications, APIs, cloud services, and enterprise platforms. • Architect solutions that support continuous authentication and continuous authorization across highly distributed digital ecosystems. • Develop scalable identity strategies for machine to machine communications, API interactions, workload identities, service meshes, and microservices architectures. • Define governance frameworks that ensure accountability, visibility, auditability, and compliance for AI agents and machine identities operating across the enterprise. • Partner with engineering and architecture teams to secure emerging identity patterns associated with AI agents, autonomous workflows, and non human actors. Modern Identity & Access Management • Design and implement identity solutions leveraging OAuth 2.0, OpenID Connect (OIDC), token based security, API authorization frameworks, and modern identity standards. • Establish secure identity patterns for cloud native applications, distributed systems, APIs, microservices, and SaaS platforms. • Strengthen enterprise identity controls through least privilege access, workload identity governance, privileged access management, credential management, and authorization policy design. • Drive innovation in identity security to address evolving risks associated with machine identities, AI systems, non human accounts, and autonomous technologies. Risk Management & Security Strategy • Identify, assess, and mitigate risks associated with credential compromise, excessive privileges, unmanaged machine identities, orphaned service accounts, and unauthorized agent activity. • Collaborate with governance, risk, compliance, and security teams to align identity strategies with regulatory requirements and enterprise risk objectives. • Evaluate emerging technologies, industry trends, and market developments related to identity, AI, machine identity governance, and autonomous systems. • Influence long term enterprise strategy for identity security, agentic identity, and next generation access management capabilities. Required Qualifications • 10+ years of hands on software engineering, platform engineering, identity engineering, security engineering, or related technical experience. • Deep expertise in Identity and Access Management (IAM), Customer Identity and Access Management (CIAM), Non Human Identity (NHI), machine identity, workload identity, privileged access management, or related disciplines. • Demonstrated expertise designing and implementing modern authentication and authorization architectures using OAuth 2.0, OpenID Connect (OIDC), token based security models, and API security frameworks. • Experience securing machine identities, service accounts, workload identities, cloud native platforms, APIs, and distributed application ecosystems. • Strong understanding of modern cloud architectures and identity c