Key Responsibilities
AI Identity Discovery & Inventory
• Design and operate mechanisms to discover and inventory AI identities, including:
o AI models, agents, and autonomous workflows
o Service accounts, non‑human identities, and API principals used by AI systems
o Identities created dynamically through AI pipelines, orchestration tools, and integrations
• Maintain authoritative visibility into where AI identities exist, what they can access, and how they are used across environments.
• Integrate AI identity discovery into broader identity, asset, and AI Security Posture Management (AI‑SPM) capabilities.
AI Identity Lifecycle Management
• Define and operationalize lifecycle controls for AI identities, including creation, modification, rotation, suspension, and decommissioning.
• Ensure AI identities are created with strong provenance, ownership, and accountability, including linkage to business and technical owners.
• Implement controls to prevent identity sprawl, orphaned AI identities, and unmanaged credentials.
Access Control & Policy Enforcement
• Design and enforce least‑privilege access models for AI identities, aligned with the sensitivity of data, models, and actions performed.
• Partner with IAM and platform teams to implement policy‑based access controls, including role‑based, attribute‑based, and context‑aware authorization for AI systems.
• Ensure AI identities comply with enterprise security standards for authentication strength, credential handling, and key/token management.
Monitoring, Detection & Risk Assessment
• Implement continuous monitoring of AI identity behavior, including access patterns, privilege use, and anomalous activity.
• Detect and investigate identity‑based risks and threats, such as excessive permissions, credential misuse, lateral movement, or abuse of AI agents.
• Leverage telemetry from identity platforms, cloud providers, and AI security tools to assess ongoing AI identity risk.
AI Security Assessments & Control Validation
• Conduct security assessments focused on AI identity usage, including architecture reviews, threat modeling, and control effectiveness testing.
• Validate that AI identity controls are correctly implemented and enforced across development, testing, and production environments.
• Partner with engineering teams to remediate identified gaps and track risk reduction over time.
Governance, Standards & Compliance
• Support development and operationalization of AI identity security standards, patterns, and control requirements, aligned with NIST, ISO, and emerging AI guidance.
• Track regulatory, legal, and industry expectations related to identity, access, and AI accountability.
• Provide evidence, reporting, and metrics to support audits, risk reviews, and governance forums.
Documentation, Reporting & Metrics
• Develop and maintain standard operating procedures (SOPs), design patterns, and runbooks for AI identity security.
• Produce clear reports on AI identity posture, including coverage, risk, and remediation progress.
• Contribute to AI identity KPIs and KRIs, such as unmanaged identities, privilege levels, and anomalous activity trends.
Advisory, Training & Enablement
• Act as a trusted advisor on AI identity security, providing guidance on secure patterns and operational best practices.
• Educate engineering and platform teams on AI identity risks, controls, and monitoring expectations.
• Support internal communities of practice focused on AI security, IAM modernization, and responsible AI adoption.
Research, Experimentation & Continuous Improvement
• Stay current on emerging trends in AI agents, autonomous systems, and non‑human identity security.
• Design and execute proofs of concept (POCs) to evaluate new AI identity security tools, controls, and monitoring approaches.
• Continuously improve AI identity security through automation, integration, and control refinement.