Job Summary:
S&P Global is seeking a Lead Identity Engineer to lead the architecture of their next-generation API security and authorization platforms. The role focuses on building robust Authorization frameworks and API Governance layers to secure enterprise data and enable safe adoption of Generative AI.
Responsibilities:
• Lead the architecture of next-generation API security and authorization platforms.
• Leverage deep expertise in securing APIs and modern authorization standards to architect the Model Context Protocol (MCP) Gateway.
• Focus on building robust Authorization frameworks and API Governance layers that can scale to support complex access patterns of AI agents.
• Drive the transformation of security posture by extending API security controls to the emerging AI ecosystem.
• Architect and govern the MCP Gateway to ensure critical data sources are protected against unauthorized AI access.
• Implement Fine-Grained Authorization (FGA) and context-aware policies to enable safe adoption of Generative AI.
Qualifications:
Required:
• 8+ years of software engineering experience, with at least 5+ years focused on API Security, IAM, or Gateway implementations.
• Bachelor's degree in computer science, Engineering, Data Science, or related technical field
• Deep, hands-on experience with any enterprise API Gateway technology (e.g., Kong, Apigee, AWS API Gateway, Azure API Management). You must understand the lifecycle of an API request from ingress to backend.
• Expert-level knowledge of OAuth 2.0 (Client Credentials, PKCE, Authorization Code), OpenID Connect (OIDC), and API Security standards (OAS, REST, GraphQL security).
• Strong backend coding proficiency in Java or Python. You must be comfortable writing high-performance APIs and micro-services.
• Strong theoretical or practical knowledge of the Model Context Protocol (MCP) specifications. You understand how MCP Servers and Clients interact and how to apply security controls to this new pattern.
• Solid experience working with enterprise Identity Providers like Okta, Microsoft Entra ID (Azure AD)
• Experience integrating security controls into CI/CD pipelines using tools like Jenkins, GitHub Actions, or GitLab.
Company:
S&P Global is a market intelligence company that provides financial information and data analytics services. Founded in 1860, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.