Security & Identity Engineer
This is a remote, client-facing consultant role with Inviso. In this position, you will support an external software development organization as part of Inviso’s delivery team, working closely with client product, engineering, security, and business stakeholders.
The Inviso Security & Identity Engineer is responsible for helping design, secure, and deliver the foundations of an enterprise AI platform used in mission-critical transportation and operational technology environments. This role focuses on threat modeling, tenant isolation, identity, authorization, secure delivery practices, and compliance-by-design.
You will work with client teams to make sure the platform is safe by construction, with security decisions built into the architecture rather than added after the fact. The ideal candidate is hands-on, pragmatic, collaborative, and able to explain complex security concepts clearly to technical and non-technical stakeholders.
This is a 100% remote role, but may require some travel due to client needs.
Experience & Skills Required
- Experience designing and securing production software platforms, preferably in multi-tenant or regulated environments.
- Strong understanding of authentication, authorization, delegated access, token exchange, service identity, and least-privilege access patterns.
- Experience defining or contributing to platform threat models and applying them to architecture, engineering, and delivery decisions.
- Ability to design and review tenant isolation models across control plane, data plane, application, and infrastructure boundaries.
- Experience securing systems that execute untrusted content, code, tools, or agent actions.
- Familiarity with secure CI/CD practices including secrets management, scanning, policy enforcement, and secure release controls.
- Ability to support compliance-by-design practices including controls, evidence, data handling, and security documentation.
- Strong communication skills and ability to partner with engineers, product leaders, client stakeholders, and customer security teams.
- Pragmatic judgment with the ability to balance security, speed, reliability, and business value.
- Interest in responsible AI, secure AI systems, and controls for model, agent, and tool-based workflows.
Desired Qualifications
- Experience designing authentication and authorization for a multi-tenant SaaS or platform environment.
- Deep familiarity with OAuth, OIDC, SAML, Entra ID, cloud IAM, or related identity technologies.
- Experience with SOC 2, ISO 27001, GDPR, or similar compliance frameworks.
- Experience securing AI, LLM, RAG, agentic, or tool-calling systems.
- Experience with enterprise-scale software, regulated delivery environments, or mission-critical systems.
- Experience using AI-assisted development tools while maintaining strong review and security discipline.
Success Criteria
Success in this role is measured by the quality of secure architecture decisions, the strength of tenant isolation and identity patterns, the practicality of security guidance, and the ability to help client teams ship reliable, compliant, and secure platform capabilities. This role is expected to raise the security bar while enabling delivery teams to move quickly and responsibly.
Benefits:
In addition to the base pay, Inviso provides an annual $2,000 training allowance to all of its employees, plus paid time off, paid holidays, and other benefits.
Why Inviso?
- Our Culture & Values are who we are.
- Our commitment to excellence is interwoven with the way we care about our people. Our low attrition rate, high average employee tenure, and the number of people that have been with Inviso for 10, 15, even 20 years, speaks volumes to who we are as a company.
- We are a meritocracy through and through. Those who excel, grow. There is no ceiling, we don’t tolerate politics.
- Inviso has maintained a deep, well-established relationship with Microsoft for over 20 years. We are a top-rated supplier and are proud to be a Managed Partner with many credentials.



