Identity Access Management & AI Governance Engineer Sr.

Reposted 14 Days Ago
Be an Early Applicant
Duluth, MN, USA
In-Office
Senior level
Aerospace
The Role
Responsible for managing identity infrastructure and security governance of AI tools, implementing access controls, and ensuring compliance with security standards.
Summary Generated by Built In

Job Summary

This position is responsible for the development and operation of our hybrid identity infrastructure (Microsoft Entra ID and Active Directory) and the security governance of enterprise AI tools. You will configure authentication, access policies, and data protection standards to ensure that AI applications (such as Microsoft Copilot and custom LLMs) are accessed securely and interact only with authorized data.

Duties and Responsibilities/Essential Functions

  • Identity Infrastructure & Access Control
  • Core IAM Operations: Manage and maintain Microsoft Entra ID (Azure AD) and on-premise Active Directory, including connect health, schema extensions, and trust relationships.  Development of auditing and reporting to business partners and stakeholders.
  • Conditional Access: Design and enforce Conditional Access policies that specifically target high-risk sign-ins and restrict access to AI platforms based on device compliance and user location.
  • SSO & Federation: Configure Enterprise Applications and SAML/OIDC integrations, ensuring strict authentication standards for third-party AI tools and SaaS platforms.
  • AI Security Governance & Data Protection
  • AI Access Governance: Implement entitlement management and access reviews to strictly control which users and groups have access to generative AI tools (e.g., Microsoft Copilot, ChatGPT Enterprise).
  • Non-Human Identity Management: Secure and govern Service Principals, Managed Identities, and API tokens used by AI agents and automated workflows to prevent unauthorized privilege escalation.
  • Data Labeling (Purview): Configure Microsoft Purview sensitivity labels and Data Loss Prevention (DLP) policies to prevent AI tools from ingesting or surfacing Restricted/Confidential internal data.
  • Privileged Access & Monitoring
  • Privileged Identity Management (PIM): Enforce Just-In-Time (JIT) access for administrative roles and monitor for unauthorized elevation of privileges related to AI infrastructure.
  • Audit & Compliance: Monitor sign-in logs and audit trails for anomalous behavior involving AI applications, ensuring compliance with internal security frameworks.
  • Lifecycle Management: Automate provisioning and de-provisioning workflows to ensure immediate revocation of access to AI tools upon employee departure.
  • Training and Best practices:
  • Coach team members on best practices in identity and access management, fostering a culture of security awareness and compliance

Qualifications

To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions.

  • Bachelor’s degree in Computer Science, Information Technology or related field; or equivalent combination of education and experience
  • IAM Experience: 4+ years of engineering experience with Microsoft Entra ID, Active Directory Domain Services (AD DS), and Group Policy.
  • Data Governance: Hands-on experience with Microsoft Purview (Information Protection, Data Lifecycle Management) and DLP.
  • AI Security Knowledge: Understanding of how to secure non-human identities (workload identities) and govern access to Large Language Models (LLMs) within an enterprise.
  • Technical Skills: Proficiency in PowerShell scripting for automation and Microsoft Graph API.
  • Networking: Solid understanding of DNS, DHCP, and VPN as they relate to authentication flows.

Preferred Qualifications

  • Certifications: SC-300 (Identity and Access Administrator), SC-400 (Information Protection Administrator).
  • Experience configuring "Entra Verified ID" or decentralized identity standards.
  • Previous experience implementing guardrails for Microsoft 365 Copilot.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position.  Duties, responsibilities and activities may change at any time with or without notice.  Work beyond 40 hours per week may be required. 

Cirrus is dedicated to a drug free work environment promoting equal employment opportunity.  Qualified applicants will receive consideration for employment without regard to race, sex, national origin, color, age, disability, religion, pregnancy, veteran status, marital and family status, sexual orientation, receipt of public assistance, genetic information or any other characteristic protected by applicable law.

Our Benefits: Cirrus provides a range of exciting benefits, including:   

  • 401(k) Plan: Dollar-for-dollar match up to 5% after 90 days, with 100% vesting after one year of employment.
  • Employer-Paid Coverages: Group term life, short- and long-term disability insurance.
  • Comprehensive Health Coverage: Medical, vision, dental, with additional dependent coverage options.
  • Free Health Tracking: With rewards for meeting health goals.
  • Generous PTO: 120 hours accrued within the first year.
  • Employee Referral Bonus: For referring talented candidates.
  • Career Development: Tuition reimbursement and professional growth opportunities.
  • Exclusive Discounts: Access to partner and marketplace discounts.
  • Community & Engagement: Company and employee clubs at various locations.

These benefits are designed to support your well-being, growth, and enjoyment at Cirrus!

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Skills Required

  • Bachelor's degree in Computer Science, Information Technology or related field; or equivalent experience
  • 4+ years of engineering experience with Microsoft Entra ID, Active Directory Domain Services, and Group Policy
  • Hands-on experience with Microsoft Purview and Data Loss Prevention
  • Understanding of securing non-human identities and governing access to LLMs
  • Proficiency in PowerShell scripting for automation and Microsoft Graph API
  • Solid understanding of DNS, DHCP, and VPN
  • Certifications SC-300 and SC-400

Cirrus Aircraft Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cirrus Aircraft and has not been reviewed or approved by Cirrus Aircraft.

  • Retirement Support A 401(k) with a company match and quick vesting bolsters long-term savings. This element reliably enhances total compensation across roles.
  • Healthcare Strength Multiple medical plan options (including HDHPs with HSA contributions and a PPO) plus dental and vision provide broad coverage choice. Wellness resources such as Calm, EAP sessions, and Hinge Health add meaningful support.
  • Wellbeing & Lifestyle Benefits Distinctive aviation perks like a discounted Company Flying Club and regular company/community events add lifestyle value. Additional discounts, tuition assistance, and recognition programs further round out the package.

Cirrus Aircraft Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Duluth, MN
1,092 Employees
Year Founded: 1984

What We Do

Cirrus Aircraft is the global leader in personal aviation. Founded in 1984, the brand is, most notably, known for: • Producing the industry's best-selling piston aircraft, the SR Series • Innovating the world’s first single-engine personal jet, the Vision Jet • Earning “the greatest achievement in aeronautics or astronautics in America,” the Robert J. Collier Trophy • Pioneering the first FAA-certified whole-airframe parachute safety system to be included as standard equipment on an aircraft, the Cirrus Airframe Parachute System® (CAPS®) The company has four locations in the United States. - Duluth, Minnesota - Grand Forks, North Dakota - Knoxville, Tennessee - McKinney, Texas

Similar Jobs

CrowdStrike Logo CrowdStrike

Analyst I, Falcon Complete (Hybrid, St Louis)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
85K-120K Annually

CrowdStrike Logo CrowdStrike

Data Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
195K-290K Annually

CrowdStrike Logo CrowdStrike

Data Engineering Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
125K-180K Annually

CrowdStrike Logo CrowdStrike

Operations Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
125K-180K Annually

Similar Companies Hiring

Red 6 Thumbnail
Aerospace • Hardware • Software • Virtual Reality • Defense
Orlando, Florida
186 Employees
Turion Space Thumbnail
Aerospace • Artificial Intelligence • Hardware • Information Technology • Software • Defense • Manufacturing
Irvine, CA
150 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account