Delivery Senior Consultant, Software Engineering Solutions, Identity & Gen AI Engineer
Job Description
Deloitte's Cyber team is expanding capabilities in secure generative AI, identity and access governance, and resilient AI delivery. The Delivery Senior Consultant, Identity & Gen AI Engineer role centers on engineering secure GenAI solutions with built-in identity, access, and trust controls, embedding IAM into GenAI delivery across enterprise and cloud environments. This hybrid Philadelphia-based position blends on-site collaboration with remote work as projects require.
Responsibilities
- Build and integrate generative AI capabilities, including LLM apps, retrieval-augmented generation flows, and AI agents, while ensuring secure data access and connectivity to downstream systems.
- Engineer authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities operating across enterprise and cloud environments.
- Develop guardrails for agentic workflows, including scoped permissions, least-privilege access, credential and secrets management, and runtime policy enforcement.
- Implement logging, monitoring, and governance to provide traceability and accountability for AI system actions.
- Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.
- Create and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.
Technologies
- Python
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Cursor
- SailPoint
- Okta
- Microsoft Entra ID
- HashiCorp Vault
- CyberArk
- LangChain
- LangGraph
- Model Context Protocol (MCP)
- Open Policy Agent (OPA)
- Cedar
- OpenFGA
- AWS
- Microsoft Azure
- Terraform
- Ansible
- OpenID Connect (OIDC)
- SAML
- OAuth
- JSON Web Token (JWT)
The Team
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. You will contribute to delivering powerful solutions that help clients navigate an evolving threat landscape. Through integrated solutions and managed services, we enable clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Qualifications
- Required: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a similar technical field; ability to work onsite up to 5 days a week; 3+ years of software engineering experience with Python or a comparable language; 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as LLM applications, retrieval-augmented generation, or AI agents, including use of model APIs, orchestration frameworks, and AI development tools (Claude Code, OpenAI Codex, GitHub Copilot, Cursor); working knowledge of identity and access management concepts and protocols (authentication, authorization, SSO) and standards (OIDC, SAML, OAuth, JWT); ability to travel 15% on average; ability to obtain and maintain necessary security clearance; must be legally authorized to work in the United States without employer sponsorship now or in the future; hybrid work model requiring residence within commutable distance to Deloitte US Delivery Center locations (Gilbert, Lake Mary, Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, Philadelphia); up to 30% of working time co-located at an assigned office; maximum 10% overnight travel; relocation within 12 weeks if needed.
- Preferred: Experience deploying generative AI solutions to production; hands-on experience with SailPoint, Okta, or Microsoft Entra ID; experience securing non-human identities and credentials using Vault or CyberArk; experience with AI agent frameworks and protocols such as LangChain, LangGraph, or MCP; experience with fine-grained authorization or policy-as-code using OPA, Cedar, or OpenFGA; familiarity with AI security risks and governance frameworks (OWASP Top 10 for LLMs, AI RMF); 2+ years of cloud workload experience (AWS, Azure); professional security certifications (CISSP, CCSP, AWS Solutions Architect, or Azure Solutions Architect); 1+ year supporting federal government environments; 1+ year with infrastructure-as-code or automation tools such as Terraform or Ansible.