Senior Consultant, Strategy, Growth, and Transformation, Identity & Gen AI Engineer
Job Description
Senior Consultant in Identity & Gen AI Engineering at Deloitte, based in Washington, DC (onsite), focused on building and securing generative AI solutions with identity, access, and governance controls.
Responsibilities
- Develop and integrate generative AI capabilities, including large language model applications, retrieval-augmented generation, and AI agents, with secure data access and integration to downstream systems.
- Design and implement authentication, authorization, and identity controls for AI agents, service accounts, and other non-human identities across enterprise and cloud environments.
- Create guardrails for agent-driven workflows, including scoped permissions, least-privilege access, secrets management, and runtime policy enforcement.
- Establish logging, monitoring, and governance to enable traceability and accountability for AI system actions.
- Collaborate with IAM, security architecture, and data teams to embed identity controls into GenAI solution delivery and operations.
- Develop and maintain reference architectures, reusable patterns, and technical documentation for building and securing AI systems.
Requirements
- Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related technical field.
- Ability to work onsite up to five days per week.
- 3+ years of software engineering experience with Python or a comparable language.
- 1+ year of hands-on experience building, integrating, or deploying generative AI solutions such as LLM applications, RAG, or AI agents, including use of model APIs, orchestration frameworks, and AI development tools such as Claude Code, OpenAI Codex, GitHub Copilot, or Cursor.
- Working knowledge of identity and access management concepts and protocols, including authentication, authorization, single sign-on (SSO), and standards such as OpenID Connect (OIDC), SAML, OAuth, and JSON Web Token (JWT).
- Ability to travel approximately 15% on average, depending on client work and engagements.
- Ability to obtain and maintain the necessary security clearance.
- Must be legally authorized to work in the United States without sponsorship now or in the future.
Technologies
- Python, Claude Code, OpenAI Codex, GitHub Copilot, Cursor
- LangChain, LangGraph, Model Context Protocol (MCP), Open Policy Agent (OPA)
- Cedar, OpenFGA, HashiCorp Vault, CyberArk, SailPoint, Okta, Microsoft Entra ID
- Terraform, Ansible
- AWS, Microsoft Azure
- OpenID Connect (OIDC), SAML, OAuth, JWT