Security Engineer, Agentic AI & Identity
Top focus
Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide.
Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace.
Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.) Job Summary This role is responsible for driving the strategy, design, implementation, and operational support of enterprise AI Identity and Access Management solutions, while advancing identity security capabilities for modern cloud, API, and Agentic AI ecosystems.
The position serves as a subject matter expert for authentication, federation, workload identities, Zero Trust architecture, and secure AI agent interactions across multi-cloud environments. Job Description What You’ll Do: Architect, deploy, and maintain Microsoft Entra ID Conditional Access Policies, including risk-based access controls, workload identities, and Zero Trust security controls.
Develop and manage secure identity solutions for users, applications, APIs, workloads, and AI agents across hybrid and multi-cloud environments. Design and implement Agent Identity frameworks utilizing Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, service principals, and machine-to-machine authentication mechanisms.
Partner with security, platform, and application teams to integrate identity controls into Agentic AI solutions leveraging MCP, RAG, A2A communications, LLMs, LangChain, LangGraph, Semantic Kernel, and related technologies. Establish and enforce Zero Trust security principles across enterprise applications, APIs, cloud workloads, and AI-driven systems.
Evaluate, troubleshoot, and resolve complex authentication, authorization, federation, and application access issues across enterprise environments. Design secure authentication and authorization architectures for modern applications and APIs, incorporating token-based security and identity best practices.
Implement IAM automation and operational efficiencies through PowerShell, Python, Microsoft Graph APIs, REST APIs, Terraform, and Infrastructure as Code practices. Collaborate with cloud engineering teams to integrate identity platforms across Azure, AWS, and GCP environments.
Develop and maintain identity architecture standards, security patterns, implementation guides, and operational procedures. Create technical documentation, workflows, architecture diagrams, and knowledge articles using Markdown, Mermaid, and related documentation tools.
Monitor emerging technologies and industry trends within Identity Security, Agentic AI, and cloud security, driving adoption of innovative capabilities where appropriate. Participate in security reviews, threat modeling exercises, and architecture governance processes to ensure compliance with enterprise security requirements.
What You’ll Need: 5+ years of IAM experience , with a strong focus on authentication, federation, application onboarding, access management, and identity security in enterprise environments. Hands-on experience designing, implementing, and troubleshooting Microsoft Entra ID Conditional Access Policies , including workload identities and risk-based access controls.
Strong experience onboarding and integrating enterprise applications using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM , and modern authentication architectures. Solid understanding of Agentic AI technologies including MCP, RAG, A2A communication, LLMs, Agent SDKs, LangChain, LangGraph, Semantic Kernel, and related frameworks.
Strong knowledge of Agent Identity concepts , including Agent IDs, Workload Identity Federation, SPIFFE/SPIRE, SSI, service principals, and machine-to-machine authentication. Experience applying Zero Trust principles across users, applications, APIs, workloads, and AI Agents.
Good understanding of application architecture, API security, token-based authentication, and secure application design. Experience working in multi-cloud environments ( Azure, AWS, GCP ) and integrating identity services across platforms. Experience with IAM automation using PowerShell, Python, Microsoft Graph APIs, REST APIs , and Infrastructure as Code tools such as Terraform is preferred.
Ability to troubleshoot complex authentication, authorization, and application access issues in large-scale enterprise environments. Soft Skills Ability to quickly learn and adapt to emerging technologies, particularly within Identity, Security, and Agentic AI domains.
Strong communication and presentation skills, with the ability to explain technical concepts to both technical and non-technical audiences. Experience creating and maintaining technical documentation, architecture diagrams, and workflows using Markdown, Mermaid, and related tools.
Strong analytical, problem-solving, and collaboration skills, with the ability to work effectively across security, engineering, and business teams. Demonstrated ownership, accountability, and ability to drive technical initiatives from design through production support.
Disclaimer: This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.
Skills Adaptability, AI Agent Security, Critical Thinking, Identity Access Management (IAM), Microsoft Entra ID (Azure Active Directory), OpenID Connect, Zero Trust Architecture Compensation Primary Location Pay Range: $104,958.81 - $157,438.22 Comcast intends to offer the selected candidate base pay within this range, dependent on job-related, non-discriminatory factors such as experience.
The application window is 30 days from the date job is posted, unless the number of applicants requires it to close sooner or later. Base pay is one part of the Total Rewards that Comcast provides to compensate and recognize employees for their work.
Most sales positions are eligible for a Commission under the terms of an applicable plan, while most non-sales positions are eligible for a Bonus. Additionally, Comcast provides best-in-class Benefits to eligible employees. We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most.
That’s why we provide an array of options, expert guidance and always-on tools, that are personalized to meet the needs of your reality – to help support you physically, financially and emotionally through the big milestones and in your everyday life.
Please visit the compensation and benefits summary on our careers site for more details. Education Bachelor's Degree (Required) While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.
Certifications (if applicable) Relevant Work Experience 5-7 Years Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.