Apply now »

Technology Architect

Location:  Bengaluru
Other locations:  Primary Location Only
Salary: Competitive
Date:  Sep 28, 2026

Job description

Requisition ID:  1745411

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

AI Identity Architect

Identity and access architecture for AI agents and non-human identities

 

Role title    

AI Identity Architect

 


Function    

Information Security / Identity & Access Management

    

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

The opportunity

The Artificial Intelligence (AI) Identity Architect will partner across technology and business teams to design and govern the integration of Agentic AI, automation and intelligence into EY’s global Identity and Access Management (IAM) ecosystem. The architect will collaborate closely with Security Architects, Development Leads, Engineering, Operations and other internal business teams to ensure that Agentic AI solutions are securely designed, complaint with IAM standards and aligned with EY’s global technology and security strategies. 

The AI Identity Architect is accountable and responsible for the alignment of business, operational and security requirements and translation of those requirements into technical IAM capabilities. IAM services include, but not limited to, Identity Lifecycle Management, authentication and authorization, session management, access requests, access provisioning, access reauthorization, remote access, IAM services API, role and entitlement models, and directory technologies. The AI Identity Architect will work with other Architects and Service Owners to create a roadmap that meets strategic and current requirements.

 

Your key responsibilities

  • Partner with Architecture, Information Security, Client Technology, and Enterprise Technology teams to embed AI-driven capabilities into the enterprise IAM strategy, ensuring alignment with business goals, security policies, regulatory requirements, and organizational technology roadmaps
  • Architect AI-augmented solutions that enhance the global IAM platforms’ intelligence, automation and adaptive capabilities
  • Architect and integrate AI-based features, such as adaptive access control, predictive threat detection and identity analytics, into the IAM framework
  • Define architectural standards, frameworks and patterns for AI-assisted IAM services across on-prem, hybrid and cloud environments
  • Establish architectural guardrails and governance models for safe and auditable deployment of AI and Agentic agents across EY’s business teams
  • Define and enforce identity management strategies tailored for AI agents, including their unique life cycles, entitlements, and owner relationships.
  • Serve as a trusted advisor to senior leadership on the application of Agentic AI to identity operations, user experience and risk reduction.
  • Partner with data and platform teams to ensure alignment with enterprise AI governance and model management frameworks.

 

Skills and attributes for success

The individual in this role must be well educated in general aspects of Information Security as well as:

  • Have proven experience in providing architecture guidance and advisory services to internal or external clients for various environments and systems, including application/technology blueprints, roadmaps, optimization, and migration strategies.
  • Extensive experience implementing or architecting AI, ML or automation technologies within IAM or cybersecurity domains.
  • Experience designing and integrating systems using the Model Context Protocol (MCP) or equivalent AI orchestration standards.
  • Strong knowledge of Agentic A architectures (multi-agent systems, LLM orchestration, reinforcement-based agents or decision engines).
  • Strong experience with enterprise IAM platforms (Entra ID, SailPoint, CyberArk, PlainID) and identity analytics.
  • Ability to effectively communicate and advocate key security requirements and controls for implementation by development teams.
  • Ability to communicate effectively with all levels of management, both verbally and in writing.

 

Microsoft Entra Agent ID and Agent 365 platform design

  • Design the agent identity model in Microsoft Entra Agent ID agent identity blueprints, parent/child inheritance, agent instances, sponsorship and ownership, and the credential model for delegated versus application-only access.
  • Establish the Microsoft Agent 365 control plane across its five pillars Registry, Access Control, Visualization, Interoperability and Security and define the operating model for the Agent 365 registry in the Microsoft 365 admin center.
  • Define the registration and discovery pathway so that agents built in Copilot Studio, Microsoft Foundry, the Microsoft Agent Framework, the Agent 365 SDK and third-party or open-source frameworks all converge on a single authoritative registry.
  • Design Conditional Access for agents, risk-based response using Microsoft Entra ID Protection, and network-layer controls for agent traffic.
  • Extend Microsoft Entra ID Governance to agent identities: access packages scoped to agent identities, access reviews, lifecycle workflows, sponsor notification and sponsorship-transfer handling, and time-bound access with automated expiry.
  • Design the delegation and consent model for agents acting on behalf of users, including token exchange, scope minimization and revocation paths.
  • Define the approach to shadow-AI discovery locally run and cloud-hosted agents surfaced through Microsoft Defender, Microsoft Intune and Agent 365 and the remediation path from discovery to governed identity.

 

Guardrails, governance and assurance

  • Establish architectural guardrails and governance models for the safe, auditable deployment of AI and agentic systems across business teams.
  • Define architectural standards, frameworks and patterns for AI-assisted IAM services across on-premises, hybrid and cloud environments.
  • Design systems and integrations using the Model Context Protocol (MCP), agent-to-agent (A2A) patterns and equivalent AI orchestration standards, with authentication, authorization and auditability designed in rather than bolted on.
  • Work with Microsoft Purview and Microsoft Defender owners so that data protection, DLP, audit and threat response cover agent activity end to end.
  • Define the control set that satisfies internal policy, external regulation and audit for non-human identities, and evidence it through logging, reporting and recertification.
  • Set standards for privileged agent access no standing privilege, short-lived credentials, just-in-time elevation and least-privilege scope design.

 

To qualify for the role, you must have 

Education:

  • Bachelor’s or Master’s degree in Information Assurance, Computer Science, Information Systems or related field of study.

 

Experience:

  • 12+ years of practical experience in the field of IT is required.  8+ years of direct Information Security experience.
  • 6+ years’ experience in hands-on Identity & Access Management positions
  • 2+ years of experience implementing or architecting AI/ML Identity systems

 

Ideally, you’ll also have:

  • Experience designing or governing Agentic AI agents for workflow orchestration or decision automation.
  • Hands-on familiarity with Agentic AI frameworks (LamgChain, CrewAI, AutoGen or similar).
  • Ability to articulate complex AI and identity concepts to non-technical stakeholders.

 

What we offer

As part of this role, you'll work in a highly integrated, global team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:

  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.

 

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »