Identity & AI Governance Engineer, Contract-to-Hire
Budget: $75.0 - $140.0
HOURLY / FULL_TIME
⭐ 4.81 (59)
United States
artificial-intelligence, oauth, python
Preferred qualifications
- Talent type: Independent
- Experience: Expert
- English: Fluent
We are hiring a senior engineer to build the trust layer for a multi-tenant AI platform. You will make identity, permissions, policy, rights, provenance, and audit enforceable in production systems used by other engineers and products.
This is not a compliance-writing role and not a generic security assessment. We need a hands-on builder who can design the model, implement the enforcement points, test the failure paths, and produce evidence that the controls work. The initial engagement is contract-to-hire, with any longer-term arrangement subject to mutual fit and formal approval.
What you will own:
- Design and implement identity propagation, tenant isolation, authorization, policy evaluation, and service-to-service trust.
- Model complex entitlements, ownership, licensing, consent, provenance, territory, revocation, and exceptions without turning the system into an unmaintainable rule maze.
- Create tamper-evident audit trails and practical evidence for enterprise or institutional review.
- Define enforcement points for model access, data use, agent tools, integrations, and privileged actions.
- Build clear APIs and schemas that product, platform, and agent engineers can adopt safely.
- Threat-model abuse, confused-deputy paths, privilege escalation, cross-tenant leakage, policy bypass, stale grants, and emergency access.
- Add automated tests for isolation, denial behavior, revocation, immutability, migration, and audit completeness.
You are likely a fit if you have:
- Shipped production identity, authorization, policy, registry, rights, licensing, or provenance systems.
- Strong experience with OAuth 2.0, OIDC, service identities, RBAC, ABAC, relationship-based access control, or policy-as-code.
- Built complex domain models and enforcement APIs, not only configured an identity provider.
- Practical threat-modeling, least-privilege, audit, revocation, and incident-response experience.
- Strong backend engineering skills in Go, Python, Java, TypeScript, or a comparable production language.
- Experience with OpenFGA, SpiceDB, OPA, Cedar, Zanzibar-style systems, or equivalent designs is helpful but not mandatory.
To apply, answer every question below:
1. Describe the most complex authorization or policy system you personally built. What was the domain, scale, data model, enforcement path, and your exact contribution?
2. Give one example of a permission, isolation, revocation, or audit failure you found in production. How did you fix it and prevent recurrence?
3. How would you model a resource whose use depends on owner, tenant, purpose, territory, consent, time, and revocation state?
4. Share one sanitized artifact you can walk through live: schema, policy, code sample, threat model, architecture document, or test suite.
5. Are you seeking a long-term full-time destination after an initial Upwork contract, and how many hours per week can you commit now?
Open job
AI proposal draft
Generate a short cover letter to copy into the offer. Says you are interested and ready to work.
Sign in to generate an AI proposal draft.
Log in