Open role

Member of Technical Staff, Identity & Cryptography

Build the role-bound credentials, revocation, and non-repudiation that make agent authority provable.

Team Identity & cryptography

Location New York, NY

Type Full-time

Level Senior / Staff MTS

Compensation $240,000 – $310,000 base + meaningful equity + benefits

What we are building

Dipp AI Technologies is on a mission to close the gap between AI’s advanced reasoning capabilities and an enterprise’s ability to trust it with real work: verifiable, cost-disciplined, and in control of its own data.

We build Orcher, the agentic control plane that enforces Human-in-the-Role across seven components, and Dipp Intelligence, our Enterprise Superintelligence solution that compounds on verified execution.

Work directly with the founding team, building for customers from startups to Fortune 100 companies across industries. Help enterprises adopt frontier models, open weights and new compute providers without surrendering authority, economics or data control.

About the role

Human-in-the-Role only works if authority is cryptographically bound to a role, scoped to a directive, and revocable in seconds. You will own the identity fabric that issues, scopes, attenuates, and revokes agent credentials across an enterprise estate.

The work spans key management, short-lived credential issuance, delegation chains, and the signing that makes an action non-repudiable when an auditor examines it two years later. It also spans the unglamorous parts: rotation without downtime, revocation propagation, and behaving correctly when an enterprise identity provider is unavailable.

You will integrate with the identity systems enterprises actually run — Entra ID, Okta, Ping — and with HSM and KMS backends under real compliance constraints.

What you will do

  • Design credential formats and delegation chains that bind an agent action to a named accountable role.
  • Build issuance, attenuation, rotation, and revocation paths with sub-second propagation targets.
  • Integrate with enterprise IdPs and with HSM/KMS backends, including FIPS-validated deployments.
  • Own signing and verification for the audit ledger so evidence stands up to external review.
  • Model and defend against credential replay, confused-deputy, and privilege-escalation attacks.
  • Document the trust model in language a security architect and an auditor can both evaluate.

What we look for

  • Hands-on experience building authentication or authorization infrastructure in production.
  • Working knowledge of applied cryptography: signatures, key derivation, envelope encryption, and rotation.
  • Familiarity with OAuth 2.1, OIDC, SPIFFE/SVID, mTLS, macaroons, or biscuit-style attenuable tokens.
  • Experience with HSM or cloud KMS integration and with key custody requirements.
  • A security mindset that starts from the threat model rather than the happy path.
  • You do not roll your own primitives, and you can explain precisely why.

Experience

  • 6+ years in backend, platform, or security engineering with at least 3 years on identity or cryptographic systems.
  • Has shipped an authorization or credential system used by other teams or external customers.
  • Exposure to enterprise security review, penetration testing, or formal audit is a strong plus.

Education

  • BS or MS in Computer Science, Cryptography, Information Security, or a related field.
  • Equivalent professional experience in security engineering is accepted in place of a degree.

Compensation and benefits

  • Meaningful equity with a standard four-year vest.
  • Full medical, dental, and vision coverage.
  • 401(k) with company contribution and a hardware budget.
  • Support for security certifications, conferences, and published research.

How we hire

  1. 01Intro conversation with the founder or hiring lead.
  2. 02Threat-modelling discussion on agent credential design.
  3. 03Practical review of code or a design you have shipped.
  4. 04Panel with control-plane and evidence engineers.
  5. 05References and offer.