Join us at Entrust
At Entrust, we’re shaping the future of identity centric security solutions. From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration, and build solutions that help keep the world moving safely.
Get to Know Us
Headquartered in Minnesota, Entrust is an industry leader in identity-centric security solutions, serving over 150 countries with cutting-edge, scalable technologies. But our secret weapon? Our people. It’s the curiosity, dedication, and innovation that drive our success and help us anticipate the future.
Platform Architect, Entrust Agentic Trust
Position Summary
The Platform Architect, is accountable for maintaining architectural coherence across the Entrust Agentic Trust Layer and every Line of Business capability that supplies into it, ensuring independent teams and product lines operate within a common architecture and governance framework.
Entrust’s operating doctrine for the Agentic Trust Layer is to complement the enterprise agentic control plane with trusted identity, security, evidence, and assurance capabilities. Our strategy is to architect a solution that brings together decades of Entrust expertise across both product and non-product domains, while actively shaping current and emerging industry standards to ensure they are fit for purpose for the agentic enterprise. By establishing a trusted foundation for AI-driven decision making and automation, Entrust enables organizations to realize the productivity, innovation, and growth benefits of AI with confidence, accountability, and governance.
This role is accountable for defining and governing the four-plane reference architecture, Identity, Authority, Execution, and Assurance, as well as the composition model, trust-plane architecture, and dependency contracts that enable multiple product teams to operate as a unified, integrated trust layer. The mandate is to ensure cryptographic assurance, interoperability, scalability, and business agility across the platform while maintaining a cohesive architecture and operating model. The role also serves as a key industry representative, partnering with standards bodies and ecosystem stakeholders to help shape emerging standards for the agentic enterprise, with particular emphasis on agentic trust, digital identity,
This role partners closely with executive leadership, product teams, engineering, security, and business stakeholders to ensure technology investments deliver measurable business value while maintaining scalability, security, and operational excellence. The Platform Architect is a named gate on every Entrust Agentic Trust Layer build track
Key Responsibilities
Trust-Layer Architecture Leadership
- Define and maintain the architecture strategy and roadmap for the four planes, and hold the reference architecture as the single normative source across product lines.
- Establish architectural principles, standards, patterns, and governance processes, including the Boundary Review process that arbitrates scope conflicts between Entrust Agentic Trust Layer and the Lines of Business.
- Own the Line of Business dependency contracts: interface definitions, service levels, versioning commitments, and internal transfer-pricing terms for each supplying primitive.
- Ensure technology investments align with business objectives and strategic priorities.
- Serve as design authority and technical gate on all Entrust Agentic Trust Layer build tracks, and as the arbiter of record when product, engineering, and Line of Business positions conflict.
Agent Identity, Authority, & Evidence Architecture
- Own the technical specification of the Agent Passport, including SPIFFE/SPIRE-based workload identity, SVID issuance and rotation, attestation of the issuing workload, and binding to Entrust CA roots and HSM-protected keys.
- Own the Permission Slip framework: HSM signing, the five binding elements, delegation chain semantics, revocation and expiry, and the Permission Slip Exchange for presentation across organizational boundaries. The term is always used in full and never shortened in specification or customer-facing material.
- Own the Evidence Ledger and Replay architecture: append-only, tamper-evident, independently verifiable records of authorization and action, with a replay capability that reconstructs an agent episode for an auditor without relying on the agent's own account of it.
- Own the Policy Engine, MCP Gateway, and Just-in-Time Authorization architecture across the Authority and Execution planes, including inline latency budgets, degradation modes, and explicit fail-open versus fail-closed policy per control point.
- Own the Continuous Authentication Engine architecture, including signal ingestion, session-risk evaluation, and the re-authorization path when confidence in a human principal or an agent's context degrades mid-session.
- Own Content Provenance architecture, including C2PA-aligned signing and verification of agent-generated artifacts, and its relationship to CSP Signing Services.
- Establish frameworks for responsible AI, model governance, explainability, and ethical use, and anchor them in the Assurance plane so that governance claims are evidenced rather than asserted.
- Partner with business leaders to identify and prioritize high-value agentic use cases.
- Ensure Entrust Agentic Trust Layer solutions are secure, compliant, scalable, and aligned with industry regulations and third-party assurance regimes.
Technology Innovation
- Champion innovation through the evaluation and adoption of emerging technologies, with priority on agent identity, delegated authorization, verifiable data structures, confidential computing, and post-quantum readiness for long-lived evidence.
- Develop technology roadmaps supporting the agentic trust layer and competitive advantage.
- Guide investment decisions related to cloud platforms, cryptographic infrastructure, agent runtimes, and hyperscaler attach surfaces.
- Evaluate build-versus-buy decisions for Entrust Agentic Trust Layer capabilities, and serve as technical diligence lead on acquisition targets in agent authorization, secrets and non-human identity, and continuous authentication.
Governance, Risk & Security
- Partner with cybersecurity teams to ensure architecture aligns with security and compliance requirements.
- Chair the Architecture Review Board and the Boundary Review forum, escalating unresolved scope conflicts to the Chief Operating Officer for arbitration.
- Ensure Entrust Agentic Trust Layer solutions comply with privacy, legal, regulatory, and ethical standards, including EU AI Act Article 50 transparency obligations, DORA operational resilience expectations, eIDAS and qualified trust service requirements, and FIPS 140-3 and Common Criteria assurance levels where in scope.
- Manage technology risks and provide recommendations to executive leadership, including a standing view of where the architecture is designed versus generally available.
Leadership & Collaboration
- Serve as a trusted advisor to executive leadership on technology strategy and emerging trends.
- Influence senior stakeholders across business and technology teams.
- Lead, mentor, and develop architects and senior technology professionals.
- Foster a culture of innovation, collaboration, continuous learning, and operational excellence.
- Represent Entrust in the standards and governance bodies that will define agentic trust, including the x402 Foundation, FIDO Alliance and AP2, OpenID Foundation, IETF working groups, and the Cloud Security Alliance, and convert standards positions into product architecture.
- Serve as the senior technical voice in analyst engagements, design-partner architecture sessions, and strategic customer reviews with regulated enterprises.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field.
- 15+ years of progressive technology leadership experience.
- 7+ years leading enterprise architecture programs or platform and security architecture for identity, cryptography, or trust infrastructure products and large-scale technology transformations.
- Deep, applied expertise in cryptography and public key infrastructure: certificate authorities, key lifecycle and custody, hardware security modules, signing services, and hardware roots of trust.
- Working expertise in workload identity (SPIFFE/SPIRE, SVIDs, mutual TLS) and modern delegated authorization (OAuth 2.x, token exchange, externalized policy, PBAC and ABAC).
- Demonstrated experience designing tamper-evident or append-only verifiable systems: Merkle-backed logs, Certificate Transparency, transparency log constructs, or equivalent.
- Deep expertise in cloud platforms (Azure, AWS, or Google Cloud), including confidential computing and external or customer-managed key management.
- Experience shipping products under third-party assurance regimes (FIPS 140-3, Common Criteria, eIDAS, SOC 2, FedRAMP), where certification evidence is an engineering deliverable rather than a compliance afterthought.
- Proven ability to influence executive stakeholders and drive strategic decisions.
- Experience leading cross-functional teams in complex global organizations.
Preferred Qualifications
- Master's degree in Computer Science, Engineering, Data Science, Business, or related field.
- Experience deploying Generative AI and Large Language Model (LLM) solutions at enterprise scale, and securing them in production.
- Knowledge of agentic AI architectures, AI orchestration frameworks, the Model Context Protocol (MCP), agent-to-agent interoperability, and agentic payment and delegated-mandate rails including x402 and AP2.
- Familiarity with the competitive control-plane landscape, including Microsoft Entra Agent ID and Agent 365, Google's SPIFFE-based agent identity work, AWS Bedrock AgentCore, and Okta cross-app access, and the ability to articulate where Entrust attaches rather than competes.
- AI, cloud, cybersecurity, or enterprise architecture certifications.
- Experience in highly regulated industries, particularly financial services and insurance, where agentic delegation carries direct fiduciary and supervisory consequences.
Contribution or maintainer standing in open trust-infrastructure communities such as SPIFFE/SPIRE, Sigstore, or Certificate Transpare
At Entrust, we don’t just offer jobs – we offer career journeys. Here is what you can expect when you join our team:
Career Growth: Whether you’re a budding developer or a seasoned expert, we’re invested in your professional journey. With learning-forward initiatives and exciting challenges, your growth is our priority.
Flexibility: Life is all about balance. Whether you’re remote, hybrid, or on-site, we offer flexible options that fit your lifestyle.
Collaboration: Here, your voice matters. Our teams thrive on sharing ideas, brainstorming solutions, and working together to build a better tomorrow.
We believe in securing identities—but it doesn’t stop there. At Entrust, we’re passionate about valuing all identities. Our culture is built on diversity, inclusion, and respect. From unconscious bias training for our leaders to global affinity groups that connect colleagues across the globe, we’re creating a community where everyone is encouraged to be themselves.
Ready to Make an Impact?
If you’re excited by the prospect of innovating, growing your career, and collaborating in a dynamic environment, Entrust is the place for you. Join us in making a difference. Let’s build a more secure world—together.
Apply today!
For more information, visit www.entrust.com. Follow us on, LinkedIn, Facebook, Instagram, and YouTube
Compensation Range:
The anticipated starting base pay for this position is: $251,672-$369,119 per year (in the primary posting location). Actual compensation will be determined based on geographic location, education, skills and experience. This position is also eligible for the company’s discretionary annual incentive plan. In addition to your pay, Entrust offers eligible colleagues and their dependents comprehensive health and well-being programs which include medical, vision, dental, a generous 401(k) matching contribution, life and disability insurance, mental health coaching, virtual fitness programs, paid personal time off plus 12 paid holidays, parental leave and education reimbursement. Please speak with the recruiter for more details. Note: Benefit and Compensation programs are subject to eligibility requirements and other terms of the applicable plan or program. Entrust has the right to end, suspend or amend any of its plans at any time in whole or in part.
For US roles, or where applicable:
Entrust is an EEO/AA/Disabled/Veterans Employer
For Canadian roles, or where applicable:
Entrust values diversity and inclusion and we are committed to building a diverse workforce with wide perspectives and innovative ideas. We welcome applications from qualified individuals of all backgrounds, and we strive to provide an accessible experience for candidates of all abilities.
If you require an accommodation, contact.
Recruiter:
Steve Donahue