Skip To Main Content
backBack to Search

Lead Agent Identity Engineer

Remote in Poland
Security.Engineering& 7 others
hot
Looking for something else?

Find a vacancy that works for you. Send us your CV to receive a personalized offer.

Find me a job

We are looking for a Lead Agent Identity Engineer to own runtime identity and access control for an Enterprise Agent Development Platform — a production-grade, cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale. The role covers inbound and outbound auth, on-behalf-of token exchange, and enterprise identity federation across agent to tool to API chains, using LangGraph and Strands Agents on AWS AgentCore Runtime.

Responsibilities
  • Own runtime identity and access control for the agent platform, including inbound and outbound auth
  • Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains
  • Integrate identity into the agent invocation lifecycle within AgentCore Runtime
  • Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent
  • Build and maintain token vault and workload identity brokering capabilities
  • Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls
  • Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens
  • Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem
Requirements
  • 5+ years of experience in cloud security or identity engineering
  • Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID)
  • Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault
  • Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange
  • Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
  • Background in enterprise identity federation with MS Entra, Okta, or Cognito
  • Skills in secure credential / secret management and token lifecycle, including rotation and vaulting
  • English proficiency at B2 level or higher
Nice to have
  • Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience
  • Familiarity with AWS AgentCore Gateway outbound-auth integration
  • Knowledge of MCP / A2A tool-invocation auth patterns
  • Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions