Lead Agent Identity Engineer
Remote in Poland
Security.Engineering& 7 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are looking for a Lead Agent Identity Engineer to own runtime identity and access control for an Enterprise Agent Development Platform — a production-grade, cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale. The role covers inbound and outbound auth, on-behalf-of token exchange, and enterprise identity federation across agent to tool to API chains, using LangGraph and Strands Agents on AWS AgentCore Runtime.
Responsibilities
- Own runtime identity and access control for the agent platform, including inbound and outbound auth
- Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains
- Integrate identity into the agent invocation lifecycle within AgentCore Runtime
- Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent
- Build and maintain token vault and workload identity brokering capabilities
- Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls
- Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens
- Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem
Requirements
- 5+ years of experience in cloud security or identity engineering
- Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID)
- Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault
- Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange
- Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
- Background in enterprise identity federation with MS Entra, Okta, or Cognito
- Skills in secure credential / secret management and token lifecycle, including rotation and vaulting
- English proficiency at B2 level or higher
Nice to have
- Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience
- Familiarity with AWS AgentCore Gateway outbound-auth integration
- Knowledge of MCP / A2A tool-invocation auth patterns
- Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions
