pracaon.plpracaon.pl

Lead Agent Identity Engineer

Remote, Polska
EPAM
Partner
today
Salary to be agreed
Full-time • Remote • IT, Data & AI

Key offer highlights

  • Min. 5 years of experience

  • DevOps / Cloud: AWS, Azure, Docker, Kubernetes

  • Full-time

  • Remote work - no commuting

Description

We are looking for a Lead Agent Identity Engineer to own runtime identity and access control for an Enterprise Agent Development Platform — a production-grade, cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale. The role covers inbound and outbound auth, on-behalf-of token exchange, and enterprise identity federation across agent to tool to API chains, using LangGraph and Strands Agents on AWS AgentCore Runtime. Responsibilities Own runtime identity and access control for the agent platform, including inbound and outbound auth Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains Integrate identity into the agent invocation lifecycle within AgentCore Runtime Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent Build and maintain token vault and workload identity brokering capabilities Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem Requirements 5+ years of experience in cloud security or identity engineering Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID) Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent) Background in enterprise identity federation with MS Entra, Okta, or Cognito Skills in secure credential / secret management and token lifecycle, including rotation and vaulting English proficiency at B2 level or higher Nice to have Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience Familiarity with AWS AgentCore Gateway outbound-auth integration Knowledge of MCP / A2A tool-invocation auth patterns Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions

Requirements

  • 5+ years of experience in cloud security or identity engineering

  • Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID)

  • Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault

  • Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange

  • Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)

  • Background in enterprise identity federation with MS Entra, Okta, or Cognito

  • Skills in secure credential / secret management and token lifecycle, including rotation and vaulting

  • English proficiency at B2 level or higher

Responsibilities

  • Own runtime identity and access control for the agent platform, including inbound and outbound auth

  • Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains

  • Integrate identity into the agent invocation lifecycle within AgentCore Runtime

  • Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent

  • Build and maintain token vault and workload identity brokering capabilities

  • Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls

  • Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens

  • Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem

Seniority

  • Lead

Nice to have

  • Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience

  • Familiarity with AWS AgentCore Gateway outbound-auth integration

  • Knowledge of MCP / A2A tool-invocation auth patterns

  • Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions

Keywords / Skills

Security.Engineering
OAuth2
OpenID Connect
Identity and Access Management
Amazon Web Services
Amazon Bedrock AgentCore
AWS Secrets Manager
Model Context Protocol
This offer was imported from an external portal.Listing source

More similar listings