Lead Agent Identity Engineer
Remote, PolskaKey offer highlights
Min. 5 years of experience
DevOps / Cloud: AWS, Azure, Docker, Kubernetes
Full-time
Remote work - no commuting
Description
We are looking for a Lead Agent Identity Engineer to own runtime identity and access control for an Enterprise Agent Development Platform — a production-grade, cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale. The role covers inbound and outbound auth, on-behalf-of token exchange, and enterprise identity federation across agent to tool to API chains, using LangGraph and Strands Agents on AWS AgentCore Runtime. Responsibilities Own runtime identity and access control for the agent platform, including inbound and outbound auth Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains Integrate identity into the agent invocation lifecycle within AgentCore Runtime Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent Build and maintain token vault and workload identity brokering capabilities Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem Requirements 5+ years of experience in cloud security or identity engineering Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID) Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent) Background in enterprise identity federation with MS Entra, Okta, or Cognito Skills in secure credential / secret management and token lifecycle, including rotation and vaulting English proficiency at B2 level or higher Nice to have Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience Familiarity with AWS AgentCore Gateway outbound-auth integration Knowledge of MCP / A2A tool-invocation auth patterns Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions
Requirements
5+ years of experience in cloud security or identity engineering
Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID)
Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault
Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange
Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
Background in enterprise identity federation with MS Entra, Okta, or Cognito
Skills in secure credential / secret management and token lifecycle, including rotation and vaulting
English proficiency at B2 level or higher
Responsibilities
Own runtime identity and access control for the agent platform, including inbound and outbound auth
Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains
Integrate identity into the agent invocation lifecycle within AgentCore Runtime
Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent
Build and maintain token vault and workload identity brokering capabilities
Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls
Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens
Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem
Seniority
Lead
Nice to have
Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience
Familiarity with AWS AgentCore Gateway outbound-auth integration
Knowledge of MCP / A2A tool-invocation auth patterns
Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions
Keywords / Skills