Security Engineer with Agent Authorization

DataArt·Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, Ukraine·Удалённо, Офис·1 нед. назад

About the Position

We are looking for a Security Engineer to support the security of an AI platform with a focus on agent authorization, credential management, identity, and observability. In this role, you will work on practical security controls that help protect agent workflows and tool integrations.

About the Project

You will contribute to an AI platform centered on secure agent operations and controlled tool access. The work includes authorization, credential management, identity validation, audit tracing, and gateway based protection for tool interactions.

Responsibilities

  • Implement authorization systems for API and tool access
  • Manage credential storage and secret rotation patterns for target systems
  • Validate agent identity and support cross agent authentication and service to service trust
  • Improve observability and tracing for agent workflows and tool invocation activity
  • Support audit logging for agent interactions and tool access events
  • Enforce gateway controls to prevent direct tool access outside approved paths
  • Work with AWS based secrets management for per target credential storage and rotation

Requirements

  • 3+ years of security engineering experience in AI or ML platforms or agent platforms
  • Experience implementing authorization systems for API or tool access
  • Experience with credential management and secret rotation patterns
  • Experience with agent workflow observability and tracing
  • Knowledge of Cedar policy engine for agent to tool permissions and tool level access control
  • Experience with OAuth tokens, API keys, and IAM roles for secure credential handling
  • Experience validating JWT and supporting service to service trust models
  • Experience with audit logging and tracing for agent workflows

Nice to Have

  • Experience with Cedar policy language or OPA for agent authorization
  • Experience with AWS Bedrock AgentCore policy configuration
  • Knowledge of agent to agent authentication patterns
  • Experience with zero trust architecture for agentic systems
  • Knowledge of MCP protocol security including authentication and authorization at tool invocation

Technologies

Cedar policy engine, OAuth, API keys, IAM roles, JWT, AWS Secrets Manager, AWS Bedrock AgentCore, OPA, MCP

Похожие вакансии

Другие вакансии DataArt