Senior Cloud Security Developer with OAuth 2.0

DataArt·Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, Ukraine·Удалённо, Офис·2д. назад

About the Position

We are looking for a Senior Cloud Security Developer who will help design and implement secure identity flows for agent based architectures, with a focus on authentication, authorization, token lifecycle management, and federation across enterprise systems.

About the Project

You will contribute to an identity focused cloud security initiative designed to support secure agent interactions and enterprise grade authorization controls. The work includes token exchange, identity federation, credential protection, and policy based access decisions across distributed systems.

Responsibilities

  • Develop inbound and outbound authentication flows using AWS Bedrock AgentCore Identity or similar technology
  • Implement On Behalf Of token exchange and scoped identity propagation across agent, tool, and API chains
  • Develop and maintain OAuth 2.0, OpenID Connect, and JWT based identity flows, including token issuance, validation, exchange, and audience or issuer checks
  • Integrate identity federation with MS Entra Agent ID integration or similar technology for workload identity brokering
  • Implement gateway outbound authorization and per target credential management while ensuring secrets are not exposed to the calling agent
  • Integrate identity controls into the agent invocation lifecycle through AgentCore Runtime
  • Collaborate on identity aware authorization using Cedar or MS Entra claims mapping in coordination with runtime controls
  • Support secure credential and secret management, including token rotation and vaulting

Requirements

  • 5+ years of experience in cloud security or identity engineering
  • Hands on experience with OAuth 2.0, OpenID Connect, and JWT implementation, including token issuance, validation, and exchange
  • Experience with On Behalf Of or token exchange flows in production, including RFC 8693 or equivalent
  • Experience with enterprise identity federation using MS Entra, Okta, or Amazon Cognito
  • Experience with secure credential and secret management and token lifecycle practices, including rotation and vaulting

Nice to Have

  • Experience with AWS Bedrock AgentCore Identity as an early adopter or equivalent
  • Experience with AWS AgentCore Gateway outbound authorization integration
  • Exposure to MCP or A2A tool invocation authentication patterns
  • Exposure to AgentCore Policy using Cedar or AWS Verified Permissions

Technologies

AWS Bedrock AgentCore Identity, OAuth 2.0, OpenID Connect, JWT, MS Entra, Okta, Amazon Cognito, Cedar, AWS Verified Permissions

Похожие вакансии

Другие вакансии DataArt