Overview

We are looking for a Senior Cloud Security Developer who will help design and implement secure identity flows for agent based architectures, with a focus on authentication, authorization, token lifecycle management, and federation across enterprise systems.
Project Overview:
You will contribute to an identity focused cloud security initiative designed to support secure agent interactions and enterprise grade authorization controls. The work includes token exchange, identity federation, credential protection, and policy based access decisions across distributed systems.

Responsibilities:
  • Develop inbound and outbound authentication flows using AWS Bedrock AgentCore Identity or similar technology
  • Implement On Behalf Of token exchange and scoped identity propagation across agent, tool, and API chains
  • Develop and maintain OAuth 2.0, OpenID Connect, and JWT based identity flows, including token issuance, validation, exchange, and audience or issuer checks
  • Integrate identity federation with MS Entra Agent ID integration or similar technology for workload identity brokering
  • Implement gateway outbound authorization and per target credential management while ensuring secrets are not exposed to the calling agent
  • Integrate identity controls into the agent invocation lifecycle through AgentCore Runtime
  • Collaborate on identity aware authorization using Cedar or MS Entra claims mapping in coordination with runtime controls
  • Support secure credential and secret management, including token rotation and vaulting
Required Qualifications:
  • 5+ years of experience in cloud security or identity engineering
  • Hands on experience with OAuth 2.0, OpenID Connect, and JWT implementation, including token issuance, validation, and exchange
  • Experience with On Behalf Of or token exchange flows in production, including RFC 8693 or equivalent
  • Experience with enterprise identity federation using MS Entra, Okta, or Amazon Cognito
  • Experience with secure credential and secret management and token lifecycle practices, including rotation and vaulting
Nice To Have:
  • Experience with AWS Bedrock AgentCore Identity as an early adopter or equivalent
  • Experience with AWS AgentCore Gateway outbound authorization integration
  • Exposure to MCP or A2A tool invocation authentication patterns
  • Exposure to AgentCore Policy using Cedar or AWS Verified Permissions
Note:

✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.

Please clearly mention that you have heard of this job opportunity on https://ijob.am.