SEE ALL VACANCIES

Agent Identity Engineer – AgentCore Identity, OBO & Federation

Vacancy details
DevOps Engineering
DevOps Engineer (AWS)
Principal
Bulgaria, Croatia, India, Poland, Portugal, Spain, Ukraine
Remote
APPLY NOW
REFER A FRIEND

We are looking for a Senior Identity & Access Management Engineer to design and implement secure identity propagation and authorization patterns across AI agent ecosystems. The role focuses on runtime identity, On-Behalf-Of (OBO) token exchange, identity federation, and secure agent-to-tool communication using AWS Bedrock AgentCore and modern enterprise identity platforms.

You will be responsible for ensuring that agents, tools, and downstream APIs operate with properly scoped identities and permissions, enabling secure delegation, authorization enforcement, and credential isolation throughout the agent invocation lifecycle.

This position requires deep hands-on experience with OAuth 2.0, OIDC, JWT validation, token exchange workflows, and enterprise identity federation. Experience with workload identity brokering, agent authorization models, and policy-based access control is highly desirable.

What project we have for you

Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
Intellia’s mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.
The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.

What you will do

  • Design and implement secure identity propagation across agent → tool → API interaction chains.
  • Build and support On-Behalf-Of (OBO) token exchange flows and scoped delegation mechanisms.
  • Integrate AWS Bedrock AgentCore Identity capabilities into agent runtime workflows.
  • Implement OAuth 2.0, OpenID Connect (OIDC), and JWT-based authentication and authorization patterns.
  • Develop identity federation integrations with enterprise identity providers such as Microsoft Entra ID, Okta, or Amazon Cognito.
  • Configure gateway-level outbound authorization and per-target credential management, ensuring sensitive credentials are never exposed to calling agents.
  • Build secure token issuance, validation, exchange, rotation, and lifecycle management processes.
  • Design and implement workload identity brokering and agent identity mapping mechanisms.
  • Implement identity-aware authorization controls using Cedar policies, claims mapping, and fine-grained access enforcement.
  • Collaborate with platform, security, and runtime teams to align identity controls with enterprise security standards.
  • Support secure agent-to-agent (A2A) and agent-to-tool invocation authorization patterns.
  • Participate in security reviews, threat modeling, and architecture discussions related to AI agent platforms.
  • Define and enforce best practices for runtime identity, federated access, delegated authorization, and credential protection.

What you need for this

Skills:
• AWS Bedrock AgentCore Identity or similar technology (inbound auth, outbound auth, token vault)
• On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains
• JWT / OAuth 2.0 / OIDC (claims, scopes, audience/issuer validation, short-lived scoped tokens)
• Identity federation and MS Entra Agent ID integration or similar technology (workload identity brokering)
• Gateway outbound authorization and per-target credential management (secrets never exposed to the calling agent)
• AgentCore Runtime integration of identity into the agent invocation lifecycle
• Cedar / MS Entra claims mapping for identity-aware authorization (coordination with Runtime Controls)
 
Experience:
• 5+ years cloud security or identity engineering
• Hands-on OAuth 2.0 / OIDC / JWT implementation (token issuance, validation, exchange)
• On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
• Enterprise identity federation with MS Entra, Okta, or Cognito
• Secure credential/secret management and token lifecycle (rotation, vaulting)
 
Nice to have:
• AWS Bedrock AgentCore Identity early adopter or equivalent
• AWS AgentCore Gateway outbound-auth integration
• MCP / A2A tool-invocation auth patterns
• AgentCore Policy (Cedar) or AWS Verified Permissions exposure

What it’s like to work at Intellias

At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. That’s why we offer a range of benefits that support your well-being and charge your professional growth.
We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.
We welcome and celebrate the uniqueness of every individual. Join Intellias for a career where your perspectives and contributions are vital to our shared success.

Have not found the most
suitable position yet?
Leave your resume and we will select a cool option for you.
Find me a job
Good news!
Link copied
Good news!
You did it.
Bad news!
Something went wrong. Please try again.