Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

Lead Agent Identity Engineer

EPAM Systems
  • ๐Ÿ‡ต๐Ÿ‡ฑ Poland
  • Remote
  • Staff / Principal
  • 15 hours ago
  • AI
  • LangGraph
  • AWS
  • Vault
  • Entra
  • JWT
  • OIDC
  • AWS Bedrock
  • Okta
  • MCP
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

We are looking for aLead Agent Identity Engineer to own runtime identity and access control for an Enterprise Agent Development Platform โ€” a production-grade, cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale. The role covers inbound and outbound auth, on-behalf-of token exchange, and enterprise identity federation across agent to tool to API chains, using LangGraph and Strands Agents on AWS AgentCore Runtime.

Responsibilities

  • Own runtime identity and access control for the agent platform, including inbound and outbound auth
  • Design and implement On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent โ†’ tool โ†’ API chains
  • Integrate identity into the agent invocation lifecycle within AgentCore Runtime
  • Manage Gateway outbound authorization and per-target credentials, ensuring secrets are never exposed to the calling agent
  • Build and maintain token vault and workload identity brokering capabilities
  • Coordinate Cedar / MS Entra claims mapping for identity-aware authorization with Runtime Controls
  • Validate claims, scopes, audience, and issuer for JWT / OAuth 2.0 / OIDC tokens, including short-lived scoped tokens
  • Partner with platform and security teams to enforce consistent identity governance across the agent ecosystem

Requirements

  • 5+ years of experience in cloud security or identity engineering
  • Hands-on experience with identity and access control specifically for AI agents in a production agentic AI project, such as On-Behalf-Of (OBO) token exchange across agent-to-tool-to-API chains, AgentCore Identity, or agent identity federation (Entra Agent ID)
  • Expertise in AWS Bedrock AgentCore Identity or similar technology, including inbound auth, outbound auth, and token vault
  • Hands-on implementation experience with OAuth 2.0, OIDC, and JWT, including token issuance, validation, and exchange
  • Experience with On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
  • Background in enterprise identity federation with MS Entra, Okta, or Cognito
  • Skills in secure credential / secret management and token lifecycle, including rotation and vaulting
  • English proficiency at B2 level or higher

Nice to have

  • Showcase of AWS Bedrock AgentCore Identity early adoption or equivalent experience
  • Familiarity with AWS AgentCore Gateway outbound-auth integration
  • Knowledge of MCP / A2A tool-invocation auth patterns
  • Exposure to AgentCore Policy (Cedar) or AWS Verified Permissions

Lead Agent Identity Engineer ยท EPAM Systems

Auto apply with Likeremote