Agent Identity Engineer - AgentCore Identity, OBO & Federation
We are looking for a Senior Identity & Access Management Engineer to design and implement secure identity propagation and authorization patterns across AI agent ecosystems. The role focuses on runtime identity, On-Behalf-Of (OBO) token exchange, identity federation, and secure agent-to-tool communication using AWS Bedrock AgentCore and modern enterprise identity platforms.You will be responsible for ensuring that agents, tools, and downstream APIs operate with properly scoped identities and permissions, enabling secure delegation, authorization enforcement, and credential isolation throughout the agent invocation lifecycle.This position requires deep hands-on experience with OAuth 2.0, OIDC, JWT validation, token exchange workflows, and enterprise identity federation. Experience with workload identity brokering, agent authorization models, and policy-based access control is highly desirable.Skills:• AWS Bedrock AgentCore Identity or similar technology (inbound auth, outbound auth, token vault)• On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains• JWT / OAuth 2.0 / OIDC (claims, scopes, audience/issuer validation, short-lived scoped tokens)• Identity federation and MS Entra Agent ID integration or similar technology (workload identity brokering)• Gateway outbound authorization and per-target credential management (secrets never exposed to the calling agent)• AgentCore Runtime integration of identity into the agent invocation lifecycle• Cedar / MS Entra claims mapping for identity-aware authorization (coordination with Runtime Controls) Experience:• 5+ years cloud security or identity engineering• Hands-on OAuth 2.0 / OIDC / JWT implementation (token issuance, validation, exchange)• On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)• Enterprise identity federation with MS Entra, Okta, or Cognito• Secure credential/secret management and token lifecycle (rotation, vaulting) Nice to have:• AWS Bedrock AgentCore Identity early adopter or equivalent• AWS AgentCore Gateway outbound-auth integration• MCP / A2A tool-invocation auth patterns• AgentCore Policy (Cedar) or AWS Verified Permissions exposureResponsibilities:Design and implement secure identity propagation across agent → tool → API interaction chains.Build and support On-Behalf-Of (OBO) token exchange flows and scoped delegation mechanisms.Integrate AWS Bedrock AgentCore Identity capabilities into agent runtime workflows.Implement OAuth 2.0, OpenID Connect (OIDC), and JWT-based authentication and authorization patterns.Develop identity federation integrations with enterprise identity providers such as Microsoft Entra ID, Okta, or Amazon Cognito.Configure gateway-level outbound authorization and per-target credential management, ensuring sensitive credentials are never exposed to calling agents.Build secure token issuance, validation, exchange, rotation, and lifecycle management processes.Design and implement workload identity brokering and agent identity mapping mechanisms.Implement identity-aware authorization controls using Cedar policies, claims mapping, and fine-grained access enforcement.Collaborate with platform, security, and runtime teams to align identity controls with enterprise security standards.Support secure agent-to-agent (A2A) and agent-to-tool invocation authorization patterns.Participate in security reviews, threat modeling, and architecture discussions related to AI agent platforms.Define and enforce best practices for runtime identity, federated access, delegated authorization, and credential protection.
