Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
DataArt contributes to a cloud security initiative focused on secure agent interactions, enterprise-grade authorization controls, identity federation, credential protection, and policy-based access decisions across distributed systems.
задачи
Develop inbound and outbound authentication flows using AWS Bedrock AgentCore Identity or similar technology;
Implement On Behalf Of token exchange and scoped identity propagation across agent, tool, and API chains;
Develop and maintain OAuth 2.0, OpenID Connect, and JWT-based identity flows, including token issuance, validation, exchange, and audience or issuer checks;
Integrate identity federation with MS Entra Agent ID integration or similar technology for workload identity brokering;
Implement gateway outbound authorization and per-target credential management while ensuring secrets are not exposed to the calling agent;
Integrate identity controls into the agent invocation lifecycle through AgentCore Runtime;
Collaborate on identity-aware authorization using Cedar or MS Entra claims mapping in coordination with runtime controls;
Support secure credential and secret management, including token rotation and vaulting.
требования
5+ Years of experience in cloud security or identity engineering;
Hands-on experience with OAuth 2.0, OpenID Connect, and JWT implementation, including token issuance, validation, and exchange;
Experience with On Behalf Of or token exchange flows in production, including RFC 8693 or equivalent;
Experience with enterprise identity federation using MS Entra, Okta, or Amazon Cognito;
Experience with secure credential and secret management and token lifecycle practices, including rotation and vaulting;
Nice to have: Experience with AWS Bedrock AgentCore Identity as an early adopter or equivalent, experience with AWS AgentCore Gateway outbound authorization integration, exposure to MCP or A2A tool invocation authentication patterns, exposure to AgentCore Policy using Cedar or AWS Verified Permissions.
условия
Work is available in Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, and Ukraine.