Agent Identity Engineer - AgentCore Identity, OBO & Federation
- Hiring from
- Spain
- Work type
- Remote
- Posted
- Oct 2, 2026
Agent Identity Engineer - AgentCore Identity, OBO & Federation
The best-match profile for the role is DevSecOps + IAM + AI in AWS
Location: Remote from Spain (an indefinite Spanish employment contract)
We are looking for a Senior Identity & Access Management Engineer to design and implement secure identity propagation and authorization patterns across AI agent ecosystems. The role focuses on runtime identity, On-Behalf-Of (OBO) token exchange, identity federation, and secure agent-to-tool communication using AWS Bedrock AgentCore and modern enterprise identity platforms.
You will be responsible for ensuring that agents, tools, and downstream APIs operate with properly scoped identities and permissions, enabling secure delegation, authorization enforcement, and credential isolation throughout the agent invocation lifecycle.
This position requires deep hands-on experience with OAuth 2.0, OIDC, JWT validation, token exchange workflows, and enterprise identity federation. Experience with workload identity brokering, agent authorization models, and policy-based access control is highly desirable.
Project Overview:
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
Intellia's mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.
The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.
Requirements:
Skills:
• 5+ years cloud security or identity engineering
• Hands-on OAuth 2.0 / OIDC / JWT implementation (token issuance, validation, exchange)
• On-Behalf-Of / token-exchange flows in production (RFC 8693 or equivalent)
• Enterprise identity federation with MS Entra, Okta, or Cognito
• Secure credential/secret management and token lifecycle (rotation, vaulting)
• AWS Bedrock AgentCore Identity or similar technology (inbound auth, outbound auth, token vault)
• On-Behalf-Of (OBO) token exchange and scoped identity propagation across agent → tool → API chains
• JWT / OAuth 2.0 / OIDC (claims, scopes, audience/issuer validation, short-lived scoped tokens)
• Identity federation and MS Entra Agent ID integration or similar technology (workload identity brokering)
• Gateway outbound authorization and per-target credential management (secrets never exposed to the calling agent)
• AgentCore Runtime integration of identity into the agent invocation lifecycle
• Cedar / MS Entra claims mapping for identity-aware authorization (coordination with Runtime Controls)
Nice to have:
• AWS Bedrock AgentCore Identity early adopter or equivalent
• AWS AgentCore Gateway outbound-auth integration
• MCP / A2A tool-invocation auth patterns
• AgentCore Policy (Cedar) or AWS Verified Permissions exposure
Responsibilities:
- Design and implement secure identity propagation across agent → tool → API interaction chains.
- Build and support On-Behalf-Of (OBO) token exchange flows and scoped delegation mechanisms.
- Integrate AWS Bedrock AgentCore Identity capabilities into agent runtime workflows.
- Implement OAuth 2.0, OpenID Connect (OIDC), and JWT-based authentication and authorization patterns.
- Develop identity federation integrations with enterprise identity providers such as Microsoft Entra ID, Okta, or Amazon Cognito.
- Configure gateway-level outbound authorization and per-target credential management, ensuring sensitive credentials are never exposed to calling agents.
- Build secure token issuance, validation, exchange, rotation, and lifecycle management processes.
- Design and implement workload identity brokering and agent identity mapping mechanisms.
- Implement identity-aware authorization controls using Cedar policies, claims mapping, and fine-grained access enforcement.
- Collaborate with platform, security, and runtime teams to align identity controls with enterprise security standards.
- Support secure agent-to-agent (A2A) and agent-to-tool invocation authorization patterns.
- Participate in security reviews, threat modeling, and architecture discussions related to AI agent platforms.
- Define and enforce best practices for runtime identity, federated access, delegated authorization, and credential protection.