Policy-Driven Security Engineer (ABAC/RBAC)

Aether Biomedical

United States

On-site

USD 110,000 - 150,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Vacation days 26+
Sick days 10
Health and life insurance
MyBenefit with Multisport
Psychological support
English language classes
Learning platforms access
Flexible workplace
Tech Skills Mentoring
Certification reimbursement

Job summary

Aether Biomedical is seeking a Security Engineer to advance policy-based authorization for enterprise AI and cloud platforms. You will collaborate with identity, security, and platform teams to develop authorization policies, integrate providers, and enable secure access controls using policy frameworks.

You will help map claims to policy rules, validate policies with Python tooling, and participate in governance and audit activities.

Qualifications

  • 3+ years of experience in security engineering, backend engineering, or a related field.
  • Hands-on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito.
  • Experience defining and managing policies within an ABAC or RBAC authorization framework.
  • Hands-on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies.
  • Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures.
  • Experience working with claims mapping and token based authorization models.
  • Understanding of secure authorization design principles and policy lifecycle management.
  • Experience with Python development for automation, validation, or backend services.

Responsibilities

  • Develop and maintain authorization policies using the Cedar policy language.
  • Author, test, and validate policy definitions for enterprise applications and AI services.
  • Implement and support access control models using ABAC and RBAC.
  • Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito.
  • Map identity claims and token attributes to authorization decisions and policy rules.
  • Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes.
  • Develop Python based tooling for policy validation, testing, and automation.
  • Design and implement parameter level access control patterns for secure tool and service interactions.
  • Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls.
  • Contribute to audit logging and authorization decision traceability practices.
  • Support security reviews and help maintain authorization governance standards.

Skills

3+ years security
ABAC/RBAC
Policy as code
Open Policy Agent
Cedar
OAuth/JWT/OpenID
Identity provider integration
Python automation
Policy lifecycle
Audit logging

Tools

LangGraph
Open Policy Agent
AWS AgentCore Gateway
Microsoft Entra ID
Okta
Amazon Cognito
Python

Job description

Aether Biomedical is seeking a Security Engineer to advance policy-based authorization for enterprise AI and cloud platforms. You will collaborate with identity, security, and platform teams to develop authorization policies, integrate providers, and enable secure access controls using policy frameworks.

You will help map claims to policy rules, validate policies with Python tooling, and participate in governance and audit activities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

QA Security Engineer for AI Platforms (Flexible Work)
QA Security Engineer for AI Platforms (Flexible Work)

Aether Biomedical • United States

On-site
USD 90,000 - 130,000
Vacation days up to 26 business days
Illness/special days off
Health and life insurance
+3
Security & Test Engineer for AI Agent Platforms
Security & Test Engineer for AI Agent Platforms

Aether Biomedical • United States

On-site
USD 90,000 - 130,000
Vacation days up to 26 days/year
Health and life insurance
Learning platforms access (O'Reilly, L
Senior Cloud Security & Identity Engineer
Senior Cloud Security & Identity Engineer

Aether Biomedical • United States

On-site
USD 150,000 - 210,000
Vacation days (26)
Health and life insurance
MyBenefit platform
+5
AI Security Engineer: Guard AI & SaaS Risk
AI Security Engineer: Guard AI & SaaS Risk

Menlo Ventures • Palo Alto (CA)

On-site
USD 155,000 - 180,000
Competitive compensation with equity
Comprehensive healthcare with dental and vision coverage
Flexible paid time off
+2
Security Engineer with Cedar Policy
Security Engineer with Cedar Policy

Aether Biomedical • United States

Hybrid
USD 110,000 - 150,000
Vacation days 26+
Sick days 10
Health and life insurance
+7
Senior ABAC & Security Platform Lead
Senior ABAC & Security Platform Lead

Amazon • San Diego (CA)

On-site
USD 220,000 - 298,000
System Dev Engineer: Policy & Access Control Innovator
System Dev Engineer: Policy & Access Control Innovator

Amazon • Austin (TX)

On-site
USD 129,000 - 175,000
Health insurance
401(k) plan
Paid time off
+1
Remote Biosecurity Safeguards Analyst
Remote Biosecurity Safeguards Analyst

Applied Methods Ltd • San Francisco (CA)

Hybrid
USD 245,000 - 285,000
Remote IAM Cloud Engineer: AI-Driven Security
Remote IAM Cloud Engineer: AI-Driven Security

HealthEquity, Inc. • United States

Remote
USD 115,000 - 150,000
Medical, dental, and vision
HSA contribution and match
401(k) match
+1
Security Platform Lead — Scale Data Protection
Security Platform Lead — Scale Data Protection

Socket.dev • Austin (TX)

On-site
USD 140,000 - 230,000
Health insurance
401(k) with 4% match
Stock options