Security Engineer with Cedar Policy

Aether Biomedical

United States

Hybrid

USD 110,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Vacation days 26+
Sick days 10
Health and life insurance
MyBenefit with Multisport
Psychological support
English language classes
Learning platforms access
Flexible workplace
Tech Skills Mentoring
Certification reimbursement

Job summary

Aether Biomedical is seeking a Security Engineer to advance policy-based authorization for enterprise AI and cloud platforms. You will collaborate with identity, security, and platform teams to develop authorization policies, integrate providers, and enable secure access controls using policy frameworks.

You will help map claims to policy rules, validate policies with Python tooling, and participate in governance and audit activities.

Qualifications

  • 3+ years of experience in security engineering, backend engineering, or a related field.
  • Hands-on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito.
  • Experience defining and managing policies within an ABAC or RBAC authorization framework.
  • Hands-on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies.
  • Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures.
  • Experience working with claims mapping and token based authorization models.
  • Understanding of secure authorization design principles and policy lifecycle management.
  • Experience with Python development for automation, validation, or backend services.

Responsibilities

  • Develop and maintain authorization policies using the Cedar policy language.
  • Author, test, and validate policy definitions for enterprise applications and AI services.
  • Implement and support access control models using ABAC and RBAC.
  • Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito.
  • Map identity claims and token attributes to authorization decisions and policy rules.
  • Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes.
  • Develop Python based tooling for policy validation, testing, and automation.
  • Design and implement parameter level access control patterns for secure tool and service interactions.
  • Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls.
  • Contribute to audit logging and authorization decision traceability practices.
  • Support security reviews and help maintain authorization governance standards.

Skills

3+ years security
ABAC/RBAC
Policy as code
Open Policy Agent
Cedar
OAuth/JWT/OpenID
Identity provider integration
Python automation
Policy lifecycle
Audit logging

Tools

LangGraph
Open Policy Agent
AWS AgentCore Gateway
Microsoft Entra ID
Okta
Amazon Cognito
Python

Job description

Technology stack

AWS AgentCore Policy, Cedar, Python, Microsoft Entra ID, OAuth 2.0, JWT, OpenID Connect, Open Policy Agent, AWS AgentCore Gateway, LangGraph, Identity Providers, Audit Logging Frameworks

Project overview

The project focuses on delivering a centralized authorization framework for enterprise AI services and cloud applications. The platform provides secure policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.

Team

Medium team (10-20 people)

Position overview

We are looking for a Security Engineer to support the implementation and governance of policy based authorization solutions for enterprise AI and cloud platforms. In this role, you will work with identity, security, and platform teams to develop authorization policies, integrate identity providers, and help built secure access control mechanisms using modern policy frameworks. You will work with security engineers, backend developers, platform engineers, architects, and governance specialists. The team follows a collaborative development approach, emphasizing policy as code, automation, secure design practices, and continuous improvement.

Responsibilities
  • Develop and maintain authorization policies using the Cedar policy language
  • Author, test, and validate policy definitions for enterprise applications and AI services
  • Implement and support access control models using attribute based and role based authorization approaches
  • Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito
  • Map identity claims and token attributes to authorization decisions and policy rules
  • Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes
  • Develop Python based tooling for policy validation, testing, and automation
  • Design and implement parameter level access control patterns for secure tool and service interactions
  • Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls
  • Contribute to audit logging and authorization decision traceability practices
  • Support security reviews and help maintain authorization governance standards
Requirements
  • 3+ years of experience in security engineering, backend engineering, or a related field
  • Hands on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito
  • Experience defining and managing policies within an ABAC or RBAC authorization framework
  • Hands on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies
  • Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures
  • Experience working with claims mapping and token based authorization models
  • Understanding of secure authorization design principles and policy lifecycle management
  • Experience with Python development for automation, validation, or backend services
  • Strong analytical and problem solving skills
  • Good written and verbal communication skills
  • Nice to have Experience with LangGraph tool invocation patterns
  • Experience integrating with AWS AgentCore Gateway
  • Knowledge of enterprise AI platform architecture and governance principles
  • Experience implementing policy as code methodologies
  • Familiarity with cloud native security services and authorization platforms
  • Exposure to audit logging and compliance reporting requirements
What We Offer:
  • Vacation days: Up to 26 business days per year.
  • 10 illness/special days off per year (fully paid, no medical papers needed) for all contract types.
  • Health and life insurance (Luxmed)
  • MyBenefit platform with Multisport option
  • Internal psychological support service
  • English language classes from the first working day
  • Access to external learning platforms: O’Reilly, LinkedIn Learning, Udemy, and a wide catalog of diverse internal training
  • Flexible workplace: work from the office, from home, or choose a hybrid option
  • Tech Skills Mentoring Program
  • Opportunities to develop as a public speaker, mentor, or technical interviewer
  • Fully paid idle (bench) when not involved in a project
  • Certification reimbursement (AWS, GCP, Microsoft, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Test Engineer with A2A Security
Security & Test Engineer with A2A Security

Aether Biomedical • United States

Hybrid
USD 90,000 - 130,000
Vacation days up to 26 days/year
Health and life insurance
Learning platforms access (O'Reilly, L
Senior Cloud Security Developer with OAuth 2.0
Senior Cloud Security Developer with OAuth 2.0

Aether Biomedical • United States

Hybrid
USD 150,000 - 210,000
Vacation days (26)
Health and life insurance
MyBenefit platform
+5
QA Engineer with Security Testing
QA Engineer with Security Testing

Aether Biomedical • United States

Hybrid
USD 90,000 - 130,000
Vacation days up to 26 business days
Illness/special days off
Health and life insurance
+3
Python Developer with Agent Registry Integration
Python Developer with Agent Registry Integration

Aether Biomedical • United States

Hybrid
USD 120,000 - 180,000
Vacation days
Health and life insurance
Flexible hybrid work
+5
Platform Engineer with AWS AgentCore Evaluation
Platform Engineer with AWS AgentCore Evaluation

Aether Biomedical • United States

Hybrid
USD 43,000 - 58,000
Vacation days: up to 26 days/year
Health and life insurance
English language classes
+2
Staff Security Engineer, IAM
Staff Security Engineer, IAM

GitLab • United States

On-site
USD 180,000 - 240,000
Staff Software Engineer - Customer Identity & Access Management (CIAM)
Staff Software Engineer - Customer Identity & Access Management (CIAM)

fastly • United States

Hybrid
USD 211,000 - 254,000
Equity
Discretionary bonus
Health, dental, vision
+6
Senior+ IAM Engineer
Senior+ IAM Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Vision & dental
HSA/FSA
+7
Senior Python Engineer with AI Exposure
Senior Python Engineer with AI Exposure

Aether Biomedical • United States

Hybrid
USD 140,000 - 190,000
Vacation days 26
Health insurance
Mental health support
+3
Senior Software Development Engineer - Agent Identity & Core Primitives
Senior Software Development Engineer - Agent Identity & Core Primitives

delinea • United States

On-site
USD 180,000 - 240,000
Competitive salary
Meaningful bonus program
Healthcare insurance
+5