Senior Cloud Security Developer with OAuth 2.0

Aether Biomedical

United States

Hybrid

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Vacation days (26)
Health and life insurance
MyBenefit platform
Learning platforms
Flexible workplace (office/home/hybrid
Mentoring program
Public speaking opportunities
Certification reimbursement

Job summary

Aether Biomedical seeks a Senior Cloud Security Developer to design and implement secure identity flows for agent-based architectures, focusing on authentication, authorization, token lifecycle management, and federation across enterprise systems.

You will build inbound/outbound authentication, implement token exchange, and integrate federation with leading identity providers, contributing to secure credential management and runtime controls.

Qualifications

  • Experience with AWS Bedrock AgentCore Identity as an early adopter or equivalent.
  • Experience with AWS AgentCore Gateway outbound authorization integration.
  • Exposure to MCP or A2A tool invocation authentication patterns.
  • Exposure to AgentCore Policy using Cedar or AWS Verified Permissions.

Responsibilities

  • Develop inbound and outbound authentication flows using AWS Bedrock AgentCore Identity or similar technology.
  • Implement On Behalf Of token exchange and scoped identity propagation across agent, tool, and API chains.
  • Develop and maintain OAuth 2.0, OpenID Connect, and JWT based identity flows, including token issuance, validation, exchange, and audience or issuer checks.
  • Integrate identity federation with MS Entra Agent ID integration or similar technology for workload identity brokering.
  • Implement gateway outbound authorization and per target credential management while ensuring secrets are not exposed to the calling agent.
  • Integrate identity controls into the agent invocation lifecycle through AgentCore Runtime.
  • Collaborate on identity aware authorization using Cedar or MS Entra claims mapping in coordination with runtime controls.
  • Support secure credential and secret management, including token rotation and vaulting.

Skills

OAuth 2.0
OpenID Connect
JWT
Token lifecycle
Federation

Education

Bachelor's degree in CS or related field

Tools

AWS Bedrock AgentCore Identity
AWS AgentCore Gateway
Cedar
AWS Verified Permissions
MS Entra
Okta
Amazon Cognito

Job description

Technology stack
  • AWS Bedrock AgentCore Identity
  • OAuth 2.0
  • OpenID Connect
  • JWT
  • MS Entra
  • Okta
  • Amazon Cognito
  • Cedar
  • AWS Verified Permissions
Project overview
  • AWS Bedrock AgentCore Identity
  • OAuth 2.0
  • OpenID Connect
  • JWT
  • MS Entra
  • Okta
  • Amazon Cognito
  • Cedar
  • AWS Verified Permissions
Position overview

We are looking for a Senior Cloud Security Developer who will help design and implement secure identity flows for agent based architectures, with a focus on authentication, authorization, token lifecycle management, and federation across enterprise systems.

Responsibilities
  • Develop inbound and outbound authentication flows using AWS Bedrock AgentCore Identity or similar technology
  • Implement On Behalf Of token exchange and scoped identity propagation across agent, tool, and API chains
  • Develop and maintain OAuth 2.0, OpenID Connect, and JWT based identity flows, including token issuance, validation, exchange, and audience or issuer checks
  • Integrate identity federation with MS Entra Agent ID integration or similar technology for workload identity brokering
  • Implement gateway outbound authorization and per target credential management while ensuring secrets are not exposed to the calling agent
  • Integrate identity controls into the agent invocation lifecycle through AgentCore Runtime
  • Collaborate on identity aware authorization using Cedar or MS Entra claims mapping in coordination with runtime controls
  • Support secure credential and secret management, including token rotation and vaulting
Requirements
  • Experience with AWS Bedrock AgentCore Identity as an early adopter or equivalent
  • Experience with AWS AgentCore Gateway outbound authorization integration
  • Exposure to MCP or A2A tool invocation authentication patterns
  • Exposure to AgentCore Policy using Cedar or AWS Verified Permissions
What We Offer:
  • Vacation days: Up to 26 business days per year.
  • 10 illness/special days off per year (fully paid, no medical papers needed) for all contract types
  • Health and life insurance (Luxmed)
  • MyBenefit platform with Multisport option
  • Internal psychological support service
  • English language classes from the first working day
  • Access to external learning platforms: O’Reilly, LinkedIn Learning, Udemy, and a wide catalog of diverse internal training
  • Flexible workplace: work from the office, from home, or choose a hybrid option
  • Tech Skills Mentoring Program
  • Opportunities to develop as a public speaker, mentor, or technical interviewer
  • Fully paid idle (bench) when not involved in a project
  • Certification reimbursement (AWS, GCP, Microsoft, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer with Cedar Policy
Security Engineer with Cedar Policy

Aether Biomedical • United States

Hybrid
USD 110,000 - 150,000
Vacation days 26+
Sick days 10
Health and life insurance
+7
Security & Test Engineer with A2A Security
Security & Test Engineer with A2A Security

Aether Biomedical • United States

Hybrid
USD 90,000 - 130,000
Vacation days up to 26 days/year
Health and life insurance
Learning platforms access (O'Reilly, L
Staff Software Engineer - Customer Identity & Access Management (CIAM)
Staff Software Engineer - Customer Identity & Access Management (CIAM)

fastly • United States

Hybrid
USD 211,000 - 254,000
Equity
Discretionary bonus
Health, dental, vision
+6
QA Engineer with Security Testing
QA Engineer with Security Testing

Aether Biomedical • United States

Hybrid
USD 90,000 - 130,000
Vacation days up to 26 business days
Illness/special days off
Health and life insurance
+3
Python Developer with Agent Registry Integration
Python Developer with Agent Registry Integration

Aether Biomedical • United States

Hybrid
USD 120,000 - 180,000
Vacation days
Health and life insurance
Flexible hybrid work
+5
Cloud Identity Engineer
Cloud Identity Engineer

Smart IT Frame LLC • Chandler (AZ)

On-site
USD 120,000 - 150,000
Platform Engineer with AWS AgentCore Evaluation
Platform Engineer with AWS AgentCore Evaluation

Aether Biomedical • United States

Hybrid
USD 43,000 - 58,000
Vacation days: up to 26 days/year
Health and life insurance
English language classes
+2
Senior ICAM Engineer, Remote, United States
Senior ICAM Engineer, Remote, United States

Technologist, Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
Health Care Plan
401k with employer match
Paid Time Off
+2
Senior Software Engineer II
Senior Software Engineer II

LexisNexis Risk Solutions • Town of Texas (WI)

Hybrid
USD 95,000 - 159,000
Senior Identity & Access Architect
Senior Identity & Access Architect

OEC • United States

Hybrid
USD 140,000 - 190,000