- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We seek an experienced Security / Policy Engineer skilled in designing and deploying authorization frameworks for AI agents and cloud-based platforms. The role emphasizes expertise in AWS AgentCore Policy (Cedar), policy-as-code methodologies, OAuth/JWT authorization schemes, and zero-trust security architectures. Ideal candidates have solid experience in cloud security, identity engineering, attribute-based access control (ABAC), and managing enterprise-level access control solutions.
Project Context
Our client is a century-old multinational with offices spanning over 180 countries, pursuing a major initiative to launch Reduced-Risk Products targeting more than 1 billion consumers worldwide. Their IT infrastructure supports over 700 applications.
Intellias' contribution involves engineering a comprehensive software ecosystem for an innovative IoT product that merges cutting-edge technology with enhanced consumer experiences. You will join the Core Architecture Team, contributing to the development and adoption of best practices within the Digital Engineering Enterprise Platform, which streamlines software development and deployment while ensuring compliance and operational excellence.
Key Responsibilities
- Architect and implement authorization policies using Cedar language and AWS AgentCore Policy.
- Create and manage policy-as-code frameworks for cloud-native infrastructures and AI agent environments.
- Develop and enforce Attribute-Based Access Control (ABAC) models centered on least-privilege and default-deny approaches.
- Integrate authorization systems with OAuth 2.0, JWT, and Microsoft Entra ID mechanisms.
- Define and maintain principals, resources, actions, and conditional policies governing access control.
- Design workflows for token validation, claims mapping, and authorization decisions.
- Implement audit logging and trace mechanisms for policy evaluations and access events.
- Collaborate closely with security, architectural, and platform teams to facilitate enterprise security reviews and governance compliance.
- Contribute to advancing zero-trust security frameworks and authorization strategies in distributed systems.
- Assess and adopt emerging AWS authorization tools, including the open-source Cedar and AWS Verified Permissions technologies.
Experience and Requirements
- Minimum of 5 years experience in cloud security or identity engineering roles.
- Proficiency in ABAC design and implementation.
- Expertise in OAuth 2.0, JWT token analysis, and claims mapping.
- Experience conducting enterprise security reviews, including InfoSec and Architecture Review Board (ARB) processes.
- Familiarity with AWS AgentCore Policy and Cedar policy language, including principals, actions, resources, and conditions.
- Understanding of policy-as-code patterns and design of default-deny authorization models.
- Knowledge of audit logging pertinent to policy decision-making.
Preferred Qualifications
- Previous exposure to the open-source AWS Cedar project.
- Experience with AWS Verified Permissions or early use of AgentCore Policy.
- Background in designing zero-trust security architectures.