Security / Policy Engineer (with Cedar)

On-siteSalary not specified
Canada · Bulgaria · Croatia · Cyprus

Tech Stack

JWTAWS

Job Description, Responsibilities & Requirements

About the Position

We are looking for a Security / Policy Engineer to design and implement authorization models for AI agents and cloud-native platforms. The role focuses on AWS AgentCore Policy (Cedar), policy-as-code, OAuth/JWT-based authorization, and zero-trust security architecture. The ideal candidate has hands-on experience with cloud security, identity engineering, ABAC design, and enterprise-grade access control systems.

Responsibilities

  • Design and implement authorization policies using Cedar and AWS AgentCore Policy.
  • Develop and maintain policy-as-code frameworks for cloud-native and AI-agent platforms.
  • Build and govern Attribute-Based Access Control (ABAC) models following least-privilege and default-deny principles.
  • Integrate authorization systems with OAuth 2.0, JWT, and Microsoft Entra ID.
  • Define and maintain principals, resources, actions, and conditional access policies.
  • Design token validation, claims mapping, and authorization decision workflows.
  • Implement audit logging and traceability for policy evaluation and access decisions.
  • Partner with security, architecture, and platform teams to support enterprise security reviews and governance processes.
  • Contribute to zero-trust security architecture and authorization strategy across distributed systems.
  • Evaluate and adopt emerging AWS authorization technologies, including Cedar and AWS Verified Permissions.

Requirements

  • Core Skills:

    • AWS AgentCore Policy (Cedar)
    • Cedar policy language
    • OAuth 2.0 / JWT / MS Entra integration
    • Policy-as-code patterns
    • Default-deny authorization models
    • Audit logging for policy decisions
  • Experience:

    • 5+ years cloud security or identity engineering
    • Attribute-based access control (ABAC) design
    • OAuth 2.0 / JWT token inspection and claims mapping
    • Enterprise security review (InfoSec, ARB processes)
  • Will be a plus:

    • AWS Cedar (open source) prior exposure
    • AWS Verified Permissions or AgentCore Policy early experience
    • Zero-trust architecture design

We Offer

  • Competitive salary
  • Opportunity to work with a multinational corporation
  • Remote work options
  • Professional growth and development opportunities

About the Company

At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.

Join Intellias for a career where your perspectives and contributions are vital to our shared success.

Job Details

Company name:
Intellias
Location:
Canada · Bulgaria · Croatia · Cyprus
Work Mode:
On-site
Posted on TheJob:
Jul 13, 2026
Last checked:
Jul 13, 2026
Apply Now
© 2026 TheJob, Inc. All rights reserved.