First seen by Alion on Sep 30, 2026.
Technology stack
AWS AgentCore Policy, Cedar, Python, Microsoft Entra ID, OAuth 2.0, JWT, OpenID Connect, Open Policy Agent, AWS AgentCore Gateway, LangGraph, Identity Providers, Audit Logging Frameworks
Project overview
The project focuses on delivering a centralized authorization framework for enterprise AI services and cloud applications. The platform provides secure policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.
Team
Medium team (10-20 people)
You will work with security engineers, backend developers, platform engineers, architects, and governance specialists. The team follows a collaborative development approach, emphasizing policy as code, automation, secure design practices, and continuous improvement.
Position overview
We are looking for a Security Engineer to support the implementation and governance of policy based authorization solutions for enterprise AI and cloud platforms. In this role, you will work with identity, security, and platform teams to develop authorization policies, integrate identity providers, and help build secure access control mechanisms using modern policy frameworks.
Responsibilities
Develop and maintain authorization policies using the Cedar policy language
Author, test, and validate policy definitions for enterprise applications and AI services
Implement and support access control models using attribute based and role based authorization approaches
Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito
Map identity claims and token attributes to authorization decisions and policy rules
Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes
Develop Python based tooling for policy validation, testing, and automation
Design and implement parameter level access control patterns for secure tool and service interactions
Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls
Contribute to audit logging and authorization decision traceability practices
Support security reviews and help maintain authorization governance standards
Requirements
3+ years of experience in security engineering, backend engineering, or a related field
Hands on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito
Experience defining and managing policies within an ABAC or RBAC authorization framework
Hands on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies
Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures
Experience working with claims mapping and token based authorization models
Understanding of secure authorization design principles and policy lifecycle management
Experience with Python development for automation, validation, or backend services
Strong analytical and problem solving skills
Good written and verbal communication skills
Nice to have
Experience with LangGraph tool invocation patterns
Experience integrating with AWS AgentCore Gateway
Knowledge of enterprise AI platform architecture and governance principles
Experience implementing policy as code methodologies
Familiarity with cloud native security services and authorization platforms
Exposure to audit logging and compliance reporting requirements
What We Offer:
Vacation days: Up to 26 business days per year.
10 illness/special days
off per year (fully paid, no medical papers needed) for all contract types
Health and life insurance (Luxmed)
MyBenefit platform with Multisport option
Internal psychological support service
English language classes from the first working day
Access to external learning platforms: O'Reilly, LinkedIn Learning, Udemy, and a wide catalog of diverse internal training
Flexible workplace: work from the office, from home, or choose a hybrid option
Tech Skills Mentoring Program
Opportunities to develop as a public speaker, mentor, or technical interviewer
Fully paid idle (bench) when not involved in a project
Certification reimbursement (AWS, GCP, Microsoft, etc.)

