Platform (Security) Engineer – Agentic Security & Enforcement
On-site in Portugal·Added 8 days ago
Overview
Requirements
Work on-site in Portugal
No relocation package mentioned.
Have 4+ years of experience
Mid-level role.
The role
We are looking for a Platform Engineer specializing in Agentic Security & Enforcement to help build the security foundation of an enterprise AI Agent Platform from the ground up. The role will focus on protecting agent-to-tool and agent-to-agent interactions through strong authorization, identity, credential management, and gateway enforcement mechanisms.
You will work on establishing zero-trust security patterns for AI agents, ensuring that agents can access only authorized tools and resources while credentials remain securely managed outside of the agent environment.
Our client is a large global enterprise operating across multiple markets, with a complex technology landscape and a strong focus on digital transformation and innovation. The organization is actively investing in modern cloud, data, and AI capabilities to enable scalable, secure, and highly automated solutions across its business.
The project is focused on building an enterprise-grade AI Agent Platform from the ground up. The platform will provide a standardized foundation for developing, deploying, orchestrating, securing, and observing AI agents across multiple teams and use cases.
The initiative covers the full agent lifecycle and brings together agent orchestration, observability, security, governance, integrations, evaluation, and platform engineering. Engineers joining the project will have an opportunity to influence key architectural and technical decisions and contribute to a new platform rather than maintaining an existing solution.
What you'll do
- Design and implement authorization mechanisms for agent-to-tool interactions, including tool-level access control.
- Define and enforce Cedar-based policies governing agent permissions and tool access.
- Implement secure agent identity and authentication, including JWT validation and service-to-service trust.
- Design credential management patterns for OAuth tokens, API keys, and AWS IAM roles, ensuring credentials are never exposed directly to agents.
- Implement secure storage and rotation of per-tool and per-target credentials using AWS secrets management capabilities.
- Enforce gateway-based access patterns to prevent agents from bypassing security controls and directly accessing protected tools.
- Implement security controls for MCP tool invocation, including authentication and authorization.
- Build auditability capabilities for agent workflows, tool invocations, and agent-to-agent interactions.
- Support security tracing and observability across agent workflows.
- Contribute to zero-trust architecture and security standards for the AI Agent Platform.
- Collaborate with platform and engineering teams to embed security controls into agent integration and execution flows.
Skills
• Agentic authorization — Cedar policy engine for agent-to-tool permissions, tool-level access control
• Agent credential management — per-tool OAuth tokens, API keys, IAM roles (never exposed to agents)
• Agent identity — JWT validation, cross-agent authentication, service-to-service trust
• Agentic audit — tracing agent workflows, tool invocation logging, agent-to-agent interaction tracking
• Gateway enforcement — ensuring agents cannot bypass the gateway to reach tools directly
• AWS secrets management — per-target credential storage and rotation
Experience
• 4+ years security engineering in AI/ML or agent platforms
• Implemented authorization systems for API or tool access
• Credential management and secret rotation patterns
• Agent workflow observability and tracing
Nice to have
• Cedar policy language or OPA for agent authorization
• AWS Bedrock AgentCore policy configuration
• Agent-to-agent authentication patterns
• Zero-trust architecture for agentic systems
• MCP protocol security (authentication, authorization at tool invocation)
About Intellias
Intellias is an AI-enabled product engineering and digital solutions partner, operating in the IT services industry. The company has over 20 years of engineering experience, employs more than 3,000 AI-enabled engineers, and serves over 170 enterprise clients worldwide. Intellias delivers digital products across mobility, healthcare and life sciences, financial services and insurance, retail, and iGaming, with a global network spanning 17 countries and 23 offices.
Intellias has a presence in Spain, with a validated office location in Malaga. The company's global delivery model and focus on senior engineering talent make it a relevant employer for international professionals, particularly those with expertise in software engineering, data engineering, AI/ML, and cloud infrastructure. With roles open in Spain across various engineering and architecture disciplines, Intellias offers opportunities for experienced professionals to work on complex, enterprise-scale projects.
- Industry
- IT Services
- Founded
- 2002
- Employees
- 3,000–5,000
- Headquarters
- Lviv, Ukraine
- Website
- intellias.com
In their own words
Additional information
At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. That’s why we offer a range of benefits that support your well-being and charge your professional growth.
We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.
We welcome and celebrate the uniqueness of every individual. Join Intellias for a career where your perspectives and contributions are vital to our shared success.
More jobs like this
or browse Security·Mid-level·Cybersecurity·IT Services

