THE ROLE
We are hiring a Senior AI Security Python Developer to contribute our AI Security Solution.
This is a pure developer role.You will design and build the authentication and authorization layer for AI systems: writing Python code, architecting OAuth 2.0 / OIDC flows, developing SDKs and integration tooling, and leading technical customer engagements end-to-end. You will implement modern access management protocols, build AWS-native security infrastructure, and help customers integrate our solutions into their AI agent applications.
You will work across the full stack of our security platform: the OAuth 2.1 authorization layer, the A2A trust model for multi-agent systems, the MCP security layer for tool access control, the SPIFFE/SPIRE workload identity infrastructure on AWS, and the SDK surface that developers use to embed all of this into their applications.
This role requires depth in both access management standards and software engineering. If your background is primarily in IAM administration, IT operations, or security monitoring - this is not the right fit. We need someone who has implemented auth protocols in code and built security infrastructure from the ground up.
You are the right fit if you have:
- Implemented OAuth 2.0 / 2.1 flows in Python - authorization servers, token endpoints, introspection, revocation
- Built or secured APIs with access management baked in - not configured through a portal, but written in code
- Worked with AWS security services (IAM, STS, Cognito, Secrets Manager, KMS) in production
- Designed or deployed workload identity or mutual TLS in cloud-native environments
- Ideally: exposure to SPIFFE/SPIRE, MCP, A2A protocols, or AI agent security
WHAT YOU WILL DO
AI Security Development
- Implement and extend OAuth 2.1 authorization flows within the solution - token issuance, validation, refresh, revocation, PKCE, dynamic client registration, and custom scope and claims design
- Build the A2A (Agent-to-Agent) authentication layer - mutual identity verification, trust chain validation, and secure context propagation across multi-step agentic workflows
- Develop MCP (Model Context Protocol) security controls - authenticating and authorizing tool calls made by AI agents to external APIs, databases, and services
- Implement SPIFFE/SPIRE workload identity on AWS - issuing and managing SVIDs, integrating the SPIRE agent with EKS / ECS workloads, and enforcing mTLS between services
- Design and implement machine identity management for AI workloads - short-lived credentials, ephemeral tokens, and automated rotation for service accounts and API keys
- Write Python components that developers embed into their AI agent applications to get authentication and authorization without reimplementing security primitives
AWS Security Infrastructure
- Build and maintain the AWS infrastructure that underpins the platform - IAM roles, STS assume-role flows, Cognito user pools / identity pools, Secrets Manager, KMS key policies, and API Gateway authorizers
- Implement fine-grained access policies for AI workloads on AWS - least-privilege IAM policies, resource-based policies, and service control policies for multi-account deployments
- Design and automate secrets lifecycle management - dynamic credential generation, rotation policies, and integration with AI agent runtimes
- Contribute to infrastructure-as-code for security components using Terraform or AWS CDK - reproducible, reviewable, auditable
Customer Integration & Technical Delivery
- Lead technical integration engagements with enterprise customers - helping them embed/ integrate the SDK into their AI agent applications and integrate with their existing AWS and identity infrastructure
- Own the integration lifecycle from architecture design through code, testing, deployment, and handover - producing clean, documented, production-ready deliverables
- Build reusable integration patterns, reference implementations, and developer documentation that reduce the effort of future customer onboardings
- Debug complex authentication failures, token flow issues, and workload identity problems in customer production environments
Security Engineering
- Conduct threat modelling for AI-specific attack surfaces - prompt injection leading to authorization bypass, cross-agent credential theft, SPIFFE SVID spoofing, MCP tool abuse
- Enforce zero-trust principles throughout the codebase - validate identity on every call, design for least privilege, assume breach
- Mentor peers on access management protocol internals, AWS security patterns, and AI security concepts
- Contribute to Vivid's internal security guidelines, architecture documentation, and customer-facing developer guides
TECHNICAL SKILLS
Required - must have, + Advantage - strong plus, No marker - nice to have
Python
Production Python - security services, SDKs, REST APIs, automation. Well-tested, maintainable, code others build on.
OAuth 2.1 / OIDC
Authorisation server implementation, token flows (PKCE, client credentials, device), introspection, revocation, scopes/claims design - in code
Access Management
OAuth 2.0/2.1, OIDC, SAML 2.0, JWT, mTLS - understanding the standards deeply, not just using them through a UI
AWS Security
IAM roles & policies, STS, Cognito, Secrets Manager, KMS, API Gateway authorizers, Security Hub - production experience
SPIFFE / SPIRE +
Workload identity, SVID issuance, SPIRE agent/server deployment, trust domain configuration, integration with K8s/ECS/EKS
A2A Protocols +
Agent-to-agent authentication and trust models - emerging standards for multi-agent system identity and delegation
MCP Security +
Model Context Protocol - securing tool access for AI agents, auth for MCP servers, scoping tool permissions
Okta / Auth0 +
Hands-on integration experience using their APIs and SDKs - an advantage, not a requirement
Go +
Go for performance-critical security components alongside Python
Cryptography +
Applied crypto: RS256/ES256 signing, key rotation, PKI, TLS/mTLS, certificate lifecycle in production systems
Docker / K8s
Containerised security workloads, K8s RBAC, pod identity, service mesh basics for mTLS enforcement
Terraform / CDK
Infrastructure-as-code for AWS security components - IAM, KMS, Secrets Manager, VPC security groups
WHAT WE ARE NOT LOOKING FOR
Please do not apply if your experience is primarily:
- IAM administration - Okta, SailPoint, or Azure AD configuration through admin UIs, not code
- L1 / L2 / L3 access management support - help desk, access requests, ticket queues
- SOC analyst, SIEM monitoring, threat detection, or incident response roles
- User provisioning / de-provisioning / access certification operations
- Cloud infrastructure without security depth - EC2/S3 management is not what this role needs
We respect these backgrounds - they simply do not match what this role builds.