Jobgether
Staff Product Engineer, Agentic Identity & Governance, AI Platform
- Compensation
- $220K–$260K / yr
- From job posting
- Location
- CA
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Staff
- Posted
- 30 September 2026 (today)
Checked todayApplications go to the employer, never to RoleSprint
About this role
Accountabilities: • Own the technical direction for authentication (AuthN), authorization (AuthZ), and on-behalf-of (OBO) access across the agentic data platform and cloud platform.
• Evaluate emerging identity and authorization patterns and determine which approaches should be adopted, adapted, or deliberately avoided.
• Design, build, and ship production systems supporting OAuth 2.1 authorization, token management, delegated tool access, and cryptographic delegation models.
• Develop mechanisms that allow AI agents to act on behalf of humans or other agents while maintaining a provable and auditable chain of authority.
• Build identity-federation capabilities that integrate effectively with enterprise identity providers such as Okta, Microsoft Entra, Ping, and similar platforms.
• Ensure identity and authorization architecture meets the requirements of security-conscious enterprise customers.
• Partner closely with engineering, security, product, and other cross-functional teams to validate technical decisions against real-world customer requirements.
• Represent the organization's technical perspective on agent identity through customer security discussions, technical documentation, and relevant industry or standards initiatives.
• Drive initiatives through production delivery, with success measured by reliable, scalable systems shipped to customers.
• Influence technical direction across multiple engineering teams without relying on formal reporting authority.
• Mentor engineers across the agentic data and cloud platform teams on identity, access management, authorization, and delegation concepts.
• Identify systemic technical challenges and communicate risks, impediments, mitigation plans, and contingency strategies to engineering leadership.
• Participate in strategic technical discussions with senior engineering peers and directors to help shape the broader engineering environment.
• Track progress and proactively communicate the status, risks, dependencies, and outcomes of initiatives under your ownership.
Requirements:
• 10+ years of software development and delivery experience, including deep hands-on expertise in authentication, authorization, identity, or access-management systems.
• Production experience with OAuth 2.0/2.1, OIDC, token exchange, delegation patterns, or related identity protocols.
• Practical experience operating authorization servers, token-management infrastructure, or comparable identity systems at scale.
• Strong understanding of token exchange and on-behalf-of patterns, including standards such as RFC 8693.
• Current knowledge of emerging agent identity and authorization approaches, including MCP authentication, A2A, cross-application access, and related token-exchange patterns.
• Ability to make sound technical decisions in areas where industry standards and best practices are still evolving.
• Experience designing identity systems that federate with, rather than replace, enterprise identity providers such as Okta, Microsoft Entra, Ping, or similar technologies.
• Demonstrated Staff- or Principal-level individual contributor experience driving technical direction across multiple teams or engineering organizations.
• Strong ability to lead through influence using technical proposals, RFCs, architecture discussions, code, and direct collaboration.
• Experience working with globally distributed engineering teams and collaborating effectively in open, GitHub-based development environments.
• Excellent written and verbal communication skills, including the ability to explain complex identity and delegation concepts to engineers, security professionals, and customers with varying technical backgrounds.
• Strong ownership, accountability, self-direction, and execution skills.
• Ability to thrive in a fast-moving environment where priorities, technologies, and industry standards evolve rapidly.
• Direct experience with agent-specific identity or delegation protocols is highly valuable.
• Experience contributing to or closely following relevant identity, OAuth, or agent-authorization standards bodies and working groups is an advantage.
• Experience working in regulated or security-sensitive enterprise environments is a plus.
• Prior experience influencing technical direction across multiple engineering organizations is strongly valued.
Benefits:
• Competitive U.S. base salary range of $220,000–$260,000, with the specific range determined by location, role level, experience, skills, education, and training.
• Fully remote work opportunity for candidates based in Canada.
• High-autonomy Staff-level individual contributor position with broad technical ownership and influence.
• Opportunity to shape emerging standards and technical approaches in agentic identity, authorization, and AI governance.
• Hands-on ownership of production systems with direct customer impact.
• Opportunity to collaborate with globally distributed engineering, security, product, and cloud platform teams.
• Access to modern AI tools and resources designed to support engineering productivity.
• Learning and professional development opportunities in a rapidly evolving technical domain.
• Culture emphasizing trust, transparency, communication, collaboration, and kindness.
• Opportunity to mentor engineers and influence technical practices across multiple teams.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- CA
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 30 September 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.