Our Customer:
Seed-stage company building a security gateway for AI agents, enforcing enterprise-grade access, observability, and compliance for AI tool usage. This role works closely with the gateway team to implement policy and authorization across users, tenants, and tools.
Your Tasks:
- Build and maintain the policy and authorization layer for MCP Gateway interactions;
- Implement fine-grained access control (per tool, per user, per tenant);
- Develop and maintain a TypeScript SDK bridging MCP protocol flows;
- Integrate authorization with agent posture, activity monitoring, and observability;
- Implement distributed tracing, metrics, and audit logging for compliance;
- Collaborate with gateway engineers to ensure consistent enforcement across the platform.
Required Experience and Skills:
- 5+ years in software engineering, with experience in backend development;
- 2+ years working with authorization or security systems;
- Strong proficiency in TypeScript and Python, including SDK and API design;
- Experience with policy engines (CEL, Cedar, OPA/Rego or similar) and production RBAC / ABAC models;
- Experience with cloud infrastructure (AWS, containers, IaC, CI/CD);
- Familiarity with identity integration (OIDC, OAuth 2.0, SAML) and enterprise IdPs (Okta, Azure AD, Keycloak);
- Experience with observability stacks (Prometheus, OpenTelemetry);
- English — Upper-Intermediate.
Would Be a Plus:
- Rust experience or strong interest in learning Rust (core gateway / policy components);
- Hands-on experience with policy engines (CEL, Cedar, OPA/Rego);
- Previous work on MCP servers, gateways, or protocol-based systems;
- Protocol Buffers and xDS experience;
- AWS security services (IAM, Verified Permissions);
- Experience implementing security/compliance standards (SOC 2, HIPAA, FedRAMP);
- Contributions to open-source authorization or policy frameworks (cel-go, cel-rust, Open Policy Agent);
- Startup experience with comfort in high-ambiguity, fast-moving environments.
Working conditions
5-day working week, 8-hour working day, flexible schedule;
All UA public holidays are days off;
Vacation and sick leave are covered by the company;