Our Customer: Seed-stage company building a security gateway for AI agents, enforcing enterprise-grade access, observability, and compliance for AI tool usage. This role works closely with the gateway team to implement policy and authorization across users, tenants, and tools.
Your Tasks: * Build and maintain the policy and authorization layer for MCP Gateway interactions; * Implement fine-grained access control (per tool, per user, per tenant); * Develop and maintain a TypeScript SDK bridging MCP protocol flows; * Integrate authorization with agent posture, activity monitoring, and observability; * Implement distributed tracing, metrics, and audit logging for compliance; * Collaborate with gateway engineers to ensure consistent enforcement across the platform.
Required Experience and Skills: * 5+ years in software engineering, with experience in backend or full-stack development; * Strong proficiency in Python and TypeScript/React, including SDK/API development; * Experience with cloud infrastructure (AWS, containers, IaC, CI/CD); * Familiarity with access control models (RBAC, ABAC) and identity integration (OIDC, OAuth 2.0, SAML); * English — Upper-Intermediate.
Would Be a Plus: * Hands-on experience with policy engines (Cedar, OPA/Rego); * Previous work on MCP servers, gateways, or protocol-based systems; * Contributions to open-source authorization or policy frameworks; * Experience implementing security/compliance standards (SOC 2, HIPAA, FedRAMP); * Startup experience with comfort in high-ambiguity, fast-moving environments.
Working Conditions: * Remote work; * 5-day working week, 8-hour working day, flexible schedule; * All public holidays are days off; * Vacation and sick leave are covered by the company.