Staff Product Engineer, Agentic Identity

6 days ago

Montréal QC, Montreal Regional Municipality, QC; Montréal region; Québec Province, Canada Lever, Inc. Full-time €220,000 - €260,000

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Product Engineer, Agentic Identity & Governance, AI Platform based in Canada.

As a Staff Product Engineer, you will own the technical direction for identity, authorization, and delegation systems powering enterprise AI agents.
You will shape how agents authenticate, access data, and act on behalf of humans or other agents in security-conscious production environments.
The role spans both the agentic data platform and cloud infrastructure, giving you broad technical influence across multiple engineering teams.
You will combine strategic architectural leadership with hands‑on engineering, designing and shipping production-hardened systems rather than stopping at technical proposals.
You will work at the intersection of rapidly evolving agent identity standards, enterprise security requirements, and practical customer needs.
This is a high‑autonomy individual contributor role where you will influence technical decisions through code, RFCs, design work, and collaboration.
You will also mentor engineers and help define the future of identity and governance for AI‑powered systems within a globally distributed engineering organization.

Accountabilities:
  • Own the technical direction for authentication (AuthN), authorization (AuthZ), and on-behalf-of (OBO) access across the agentic data platform and cloud platform.

  • Evaluate emerging identity and authorization patterns and determine which approaches should be adopted, adapted, or deliberately avoided.

  • Design, build, and ship production systems supporting OAuth 2.1 authorization, token management, delegated tool access, and cryptographic delegation models.

  • Develop mechanisms that allow AI agents to act on behalf of humans or other agents while maintaining a provable and auditable chain of authority.

  • Build identity-federation capabilities that integrate effectively with enterprise identity providers such as Okta, Microsoft Entra, Ping, and similar platforms.

  • Ensure identity and authorization architecture meets the requirements of security-conscious enterprise customers.

  • Partner closely with engineering, security, product, and other cross‑functional teams to validate technical decisions against real‑world customer requirements.

  • Represent the organization's technical perspective on agent identity through customer security discussions, technical documentation, and relevant industry or standards initiatives.

  • Drive initiatives through production delivery, with success measured by reliable, scalable systems shipped to customers.

  • Influence technical direction across multiple engineering teams without relying on formal reporting authority.

  • Mentor engineers across the agentic data and cloud platform teams on identity, access management, authorization, and delegation concepts.

  • Identify systemic technical challenges and communicate risks, impediments, mitigation plans, and contingency strategies to engineering leadership.

  • Participate in strategic technical discussions with senior engineering peers and directors to help shape the broader engineering environment.

  • Track progress and proactively communicate the status, risks, dependencies, and outcomes of initiatives under your ownership.

Requirements:

  • 10+ years of software development and delivery experience, including deep hands‑on expertise in authentication, authorization, identity, or access‑management systems.

  • Production experience with OAuth 2.0/2.1, OIDC, token exchange, delegation patterns, or related identity protocols.

  • Practical experience operating authorization servers, token‑management infrastructure, or comparable identity systems at scale.

  • Strong understanding of token exchange and on‑behalf‑of patterns, including standards such as RFC 8693.

  • Current knowledge of emerging agent identity and authorization approaches, including MCP authentication, A2A, cross‑application access, and related token‑exchange patterns.

  • &