Rodeo
Get started

Ditto

Senior Principal Engineer - Agentic AI

Remote
Posted about 20 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Ditto

At Ditto, we're redefining digital trust. Our unified identity platform helps banks, financial institutions, governments and other regulated organisations verify identities, prevent fraud and deliver secure digital experiences through identity verification, authentication, passwordless access and mobile threat defence.

We're a global team with a startup mindset, led by CEO Gonzalo Alonso, on a mission to make digital trust simple, secure and accessible.

The Role

AI agents are beginning to act on behalf of people and businesses—making decisions, transacting, and connecting to other systems on their own. The identity tools most organisations rely on today were built for people or predictable machine identities, not autonomous agents.

Ditto is investing in an agentic identity platform to address this. We're hiring a Senior Principal Engineer to help design and build it—hands-on—drawing on Ditto's heritage in identity, device binding, runtime protection and continuous authentication, and using large language models as a genuine force-multiplier for the research and the delivery.

In one line: own the design and hands-on build of the platform's hardest capabilities—verifiable agent identity, instance integrity, and continuous runtime trust—on a modern, standards-based foundation, moving at real pace.

Where You'll Make an Impact

In this role, you'll:

  • Help set the technical direction and architecture for the platform, and make sound build/buy calls under uncertainty.
  • Integrate with existing enterprise identity providers and open standards rather than reinventing them, keeping external systems behind adapters so implementations can evolve as standards mature.
  • Grow and mentor the team that scales the platform—a genuine principal-level remit.
  • Engage the broader standards and security community to keep the work current, credible and interoperable.

What You'll Work With

A fast-moving standards landscape, spanning agent & workload identity, authentication, delegation, attestation, continuous trust, agent interop, provenance and EU regulation. You won't start from a blank page—several capabilities extend foundations Ditto has shipped for years in identity, device binding, runtime protection and continuous authentication.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Agent & workload identity: SPIFFE / SVID, workload identity, DID / VC, W3C agent identity work

AuthN & credentials: OAuth 2.1, OIDC, PKI, FIDO2 / WebAuthn, mTLS, sender-constrained tokens (DPoP)

Delegation & authorization: Token exchange (RFC 8693), on-behalf-of, CIBA, policy-based authorization

Attestation & integrity: Hardware attestation, TEEs (SEV-SNP, TDX, Nitro, Secure Enclave), RASP

Continuous trust: Shared Signals / CAEP, continuous & risk-based authentication

Agent interop: MCP, agent-to-agent protocols and the identity work around them

Provenance: Tamper-evident logs, software supply-chain attestation (SLSA / Sigstore)

Regulatory (EU): EU AI Act, eIDAS 2.0 / EUDI wallet, GDPR, DORA

LLMs are core to how this role works, not a novelty: synthesizing fast-moving specs and vendor landscapes into build/buy decisions, driving threat models (OWASP NHI, Agentic Top 10) mapped to the property that defeats each attack, and accelerating delivery from spec to a working, demonstrable slice—always verified against primary sources, especially for crypto and security-critical logic.

Who You Are

You're someone who:

  • Builds evidence-first—shipping small, demonstrable increments and letting each one earn the next, rather than making big up-front bets.
  • Reasons clearly from primary-source specs in a fast-moving, still-forming standards landscape.
  • Uses LLMs deliberately and rigorously, and knows exactly where their output must be verified against primary sources.
  • Is comfortable owning ambiguity at principal level—architecting and shipping, and mentoring a team along the way.

What We're Looking For

Must-have:

  • 10+ years building production distributed systems, platform, or security infrastructure, with principal-level technical ownership—architecting and shipping, not only advising.
  • Deep identity & authorization expertise: OAuth 2.1 / OIDC, token exchange and on-behalf-of flows, sender-constrained tokens, PKI, FIDO2 / WebAuthn, mTLS, and workload identity.
  • Applied cryptography in practice: credential formats, binding proofs, key lifecycle and rotation, and clear reasoning about what a construction does and does not prove.
  • Hands-on depth in at least one differentiating area: hardware attestation / TEEs, RASP, or continuous / risk-based authentication and shared signals.
  • Demonstrated fluency leveraging LLMs for rigorous technical research and for building, with the judgement to verify output against primary sources.
  • Fluent English, spoken and written; based in Europe (EU / EEA) and able to work across European time zones with a mostly-overlapping team.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Bonus Points

  • Fluent or native Spanish, spoken and written—valuable across our Spanish-speaking European and LATAM customers and partners.
  • Experience with agent ecosystems and protocols (MCP, agent-to-agent) and the identity work around them.
  • Decentralised identity (DID / VC) and eIDAS 2.0 / EUDI wallet models.
  • EU regulatory fluency—EU AI Act, DORA, GDPR—and experience building audit and traceability in from day one.
  • Participation in standards bodies (e.g. IETF, OWASP) or relevant open-source contribution.

Why Join Ditto

A rare mandate to help define and build a category-shaping platform on an open, still-forming standards landscape—with principal-level ownership of architecture and technical direction, and a path to build and lead the team. You'll build on foundations Ditto has shipped for years in identity, device binding, runtime protection and continuous authentication, rather than starting from scratch.

We value ownership, curiosity and collaboration, giving our people the freedom to make decisions, challenge ideas and grow their careers while helping build the future of digital trust.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Identity and Access Management
OAuth 2.1
OIDC
PKI
FIDO2
WebAuthn
mTLS
Distributed Systems
Cryptography
Hardware Attestation
TEEs
RASP
Large Language Models
Security Infrastructure
Cloud Security
Standards Compliance

Location

United Kingdom

Sign up to applySee more jobs like this