AI-Augmented IAM Security Engineer

Brak informacji o wynagrodzeniu
MidFull-time
#441067·Dodano wczoraj·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Identity and Access ManagementPrivileged Access ManagementSSOSAMLOAuth 2.0OpenId ConnectSCIMPython

Firma i stanowisko

EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, EPAM empowers clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Wymagania

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
  • 2+ years of hands-on experience implementing or operating Identity and Access Management solutions
  • Experience with at least one enterprise IAM, IGA, PAM or federation platform
  • Understanding of IAM concepts: identity lifecycle, authentication and authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, privileged access
  • Knowledge of IAM protocols and standards: SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos
  • Experience configuring IAM controls, policies, connectors and access governance workflows
  • Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS or GCP
  • Scripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM or Terraform
  • Ability to collaborate effectively with developers, architects, infrastructure engineers, security operations, compliance teams and business stakeholders
  • Competency to follow, maintain and improve defined IAM and security processes, execute changes from tickets, runbooks and designs, and escalate design-level questions
  • Practical understanding of AI-assisted productivity and automation including AI agents, automated IAM tasks, LLM integration, prompt engineering, and secure AI usage with sensitive identity data awareness
  • Good communication skills to explain IAM issues, technical decisions and remediation steps to both technical and non-technical stakeholders

Nice to have:

  • Familiarity with IAM platforms: Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk
  • Experience with CIAM, B2B/B2C identity, customer identity, external identity, partner access scenarios; SIEM/SOAR integrations for IAM monitoring, alerting, automated response
  • Experience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changes
  • Familiarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, Power Automate
  • Understanding AI security risks including data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposure
  • Relevant certifications: SC-300, Okta Certified Professional / Administrator / Consultant, SailPoint, Saviynt, CyberArk, Ping Identity, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, AWS Certified AI Practitioner

Obowiązki

  • Implement, configure, and operate IAM solutions and controls based on architecture, standards, and designs defined by IAM architects and security leadership
  • Maintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning
  • Configure core IAM capabilities including SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access
  • Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases, and APIs
  • Execute access certification and review campaigns, perform entitlement clean-up, and configure segregation-of-duties (SoD) rules
  • Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, just-in-time and just-enough access
  • Develop automation scripts, workflows, and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
  • Monitor IAM platform health, troubleshoot incidents and access issues, and perform patching, upgrades, and configuration hardening
  • Maintain IAM logging, alerting and monitoring, and run backup and recovery procedures
  • Deploy AI-assisted automations and agentic workflows reducing manual effort in IAM operations such as access request triage, entitlement analysis, anomaly detection, root-cause analysis, privileged access review support, compliance evidence collection, and documentation generation
  • Integrate AI agents and LLM-backed automations into IAM systems and operational pipelines using function calling, SCIM, REST and webhooks
  • Develop and maintain reusable prompts, structured-prompting patterns and prompt templates; implement retrieval over IAM policies, role catalogs, runbooks, and documentation (e.g., RAG)
  • Implement output verification, human-in-the-loop approval gates, and rollback paths in AI-assisted IAM workflows
  • Implement security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data and auditability
  • Monitor AI-assisted IAM automations in production, measure accuracy and impact, tune prompts, tools, workflows, and produce operational documentation while supporting audits and compliance

Benefity

  • Hybrid by design with opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including certification (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee and more
  • Corporate, social and well-being events
Elastyczne godziny
Pakiet relokacyjny
Szkolenia wewnętrzne
Budżet konferencyjny
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Opieka zdrowotna
Ubezpieczenie
Premie
Udziały pracownicze
Darmowe przekąski

Inne informacje

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności.

EPAM Systems

EPAM Systems

880 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz