AI-Augmented IAM Security Engineer
Brak informacji o wynagrodzeniu
MidFull-time
#441080·Dodano wczoraj·0
Źródło: justjoin.itTech Stack / Keywords
Identity and Access ManagementPrivileged Access ManagementSAMLOAuth 2.0OpenId ConnectLDAPPythonSCIMPowershellTerraform
Firma i stanowisko
EPAM Systems is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. The company has over thirty years of expertise in custom software, product and platform engineering, empowering clients to become AI-Native enterprises.
Wymagania
- Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
- 2+ years hands-on experience implementing or operating Identity and Access Management solutions
- Experience with at least one enterprise IAM, IGA, PAM or federation platform
- Understanding of IAM concepts including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege and privileged access
- Knowledge of IAM protocols and standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
- Experience configuring IAM controls, policies, connectors and governance workflows
- Working knowledge of cloud IAM concepts on at least one major cloud platform (Azure, AWS, GCP)
- Scripting and automation experience with at least one of PowerShell, Python, Bash, REST APIs, SCIM or Terraform
- Ability to collaborate with developers, architects, security operations, compliance teams, and business stakeholders
- Competency to follow, maintain and improve IAM and security processes including executing changes from tickets and runbooks
- Practical understanding of AI-assisted productivity and automation including building AI agents, integrating LLMs, prompt engineering and secure AI tool use
- Good communication skills to explain IAM issues and technical decisions to technical and non-technical stakeholders
Nice to have:
- Familiarity with IAM platforms like Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk
- Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios
- Experience with SIEM/SOAR integrations for IAM monitoring and automated response
- Experience with CI/CD-based IAM deployment, configuration-as-code and automated testing
- Familiarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, Power Automate
- Understanding of AI security risks including data leakage, prompt injection, and sensitive identity data exposure
- Certifications such as SC-300, Okta Certified Professional/Administrator/Consultant, SailPoint, Saviynt, CyberArk, Ping Identity, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, AWS Certified AI Practitioner
Obowiązki
- Implement, configure and operate IAM solutions and controls based on designs defined by IAM architects and security leadership
- Maintain identity lifecycle processes including automated provisioning and deprovisioning
- Configure core IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC, and least-privilege access
- Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, source systems, databases, and APIs
- Execute access certification campaigns, perform entitlement clean-up, and configure segregation-of-duties rules
- Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, and just-in-time access
- Develop automation scripts and workflows using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
- Monitor IAM platform health, troubleshoot incidents, and perform patching, upgrades, and configuration hardening
- Maintain IAM logging, alerting, monitoring, backups, and recovery procedures
- Deploy AI-assisted automations and agentic workflows to reduce manual IAM operation efforts
- Integrate AI agents and LLM-backed automations into IAM systems and pipelines using function calling, SCIM, REST and webhooks
- Develop and maintain reusable prompts and structured-prompting patterns for AI assistants
- Implement output verification, human-in-the-loop approvals, and rollback paths for AI-assisted workflows
- Implement security and privacy controls for IAM AI usage including access controls and auditability
- Monitor and tune AI-assisted IAM automations, and produce operational documentation and compliance evidence
Benefity
- Hybrid work mode with opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including thought leadership, mentoring, soft skills, and well-being
- Certifications (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay
- Participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee
- Corporate, social and well-being events
Elastyczne godziny
Pakiet relokacyjny
Budżet konferencyjny
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Opieka zdrowotna
Ubezpieczenie
Udziały pracownicze
Premie
Darmowe przekąski
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie.
EPAM Systems
869 aktywnych ofert