AI-Augmented IAM Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups, with over thirty years of experience in custom software, product, and platform engineering to empower clients to become AI-native enterprises.
Wymagania
- Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent experience
- 2+ years hands-on experience implementing or operating IAM solutions
- Experience with at least one enterprise IAM, IGA, PAM, or federation platform
- Understanding of IAM concepts: identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, privileged access
- Knowledge of IAM protocols and standards: SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos
- Experience configuring IAM controls, policies, connectors, and governance workflows
- Working knowledge of cloud IAM concepts on major platforms such as Azure, AWS, or GCP
- Scripting and automation experience with PowerShell, Python, Bash, REST APIs, SCIM, or Terraform
- Capability to collaborate with developers, architects, infrastructure engineers, security, compliance, and business teams
- Ability to follow and improve defined IAM and security processes from tickets and runbooks
- Practical understanding of AI-assisted productivity and automation including AI agents, LLM integration, prompt engineering, and secure use of AI with sensitive data
- Good communication skills to explain technical IAM issues and decisions to technical and non-technical stakeholders
Nice to have:
- Familiarity with IAM platforms: Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk
- Experience with CIAM, B2B/B2C, customer identity, partner access scenarios, SIEM/SOAR for IAM
- Experience with CI/CD deployment, configuration-as-code, and automated testing of IAM changes
- Familiarity with AI/LLM platforms and frameworks like Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, Power Automate
- Understanding of AI security risks including data leakage, prompt injection, excessive agency, insecure tool use, model governance, and sensitive identity data exposure
- Certifications such as SC-300, Okta Certified Professional/Administrator/Consultant, SailPoint, Saviynt, CyberArk, Ping Identity, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, AWS Certified AI Practitioner
Obowiązki
- Implement, configure, and operate IAM solutions based on defined architectures and standards
- Maintain identity lifecycle processes including automated provisioning and deprovisioning
- Configure IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, and role models
- Develop and deploy IAM integrations and connectors with cloud platforms, SaaS, enterprise systems, directories, and APIs
- Execute access certification and entitlement clean-up, configure segregation-of-duties rules
- Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, and just-in-time access
- Develop automation scripts and workflows using PowerShell, Python, REST APIs, SCIM, Terraform, or similar
- Monitor platform health, troubleshoot incidents, perform patching, upgrades, and hardening
- Maintain logging, alerting, monitoring, and backup and recovery following runbooks
- Deploy AI-assisted automations reducing manual effort in IAM operations like access triage, anomaly detection, and compliance documentation
- Integrate AI agents and LLM automations into IAM systems using function calling, SCIM, REST, and webhooks
- Develop reusable prompt templates, structured prompting patterns, and implement retrieval over policies and documentation
- Implement output verification, human-in-the-loop approvals, and rollback paths for AI-driven changes
- Implement security and privacy controls for AI in IAM including least-privilege for agents and credentials, prompt-injection resistance, and auditability
- Monitor AI-assisted automations in production, tune prompts and workflows, and support audits and compliance evidence requests
Benefity
- Opportunity to join a team of top tech minds in AI, cloud, and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid work mode and remote work opportunity within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including mentoring, soft skills, and well-being
- Certification support (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay and participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment zones, table tennis, football, free snacks, and coffee
- Corporate, social, and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
897 aktywnych ofert