AI-Augmented IAM Security Engineer

Brak informacji o wynagrodzeniu
MidFull-time
#441154·Dodano 3 dni temu·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Identity and Access ManagementPrivileged Access ManagementSAMLOAuth 2.0OpenId ConnectSCIMLDAPPowershellPythonPrompt Engineering

Firma i stanowisko

EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, they empower clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Wymagania

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
  • 2+ years of hands-on experience implementing or operating Identity and Access Management solutions
  • Experience with at least one enterprise IAM, IGA, PAM or federation platform
  • Understanding of IAM concepts including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access
  • Knowledge of IAM protocols and standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
  • Experience configuring IAM controls, policies, connectors and access governance workflows
  • Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS, or GCP
  • Scripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM, or Terraform
  • Ability to collaborate with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders
  • Competency to follow and improve defined IAM and security processes executing changes from tickets, runbooks and designs
  • Practical understanding of AI-assisted productivity and automation including building AI agents, integrating LLMs, prompt engineering, and AI tools security
  • Good communication skills with the ability to explain IAM issues and remediation to both technical and non-technical audiences

Nice to have:

  • Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, or CyberArk
  • Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios, plus SIEM/SOAR integrations
  • Experience with CI/CD-based IAM deployment, configuration-as-code, and automated testing of IAM changes
  • Familiarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or Power Automate
  • Understanding of AI security risks including data leakage, prompt injection, excessive agency, insecure tool use, and model governance
  • Relevant certifications such as SC-300, Okta Certified Professional, SailPoint, Saviynt, CyberArk, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, or AWS Certified AI Practitioner

Obowiązki

  • Implement, configure, and operate IAM solutions and controls based on architecture, standards, and designs defined by IAM architects and security leadership
  • Maintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning across target systems
  • Configure core IAM capabilities, including SSO, federation, MFA and passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access
  • Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases, and APIs
  • Execute access certification and review campaigns, perform entitlement clean-up, and configure segregation-of-duties (SoD) rules according to access policies
  • Operate Privileged Access Management controls, including credential vaulting, secrets rotation, session management, and just-in-time and just-enough access
  • Develop automation scripts, workflows, and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
  • Monitor IAM platform health, troubleshoot and resolve incidents and access issues, and perform patching, upgrades, and configuration hardening
  • Maintain IAM logging, alerting and monitoring, and run backup and recovery procedures according to defined runbooks and resilience requirements
  • Deploy AI-assisted automations and agentic workflows to reduce manual effort across daily IAM operations
  • Integrate AI agents and LLM-backed automations into IAM systems and operational pipelines via function calling, SCIM, REST and webhooks
  • Develop and maintain reusable prompts, structured-prompting patterns and prompt templates for AI assistants
  • Implement output verification, human-in-the-loop approval gates, and rollback paths in AI-assisted IAM workflows
  • Implement security and privacy controls for IAM AI usage including least-privilege access for agents and prompt-injection resistance
  • Monitor AI-assisted IAM automations in production, tune prompts and workflows, and support audits and compliance evidence requests

Benefity

  • Hybrid work mode with opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs
  • Thought leadership, mentoring, soft skills, and well-being programs
  • Certification opportunities (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee, and more
  • Corporate, social, and well-being events
Elastyczne godziny
Pakiet relokacyjny
Budżet konferencyjny
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Opieka zdrowotna
Premie
Udziały pracownicze
Darmowe przekąski

Inne informacje

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności.

EPAM Systems

EPAM Systems

931 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz