AI-Augmented IAM Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. They have over thirty years of expertise in custom software, product, and platform engineering, empowering clients to become AI-Native enterprises.
Wymagania
- Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
- 2+ years of hands-on experience implementing or operating Identity and Access Management solutions
- Experience with at least one enterprise IAM, IGA, PAM or federation platform
- Understanding IAM concepts including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege and privileged access
- Knowledge of IAM protocols and standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
- Experience configuring IAM controls, policies, connectors, and access governance workflows
- Working knowledge of cloud IAM for at least one major platform such as Azure, AWS or GCP
- Scripting and automation experience using PowerShell, Python, Bash, REST APIs, SCIM or Terraform
- Ability to collaborate with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders
- Competency in following and improving IAM and security processes, executing changes from tickets, runbooks, and designs
- Practical understanding of AI-assisted productivity and automation including AI agents, LLM integration, prompt engineering, and secure AI tool usage
- Good communication skills to explain IAM issues and decisions to technical and non-technical stakeholders
Nice to have:
- Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk
- Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios
- Experience with SIEM/SOAR integrations for IAM monitoring and automated response
- Experience with CI/CD-based IAM deployment, configuration-as-code, and automated testing
- Familiarity with AI/LLM platforms like Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, Power Automate
- Understanding AI security risks including data leakage, prompt injection, excessive agency, insecure tool use, model governance, and sensitive data exposure
- Certifications such as SC-300, Okta Certified Professional/Administrator/Consultant, SailPoint, Saviynt, CyberArk, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, AWS Certified AI Practitioner
Obowiązki
- Implement, configure and operate IAM solutions and controls based on architecture and standards defined by IAM architects and security leadership
- Maintain identity lifecycle processes including automated provisioning and deprovisioning
- Configure core IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, and role models
- Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, databases, and APIs
- Execute access certification and reviews, entitlement clean-up, and configure segregation-of-duties rules
- Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, and just-in-time access
- Develop automation scripts, workflows and tooling using PowerShell, Python, REST APIs, SCIM, and Terraform
- Monitor IAM platform health, troubleshoot incidents, perform patching, upgrades, and configuration hardening
- Maintain IAM logging, alerting, monitoring, backup and recovery procedures
- Deploy AI-assisted automations and workflows to reduce manual effort in daily IAM operations
- Integrate AI agents and LLM-backed automations into IAM systems and operational pipelines via function calling, SCIM, REST, and webhooks
- Develop and maintain reusable prompts, structured-prompting patterns, and prompt templates for AI assistants
- Implement output verification, human-in-the-loop approval gates, and rollback paths in AI-assisted workflows
- Implement security and privacy controls for IAM AI usage including least-privilege access, secrets handling, prompt-injection resistance, and auditability
- Monitor AI-assisted automations in production, tune prompts, tools and workflows, and support audits and compliance evidence requests
Benefity
- Supportive, agile, startup-like culture with a team of top tech minds in AI, cloud, and digital platform modernization
- Hybrid mode and opportunity to work remotely within Poland
- Chance to work abroad up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including certifications (Anthropic, Gemini, GCP, Azure, AWS)
- Thought leadership, mentoring, soft skills, well-being programs
- English classes
- Stable pay with participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, and shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee
- Corporate, social, and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
869 aktywnych ofert