AI-Augmented IAM Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Wymagania
- Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
- 2+ years hands-on experience implementing or operating Identity and Access Management solutions
- Experience with at least one enterprise IAM, IGA, PAM or federation platform
- Understanding of IAM concepts including identity lifecycle, authentication and authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access
- Knowledge of IAM protocols and standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
- Experience configuring IAM controls, policies, connectors, and access governance workflows
- Working knowledge of cloud IAM concepts on at least one major cloud platform (Azure, AWS or GCP)
- Scripting and automation experience using PowerShell, Python, Bash, REST APIs, SCIM or Terraform
- Capability to collaborate with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders
- Competency in following, maintaining, and improving defined IAM and security processes executing changes from tickets, runbooks and designs while escalating design-level questions
- Practical understanding of AI-assisted productivity and automation including building AI agents, integrating LLMs with tools/documents, prompt engineering, and secure AI tool usage
- Good communication skills to explain IAM issues, technical decisions, and remediation steps to technical and non-technical stakeholders
Nice to have:
- Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt or CyberArk
- Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios; SIEM/SOAR integrations for IAM monitoring and automated response
- Experience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changes
- Familiarity with AI/LLM platforms such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen or Power Automate
- Understanding of AI security risks: data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposure
- Industry certifications including SC-300, Okta Certified Professional/Administrator/Consultant, SailPoint, Saviynt, CyberArk, Ping Identity, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, or AWS Certified AI Practitioner
Obowiązki
- Implement, configure and operate IAM solutions based on architecture, standards, and designs defined by IAM architects and security leadership
- Maintain identity lifecycle processes including automated provisioning and deprovisioning across target systems
- Configure core IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC, and least-privilege access
- Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, source systems, databases, and APIs
- Execute access certification and review campaigns, implement entitlement clean-up and configure segregation-of-duties rules
- Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, just-in-time and just-enough access
- Develop automation scripts, workflows, and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
- Monitor IAM platform health, troubleshoot incidents and access issues, perform patching, upgrades, and configuration hardening
- Maintain IAM logging, alerting, monitoring, backup and recovery procedures according to runbooks and resilience requirements
- Deploy AI-assisted automations and agentic workflows reducing manual effort across daily IAM operations such as access request triage, entitlement analysis, anomaly detection, root-cause analysis, privileged access review, compliance evidence collection, and documentation generation
- Integrate AI agents and LLM-backed automations into IAM systems and operational pipelines via function calling, SCIM, REST, and webhooks
- Develop and maintain reusable prompts, structured-prompting patterns and prompt templates, implementing retrieval over IAM policies, role catalogs, runbooks, and documentation
- Implement output verification, human-in-the-loop approval gates and rollback paths in AI-assisted IAM workflows
- Implement security and privacy controls for IAM AI usage including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data, and full auditability of AI-driven actions
- Monitor AI-assisted IAM automations in production, measure accuracy and impact, continuously tune prompts, tools and workflows
- Produce operational documentation, runbooks, and standard operating procedures; support audits and compliance evidence requests
Benefity
- Access to top tech minds driving innovation in AI, cloud and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid work mode and opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including certification opportunities (Anthropic, Gemini, GCP, Azure, AWS)
- Thought leadership, mentoring, soft skills and well-being programs
- English classes
- Stable pay
- Participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee
- Corporate, social and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
1220 aktywnych ofert