AI-Augmented IAM Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM Systems is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups with over thirty years of expertise in custom software, product, and platform engineering. The company empowers clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Wymagania
- Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
- 2+ years hands-on experience implementing or operating Identity and Access Management solutions
- Experience with at least one enterprise IAM, IGA, PAM or federation platform
- Understanding of IAM concepts including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access
- Knowledge of IAM protocols and standards such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
- Experience configuring IAM controls, policies, connectors, and access governance workflows
- Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS or GCP
- Scripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM or Terraform
- Ability to work closely with developers, architects, infrastructure engineers, security operations, compliance teams and business stakeholders
- Competency to follow, maintain and improve defined IAM and security processes and escalate design-level questions
- Practical understanding of AI-assisted productivity and automation including AI agents, LLM tool integration, prompt engineering, and secure AI tool usage
- Good communication skills to explain IAM issues and technical decisions to technical and non-technical stakeholders
Nice to have:
- Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk
- Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios, and SIEM/SOAR integrations for IAM monitoring
- Experience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changes
- Familiarity with AI/LLM platforms such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, Power Automate
- Understanding of AI security risks including data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposure
- Certifications such as SC-300, Okta Certified Professional, SailPoint, Saviynt, CyberArk, Ping Identity, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900, or AWS Certified AI Practitioner
Obowiązki
- Implement, configure, and operate IAM solutions and controls based on architecture and standards defined by IAM architects and security leadership
- Maintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning
- Configure core IAM capabilities including SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access
- Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, databases, and APIs
- Execute access certification and review campaigns, perform entitlement cleanup, and configure segregation-of-duties (SoD) rules
- Operate Privileged Access Management controls including credential vaulting, secrets rotation, session management, just-in-time and just-enough access
- Develop automation scripts, workflows, and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
- Monitor IAM platform health, troubleshoot and resolve incidents, and perform patching, upgrades, and configuration hardening
- Maintain IAM logging, alerting, monitoring, and run backup and recovery procedures
- Deploy AI-assisted automations and agentic workflows to reduce manual effort in IAM operations such as access request triage and entitlement analysis
- Integrate AI agents and LLM-backed automations into IAM systems and pipelines using function calling, SCIM, REST, and webhooks
- Develop and maintain reusable prompts, prompt patterns, and implement retrieval over IAM policies and documentation
- Implement output verification, human-in-the-loop approval, and rollback paths in AI-assisted IAM workflows
- Implement security and privacy controls for IAM AI usage including least-privilege access for agents, secrets handling, prompt-injection resistance, and auditability
- Monitor AI-assisted IAM automations, measure accuracy and impact, tune workflows, and produce documentation to support audits and compliance
Benefity
- Opportunity to work with top tech minds in AI, cloud and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid by design work mode with remote work opportunity within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including mentoring, soft skills and well-being
- Certification support (Anthropic, Gemini, GCP, Azure, AWS)
- English language classes
- Stable pay
- Participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment zones, table tennis, football, free snacks, and coffee
- Corporate, social and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
1197 aktywnych ofert