Lead Security / Policy Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#453717·Dodano 2 dni temu·0
Źródło: EPAM Systems
Aplikuj teraz

Tech Stack / Keywords

OAuth2JWTOIDCRBACABACCedarOPAAWS AgentCore PolicyAmazon Web Services

Wymagania

  • 5+ years of experience in cloud security or identity engineering
  • Hands-on experience with authorization or policy-as-code for AI agents in production agentic AI projects, such as Cedar/OPA policy engines enforcing agent-to-agent boundaries, capability/agent-card discovery, or default-deny agent authorization models
  • Expertise in identity-aware authorization, including OAuth 2.0, JWT token inspection and claims mapping, and OIDC
  • Skills in RBAC and ABAC design patterns
  • Background in either direct policy-as-code experience (Cedar, OPA) or demonstrable A2A protocol depth, including agent identity, capability/agent-card discovery, and trust boundaries
  • Experience leading enterprise security review processes including InfoSec and ARB workflows
  • Knowledge of AWS AgentCore Policy and Cedar policy language (principals, actions, resources, conditions)
  • Proficiency in English at a B2+ level

Nice to have:

  • Familiarity with Cedar specifically, or AWS Cedar (open source)
  • Practical familiarity with a policy-decision-point pattern, including evaluation of requests against declarative rules, default-deny models, staged rollout from LOG_ONLY to ENFORCE
  • Early experience with AWS Verified Permissions or AgentCore Policy
  • Cloud-native AWS exposure
  • Skills in zero-trust architecture design

Obowiązki

  • Lead the architecture of the policy engine and Cedar policy schema design across the platform
  • Define authorization models that govern agent-to-agent capability advertisement and invocation
  • Drive enterprise InfoSec review processes and ensure alignment with ARB requirements
  • Establish default-deny authorization patterns for agent interactions
  • Integrate identity-aware authorization using OAuth 2.0, JWT, and MS Entra
  • Build and maintain policy-as-code patterns to standardize governance across agent development teams
  • Oversee audit logging mechanisms for policy decisions and enforcement outcomes
  • Guide staged rollout strategies for policy enforcement, from monitoring to full enforcement
  • Collaborate with engineering teams to reason about trust boundaries between interacting agents

Benefity

  • Hybrid by design mode and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs
  • Thought leadership, mentoring, soft skills and well-being programs
  • Certification (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
  • Corporate, social and well-being events
Elastyczne godziny
Płatny urlop
Opieka zdrowotna
Karta sportowa
Ubezpieczenie
Spotkania integracyjne
Kursy językowe
Budżet konferencyjny
Dofinansowanie szkoleń
Premie
Udziały pracownicze
Napoje w biurze
Darmowe przekąski

Inne informacje

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

EPAM Systems

EPAM Systems

1356 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz