{"id":1509188,"url":"https://alion.io/job/dataart-security-engineer-with-cedar-policy","title":"Security Engineer with Cedar Policy","company":{"id":46984,"name":"DataArt","domain":"dataart.com","url":"https://alion.io/company/dataart-com","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"inferred_payroll_markers","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Wrocław, Poland"],"countries":["PL"],"hiring_countries":["PL"],"hiring_countries_total":1,"salary":{"min":18000,"max":20000,"currency":"PLN","period":"month","gross":null,"usd_annual":62340},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"AWS Bedrock AgentCore","optional":false},{"name":"LangGraph","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Okta","optional":false},{"name":"Open Policy Agent","optional":false},{"name":"Python","optional":false},{"name":"GCP","optional":true},{"name":"LangChain","optional":true}],"status":"live","first_seen_at":"2026-09-30T07:00:16Z","employer_posted_date":null,"last_verified_at":"2026-09-30T07:00:16Z","board_verified":false,"closed_at":null,"days_open":5,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":5},"description":"Technology stack\nAWS AgentCore Policy, Cedar, Python, Microsoft Entra ID, OAuth 2.0, JWT, OpenID Connect, Open Policy Agent, AWS AgentCore Gateway, LangGraph, Identity Providers, Audit Logging Frameworks\nProject overview\nThe project focuses on delivering a centralized authorization framework for enterprise AI services and cloud applications. The platform provides secure policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.\nTeam\nMedium team (10-20 people)\nYou will work with security engineers, backend developers, platform engineers, architects, and governance specialists. The team follows a collaborative development approach, emphasizing policy as code, automation, secure design practices, and continuous improvement.\nPosition overview\nWe are looking for a Security Engineer to support the implementation and governance of policy based authorization solutions for enterprise AI and cloud platforms. In this role, you will work with identity, security, and platform teams to develop authorization policies, integrate identity providers, and help build secure access control mechanisms using modern policy frameworks.\nResponsibilities\nDevelop and maintain authorization policies using the Cedar policy language\n\nAuthor, test, and validate policy definitions for enterprise applications and AI services\n\nImplement and support access control models using attribute based and role based authorization approaches\n\nConfigure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito\n\nMap identity claims and token attributes to authorization decisions and policy rules\n\nSupport the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes\n\nDevelop Python based tooling for policy validation, testing, and automation\n\nDesign and implement parameter level access control patterns for secure tool and service interactions\n\nCollaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls\n\nContribute to audit logging and authorization decision traceability practices\n\nSupport security reviews and help maintain authorization governance standards\n\nRequirements\n3+ years of experience in security engineering, backend engineering, or a related field\n\nHands on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito\n\nExperience defining and managing policies within an ABAC or RBAC authorization framework\n\nHands on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies\n\nKnowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures\n\nExperience working with claims mapping and token based authorization models\n\nUnderstanding of secure authorization design principles and policy lifecycle management\n\nExperience with Python development for automation, validation, or backend services\n\nStrong analytical and problem solving skills\n\nGood written and verbal communication skills\n\nNice to have\nExperience with LangGraph tool invocation patterns\n\nExperience integrating with AWS AgentCore Gateway\n\nKnowledge of enterprise AI platform architecture and governance principles\n\nExperience implementing policy as code methodologies\n\nFamiliarity with cloud native security services and authorization platforms\n\nExposure to audit logging and compliance reporting requirements\n\nWhat We Offer:\nVacation days: Up to 26 business days per year.\n\n10 illness/special days\noff per year (fully paid, no medical papers needed) for all contract types\n\nHealth and life insurance (Luxmed)\n\nMyBenefit platform with Multisport option\n\nInternal psychological support service\n\nEnglish language classes from the first working day\n\nAccess to external learning platforms: O'Reilly, LinkedIn Learning, Udemy, and a wide catalog of diverse internal training\n\nFlexible workplace: work from the office, from home, or choose a hybrid option\n\nTech Skills Mentoring Program\n\nOpportunities to develop as a public speaker, mentor, or technical interviewer\n\nFully paid idle (bench) when not involved in a project\n\nCertification reimbursement (AWS, GCP, Microsoft, etc.)","description_format":"text","description_chars":4258,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":true}]},"benefits":["Certification reimbursement","Flexible schedule","Life insurance"],"hiring_locations":[{"name":"Poland","iso":"PL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["IT Outsourcing & Dedicated Teams","Custom Software Development"],"lifecycle":[{"event":"open","at":"2026-09-30T07:12:24Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":4,"expected_fill_days":37,"reasons":["seen:4","velocity","win:early"],"computed_at":"2026-10-05T05:45:15Z"},"pay":{"stated_usd_annual":62340,"is_top_pay":false},"html_url":"https://alion.io/job/dataart-security-engineer-with-cedar-policy","json_url":"https://alion.io/job/dataart-security-engineer-with-cedar-policy.json","meta":{"generated_at":"2026-10-06T00:41:01Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":825,"day_limit":5000,"remaining_today":4175,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":46984},"rest":"https://alion.io/mcp/rest/get_company?id=46984"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fdataart-security-engineer-with-cedar-policy"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fdataart-security-engineer-with-cedar-policy"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fdataart-security-engineer-with-cedar-policy"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/dataart-security-engineer-with-cedar-policy\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fdataart-security-engineer-with-cedar-policy"}]}