368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$36k – $107k per year (Estimated)
Location
Remote (Poland)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
EPAM is a global digital transformation and software engineering company founded in 1993. It helps enterprises and startups build software products, cloud solutions, and AI-enabled services. The company is known for combining strong engineering expertise with consulting, design, and product development capabilities.

We are seeking an AI-Augmented IAM Security Engineer to handle the hands-on implementation, configuration, automation and day-to-day operation of enterprise Identity and Access Management. This is a delivery-and-operations role that works within the designs, standards, role models and policies set by IAM architects and security leadership. The focus is building, configuring, scripting, running and troubleshooting IAM, not defining target-state architecture, role models or governance policy.

Responsibilities

  • Implement, configure and operate IAM solutions and controls based on architecture, standards and designs defined by IAM architects and security leadership
  • Maintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning across target systems
  • Configure core IAM capabilities, including SSO, federation, MFA and passwordless authentication, conditional access, RBAC/ABAC role models and least-privilege access
  • Develop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases and APIs
  • Execute access certification and review campaigns, perform entitlement clean-up and configure segregation-of-duties (SoD) rules according to access policies defined by architects and the business
  • Operate Privileged Access Management controls, including credential vaulting, secrets rotation, session management and just-in-time and just-enough access
  • Develop automation scripts, workflows and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologies
  • Monitor IAM platform health, troubleshoot and resolve incidents and access issues, and perform patching, upgrades and configuration hardening
  • Maintain IAM logging, alerting and monitoring, and run backup and recovery procedures according to defined runbooks and resilience requirements
  • Deploy AI-assisted automations and agentic workflows that reduce manual effort across daily IAM operations, such as access request triage, entitlement analysis, anomaly detection, root-cause analysis, privileged access review support, compliance evidence collection and documentation generation
  • Integrate AI agents and LLM-backed automations into IAM systems and operational pipelines, connecting models to internal tools, APIs, directories, ticketing and IAM platforms via function calling, SCIM, REST and webhooks
  • Develop and maintain reusable prompts, structured-prompting patterns and prompt templates, and implement retrieval over IAM policies, role catalogs, runbooks and documentation (for example RAG) so AI assistants answer from current authoritative internal sources
  • Implement output verification, human-in-the-loop approval gates and rollback paths in AI-assisted IAM workflows, so no AI-driven change reaches production access without review
  • Implement security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data and full auditability of AI-driven actions
  • Monitor AI-assisted IAM automations in production, measure their accuracy and impact, continuously tune prompts, tools and workflows, and produce operational documentation, runbooks and standard operating procedures while supporting audits and compliance evidence requests

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience
  • 2+ years of hands-on experience implementing or operating Identity and Access Management solutions
  • Experience with at least one enterprise IAM, IGA, PAM or federation platform
  • Understanding of IAM concepts, including identity lifecycle, authentication and authorization, SSO, federation, MFA, RBAC/ABAC, least privilege and privileged access
  • Knowledge of common IAM protocols and standards such as SAML, OAuth 2.0 and OpenID Connect, alongside SCIM, LDAP and Kerberos
  • Experience configuring IAM controls, policies, connectors and access governance workflows
  • Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS or GCP
  • Scripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM or Terraform
  • Capability to work closely with developers, architects, infrastructure engineers, security operations, compliance teams and business stakeholders
  • Competency to follow, maintain and improve defined IAM and security processes, executing changes from tickets, runbooks and designs while escalating design-level questions
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including building AI agents, automating repetitive IAM tasks, integrating LLMs with tools and documents, prompt engineering and using AI tools securely with awareness of sensitive identity data
  • Good communication skills and the ability to explain IAM issues, technical decisions and remediation steps to both technical and non-technical stakeholders

Nice to have

  • Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory and Okta, alongside Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt or CyberArk
  • Experience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios, plus SIEM/SOAR integrations for IAM monitoring, alerting and automated response
  • Experience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changes
  • Familiarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock and Microsoft Copilot Studio, alongside LangChain, AutoGen or Power Automate
  • Understanding of AI security risks, including data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposure
  • SC-300, Okta Certified Professional / Administrator / Consultant, SailPoint, Saviynt, CyberArk or Ping Identity certifications, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900 or AWS Certified AI Practitioner

We offer

  • We gather like-minded people:
    • Top tech minds driving innovation in AI, cloud and digital platform modernization
    • Supportive team and agile, startup-like culture
    • Hybrid by design mode and opportunity to work remotely within Poland
    • Chance to work abroad for up to 60 days annually
    • Business-driven relocation opportunities
  • We provide growth opportunities:
    • Career development programs
    • Thought leadership, mentoring, soft skills and well-being programs
    • Certification (Anthropic, Gemini, GCP, Azure, AWS)
    • English classes
  • We cover it all:
    • Stable pay
    • Participation in the Employee Stock Purchase Plan with a 15% discount
    • Benefits package (health insurance, multisport, shopping vouchers)
    • Referral bonuses up to $2,000
    • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
    • Corporate, social and well-being events
  • Please, note:
    • Benefits listed above are available to employees only
    • We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
    • We will reach out to selected candidates exclusively

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$131k – $256k per year (Estimated) • Equity • Remote • Full-Time • 8+ years exp
AI/ML
Anthropic
DevOps
AWS
Azure
CI/CD
GCP
Platform Engineering
Apply
$150k – $200k per year • In office • Full-Time • 3+ years exp • San Francisco
TypeScript
AI/ML
AI Agents
Management
Slack
Apply
Founding Engineer 5 days ago
$150k – $200k per year • In office • Full-Time • 3+ years exp • San Francisco
TypeScript
AI/ML
AI Agents
Apply
Data Engineer II 5 days ago
$225k per year • Remote/Hybrid • 3+ years exp • Bachelor's Degree • Aliso Viejo
Java
Kotlin
Python
Scala
SQL
Databases
Apache Kafka
OpenSearch
AI/ML
Flink
Spark
DevOps
Amazon EKS
CI/CD
Docker
Git
gRPC
Kubernetes
WebSockets
AWS
Analytics
ETL/ELT
Apply
$123k – $272k per year (Estimated) • In office • Full-Time • 7+ years exp • Chicago
DevOps
AWS
CI/CD
Terraform
Apply
$131k – $256k per year (Estimated) • Equity • Remote • Full-Time • 8+ years exp
AI/ML
Anthropic
DevOps
AWS
Azure
CI/CD
GCP
Platform Engineering
Apply
$91k – $223k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Python
SQL
TypeScript
JavaScript
Python
FastAPI
pySpark
Databases
Databricks
OpenSearch
PostgreSQL
AI/ML
Claude
Claude Code
Spark
Anthropic
Frontend
Next.js
Radix UI
React.js
Storybook
Zustand
DevOps
AWS
Azure
GCP
Platform Engineering
QA
Playwright
Apply
$65k – $109k per year (Estimated) • Equity • Remote • Full-Time • 7+ years exp • Bachelor's Degree • Katowice
C#
SQL
TypeScript
JavaScript
C#
ASP.NET Core
Databases
DynamoDB
PostgreSQL
AI/ML
Gemini
Prompt Engineering
Anthropic
Frontend
Angular
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
Git
GitHub Actions
Jenkins
Kubernetes
Platform Engineering
GitHub
Apply
$102k – $221k per year (Estimated) • Equity • Remote • Full-Time • PhD
PowerShell
Python
SQL
Databases
Azure Cosmos DB
Azure SQL Database
AI/ML
AI Agents
AutoGen
Copilot
Function Calling
LangChain
LangGraph
RAG
Semantic Kernel
OpenAI
DevOps
ArgoCD
AWS
Azure
Azure AKS
Azure DevOps
CI/CD
GCP
GitHub Actions
GitLab CI
GitOps
Helm
Kubernetes
Kustomize
Platform Engineering
Service Mesh
Terraform
GitHub
GitLab
Apply
$89k – $203k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp
AI/ML
Anthropic
DevOps
AWS
Azure
CI/CD
GCP
Helm
Kubernetes
Platform Engineering
Terraform
Cybersecurity
SonarQube
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.