AI-Augmented IAM Security Engineer

EPAM Systems

Montenegro

Híbrido

BRL 353 000 - 529 000

Tempo integral

Há 13 dias

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Learning platform access
Free English classes with certified老師
Employee Stock Purchase Plan
Comprehensive medical package
Trust days

Resumo da oferta

EPAM Systems is hiring an AI-Augmented IAM Security Engineer to implement and operate enterprise IAM, focusing on automation, scripting, and AI-assisted workflows. You will build provisioning, SSO/MFA, and RBAC/ABAC controls, and integrate IAM with cloud, SaaS, and internal systems.

You will collaborate with security leadership to follow designs and runbooks, while deploying AI-enabled runbooks and ensuring auditability and secure AI usage. Hybrid work in Montenegro is offered.

Qualificações

  • Bachelor's degree in CS, cybersecurity or engineering or equivalent experience.
  • 2+ years hands-on IAM implementation or operation experience.
  • Experience with at least one IAM platform (IAM/IGA/PAM or federation).
  • Fundamental IAM concepts: lifecycle, SSO, MFA, RBAC/ABAC, least privilege.
  • Knowledge of SAML, OAuth2, OpenID Connect, SCIM, LDAP, Kerberos.
  • Cloud IAM knowledge across Azure, AWS or GCP.
  • Scripting/automation with PowerShell, Python, Bash, REST, SCIM, or Terraform.
  • Ability to collaborate with developers, architects, security and business teams.
  • English proficiency at least B2.

Responsabilidades

  • Implement, configure, and operate IAM solutions per architecture and standards.
  • Build and maintain identity lifecycle with automated provisioning/deprovisioning.
  • Configure core IAM capabilities: SSO, federation, MFA, passwordless, RBAC/ABAC.
  • Develop IAM integrations with cloud platforms, SaaS and enterprise systems.
  • Execute access reviews, entitlement cleanup, and SoD rules.
  • Operate Privileged Access Management controls and vaulting.
  • Develop automation scripts and IAM tooling (PowerShell, Python, REST, SCIM, Terraform).
  • Monitor IAM health, troubleshoot incidents, and perform hardening.
  • Maintain IAM logging, monitoring, runbooks, and recovery procedures.
  • Build AI-assisted automations and agentic IAM workflows.
  • Integrate AI agents with internal tools via APIs and SCIM/rest/webhooks.
  • Create and refine prompts for recurring IAM tasks.
  • Enable AI governance with current authoritative sources.
  • Ensure human-in-the-loop gates and rollback paths for AI-driven changes.
  • Maintain security/privacy controls for AI usage in IAM.
  • Monitor AI automations in production and tune for accuracy.

Conhecimentos

Hands-on IAM
IAM concepts
Scripting/Automation
AI-assisted productivity
English B2+
PowerShell
Python
REST APIs
SCIM
Terraform

Formação académica

Bachelor's degree

Ferramentas

PowerShell
Python
REST APIs
SCIM
Terraform

Descrição da oferta de emprego

We are seeking an AI-Augmented IAM Security Engineer to handle the hands-on implementation, configuration, automation and day-to-day operation of enterprise Identity and Access Management. This is a delivery-and-operations role that works within the designs, standards, role models and policies set by IAM architects and security leadership. The focus is building, configuring, scripting, running and troubleshooting IAM, not defining target-state architecture, role models or governance policy.

This position offers hybrid setup with the flexibility to work from any location in Montenegro, whether it's your home or our dynamic offices in Herceg-Novi and Podgorica.

Responsibilities
  • Implement, configure, and operate IAM solutions and controls based on architecture, standards, and designs defined by IAM architects and security leadership
  • Build and maintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning across target systems
  • Configure and maintain core IAM capabilities, including SSO, federation, MFA and passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access
  • Develop, deploy, and maintain IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases, and APIs
  • Execute access certification and review campaigns, perform entitlement clean-up, and configure segregation-of-duties (SoD) rules according to access policies defined by architects and the business
  • Implement and operate Privileged Access Management controls, including credential vaulting, secrets rotation, session management, and just-in-time and just-enough access
  • Develop and maintain automation scripts, workflows, and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform, or similar technologies
  • Monitor IAM platform health, troubleshoot and resolve incidents and access issues, and perform patching, upgrades, and configuration hardening
  • Implement and maintain IAM logging, alerting, and monitoring, and run backup and recovery procedures according to defined runbooks and resilience requirements
  • Build, deploy, and maintain AI-assisted automations and agentic workflows that reduce manual effort across daily IAM operations, such as access request triage, classification, and routing; entitlement analysis, access review summarization, and reviewer recommendations; role and entitlement analysis and access anomaly detection; provisioning and lifecycle workflow troubleshooting and root-cause analysis; privileged access review support; compliance evidence collection; IAM runbook, query, and documentation generation
  • Build and integrate AI agents and LLM-backed automations into IAM systems and operational pipelines, connecting models to internal tools, APIs, directories, ticketing, and IAM platforms via function calling, SCIM, REST, and webhooks
  • Develop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring IAM tasks, and tune them for accuracy, consistency, and safe behavior
  • Implement retrieval over IAM policies, role catalogs, runbooks, and documentation (for example RAG) so AI assistants answer from current, authoritative internal sources rather than guesswork
  • Implement output verification, human-in-the-loop approval gates, and rollback paths in AI-assisted IAM workflows, so no AI-driven change reaches production access without review
  • Implement security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data, and full auditability of AI-driven actions
  • Monitor AI-assisted IAM automations in production, measure their accuracy and impact, and continuously tune prompts, tools, and workflows based on results and feedback
  • Produce and maintain operational documentation, runbooks, and standard operating procedures, and support audits and compliance evidence requests
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience
  • 2+ years of hands-on experience implementing or operating Identity and Access Management solutions
  • Hands-on experience with at least one enterprise IAM, IGA, PAM, or federation platform
  • Solid understanding of IAM concepts, including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access
  • Practical knowledge of common IAM protocols and standards, such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
  • Experience configuring IAM controls, policies, connectors, and access governance workflows
  • Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS, or GCP
  • Scripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM, or Terraform
  • Ability to work closely with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders
  • Ability to follow, maintain, and improve defined IAM and security processes
  • Comfortable executing changes from tickets, runbooks, and designs provided by senior engineers and architects, and escalating design-level questions rather than owning them
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including at least some of the following: building or configuring AI agents; using AI to automate repetitive IAM or security tasks; integrating LLMs with tools, APIs, documents, or workflows; prompt engineering and structured prompting; creating AI-assisted runbooks, scripts, queries, or documentation; using AI tools securely with awareness of sensitive identity data, access control, and audit requirements
  • Good communication skills and the ability to explain IAM issues, technical decisions, and remediation steps to both technical and non-technical stakeholders
  • Hands-on proficiency is a must
  • English proficiency at B2 level or higher
Nice to have
  • Experience with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk, or similar
  • Experience with CIAM, B2B/B2C identity, customer identity, external identity, or partner access scenarios
  • Experience with SIEM/SOAR integrations for IAM monitoring, alerting, and automated response
  • Experience with CI/CD-based IAM deployment, configuration-as-code, and automated testing of IAM changes
  • Experience with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or Power Automate
  • Understanding of AI security risks, including data leakage, prompt injection, excessive agency, insecure tool use, model governance, and sensitive identity data exposure
  • Security or IAM certifications such as SC-300: Microsoft Identity and Access Administrator; Okta Certified Professional / Administrator / Consultant; SailPoint, Saviynt, CyberArk, or Ping Identity certifications; CISSP, CISM, CISA, CCSK, CCSP, SSCP, or similar
  • AI-related certifications are a plus, for example: AI-900: Microsoft Azure AI Fundamentals; AWS Certified AI Practitioner
We offer
  • We connect like-minded people
    • Experience exchange with colleagues from 55+ locations
    • Corporate and social events
    • Enjoyable working environment
    • Personal career development, soft skills and well-being programs
    • Unlimited access to Internal Learning Platform
    • Free English classes with certified teachers
    • Participation in the Employee Stock Purchase Plan
    • Comprehensive medical package (can be extended to family members)
    • Four trust days per year for personal needs
    • Benefits package (hotels, restaurants, stores and services)

EPAM is a leading global provider of digital platform engineering and development services. For over 30 years, our team has helped leading brands navigate the waves of digital transformation, building solutions that help them stay competitive through constant market disruption.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Montenegro

Híbrido
BRL 420 000 - 600 000
Corporate events
Internal Learning Platform
English classes
+2
Senior AI Engineer
Senior AI Engineer

EPAM Systems • Montenegro

Híbrido
BRL 233 000 - 409 000
Hybrid work setup
Global team collaboration
Comprehensive medical package
+2
Cloud Native .NET Engineer with AI Integration Focus
Cloud Native .NET Engineer with AI Integration Focus

EPAM Systems • Montenegro

Híbrido
BRL 300 000 - 510 000
Global team with 55+ locations
Corporate and social events
Medical package with family coverage
+3
Regional AI Run Lead
Regional AI Run Lead

EPAM Systems • Montenegro

Híbrido
BRL 870 000 - 1 178 000
Stock purchase plan
Medical package
Learning platform access
+1
Lead AI Engineer
Lead AI Engineer

EPAM Systems • Montenegro

Híbrido
BRL 527 000 - 878 000
Unlimited access to Internal Learning
Free English classes
Employee Stock Purchase Plan
+2
Senior .NET Engineer with AWS
Senior .NET Engineer with AWS

EPAM Systems • Montenegro

Híbrido
BRL 359 000 - 538 000
Corporate events
Social events
Free English classes
+5
Junior IAM Analyst
Junior IAM Analyst

Pipefy • Curitiba

Híbrido
BRL 60 000 - 90 000
Health and dental insurance
Life insurance
Flexible hours (40h/ week)
+8
Senior Java Software Engineer
Senior Java Software Engineer

EPAM Systems • Montenegro

Híbrido
BRL 360 000 - 480 000
Career development
English classes
Employee Stock Purchase Plan
+2
Senior Data Integration Engineer
Senior Data Integration Engineer

EPAM Systems • Montenegro

Híbrido
BRL 420 000 - 660 000
Medical package
Stock Purchase Plan
Learning Platform access
+2
AI Center of Excellence (COE) Engineering Manager
AI Center of Excellence (COE) Engineering Manager

EPAM Systems • Brasil

Presencial
BRL 300 000 - 550 000
International projects
Global career opportunities
LinkedIn Learning access
+5