Lead AI-Augmented IAM Security Engineer

EPAM Systems

Montenegro

Híbrido

BRL 533 000 - 770 000

Tempo integral

há 22 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Comprehensive medical package (can be 
Unlimited access to Internal Learning 
Corporate and social events

Resumo da oferta

EPAM Systems is seeking a Lead AI-Augmented IAM Security Engineer to implement and operate IAM controls, automate tasks, and maintain security posture. You will work within IAM standards and be responsible for AI-powered workflows and robust access governance.

The role emphasizes hands-on IAM delivery, scripting, and collaboration with security leadership, with a hybrid model across Montenegro offices and remote work options.

Qualificações

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
  • Hands-on experience deploying or operating Identity and Access Management solutions.
  • Strong grasp of IAM concepts such as SSO, MFA, RBAC/ABAC, least privilege.

Responsabilidades

  • Deploy, configure, and run IAM solutions and controls per architecture.
  • Manage identity lifecycle (Joiner/Mover/Leaver) across target systems.
  • Set up and maintain IAM capabilities (SSO, federation, MFA, passwordless).
  • Develop AI-assisted automations and agentic IAM workflows.
  • Maintain IAM logging, monitoring, and recovery procedures.
  • Create prompts and AI-assisted runbooks for IAM tasks.

Conhecimentos

Hands-on proficiency
Strong communication skills
English proficiency

Formação académica

Bachelor's degree

Ferramentas

PowerShell
Python
Bash
REST APIs
SCIM
Terraform

Descrição da oferta de emprego

We are looking for a Lead AI-Augmented IAM Security Engineer to manage the practical implementation, configuration, automation, and everyday operation of enterprise Identity and Access Management. This position centers on delivery and operations, functioning within the designs, standards, role models, and policies established by IAM architects and security leadership. The emphasis lies in building, configuring, scripting, running, and troubleshooting IAM rather than shaping target-state architecture, role models, or governance policy.
This position offers hybrid setup with the flexibility to work from any location in Montenegro, whether it's your home or our dynamic offices in Herceg-Novi and Podgorica.

Responsibilities
  • Deploy, configure, and run IAM solutions and controls guided by the architecture, standards, and designs set by IAM architects and security leadership
  • Establish and sustain identity lifecycle (Joiner / Mover / Leaver) processes, covering automated provisioning and deprovisioning across target systems
  • Set up and maintain core IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access
  • Create, roll out, and maintain IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases, and APIs
  • Run access certification and review campaigns, carry out entitlement clean-up, and configure segregation-of-duties (SoD) rules in line with access policies set by architects and the business
  • Deploy and operate Privileged Access Management controls, including credential vaulting, secrets rotation, session management, and just-in-time and just-enough access
  • Build and maintain automation scripts, workflows, and IAM tooling with PowerShell, Python, REST APIs, SCIM, Terraform, or comparable technologies
  • Track IAM platform health, diagnose and resolve incidents and access issues, and handle patching, upgrades, and configuration hardening
  • Set up and maintain IAM logging, alerting, and monitoring, and execute backup and recovery procedures per defined runbooks and resilience requirements
  • Create, deploy, and maintain AI-assisted automations and agentic workflows that cut manual effort across daily IAM operations, such as access request triage, classification, and routing; entitlement analysis, access review summarization, and reviewer recommendations; role and entitlement analysis and access anomaly detection; provisioning and lifecycle workflow troubleshooting and root-cause analysis; privileged access review support; compliance evidence collection; IAM runbook, query, and documentation generation
  • Develop and embed AI agents and LLM-backed automations into IAM systems and operational pipelines, linking models to internal tools, APIs, directories, ticketing, and IAM platforms through function calling, SCIM, REST, and webhooks
  • Build, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring IAM tasks, and refine them for accuracy, consistency, and safe behavior
  • Set up retrieval over IAM policies, role catalogs, runbooks, and documentation (for example RAG) so AI assistants respond from current, authoritative internal sources instead of guesswork
  • Put in place output verification, human-in-the-loop approval gates, and rollback paths within AI-assisted IAM workflows, so no AI-driven change reaches production access without review
  • Apply security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data, and complete auditability of AI-driven actions
  • Oversee AI-assisted IAM automations in production, gauge their accuracy and impact, and continually refine prompts, tools, and workflows based on results and feedback
  • Create and maintain operational documentation, runbooks, and standard operating procedures, and assist with audits and compliance evidence requests
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience
  • 2+ years of hands-on experience deploying or operating Identity and Access Management solutions
  • Hands-on experience with at least one enterprise IAM, IGA, PAM, or federation platform
  • Strong grasp of IAM concepts, including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access
  • Practical familiarity with common IAM protocols and standards, such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos
  • Experience setting up IAM controls, policies, connectors, and access governance workflows
  • Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS, or GCP
  • Scripting and automation experience with at least one of PowerShell, Python, Bash, REST APIs, SCIM, or Terraform
  • Capacity to collaborate closely with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders
  • Capacity to follow, maintain, and enhance defined IAM and security processes
  • At ease carrying out changes from tickets, runbooks, and designs supplied by senior engineers and architects, and escalating design-level questions rather than owning them
  • Practical grasp of AI-assisted productivity and automation beyond basic chatbot usage, including at least some of the following: building or configuring AI agents; using AI to automate repetitive IAM or security tasks; integrating LLMs with tools, APIs, documents, or workflows; prompt engineering and structured prompting; creating AI-assisted runbooks, scripts, queries, or documentation; using AI tools securely with awareness of sensitive identity data, access control, and audit requirements
  • Strong communication skills and the ability to explain IAM issues, technical decisions, and remediation steps to both technical and non-technical stakeholders
  • Hands-on proficiency is essential
  • English proficiency at B2 level or higher
Nice to have
  • Experience with IAM platforms such as Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk, or similar
  • Experience with CIAM, B2B/B2C identity, customer identity, external identity, or partner access scenarios
  • Experience with SIEM/SOAR integrations for IAM monitoring, alerting, and automated response
  • Experience with CI/CD-based IAM deployment, configuration-as-code, and automated testing of IAM changes
  • Experience with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or Power Automate
  • Awareness of AI security risks, including data leakage, prompt injection, excessive agency, insecure tool use, model governance, and sensitive identity data exposure
  • Security or IAM certifications such as SC-300: Microsoft Identity and Access Administrator; Okta Certified Professional / Administrator / Consultant; SailPoint, Saviynt, CyberArk, or Ping Identity certifications; CISSP, CISM, CISA, CCSK, CCSP, SSCP, or similar
  • AI-related certifications are a plus, for example: AI-900: Microsoft Azure AI Fundamentals; AWS Certified AI Practitioner
We offer
  • We connect like-minded people
    • Experience exchange with colleagues from 55+ locations
    • Corporate and social events
    • Enjoyable working environment
    • Personal career development, soft skills and well-being programs
    • Unlimited access to Internal Learning Platform
    • Free English classes with certified teachers
    • Participation in the Employee Stock Purchase Plan
    • Comprehensive medical package (can be extended to family members)
    • Four trust days per year for personal needs
    • Benefits package (hotels, restaurants, stores and services)

EPAM is a leading global provider of digital platform engineering and development services. For over 30 years, our team has helped leading brands navigate the waves of digital transformation, building solutions that help them stay competitive through constant market disruption.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM Systems • Montenegro

Híbrido
BRL 355 000 - 533 000
Corporate learning & development
Flexible hybrid work model
Medical package
+1
Azure Systems Architect
Azure Systems Architect

EPAM Systems • Montenegro

Híbrido
BRL 533 000 - 829 000
Comprehensive medical package
Free English classes with certifiedte
Stock Purchase Plan
+2
Lead AI Engineer
Lead AI Engineer

EPAM Systems • Montenegro

Híbrido
BRL 474 000 - 710 000
Hybrid work
Global team
Career development
+4
AI Center of Excellence (COE) Engineering Manager
AI Center of Excellence (COE) Engineering Manager

EPAM Systems • Brasil

Teletrabalho
BRL 350 000 - 520 000
Healthcare benefits
Paid time off
Regional AI Run Lead
Regional AI Run Lead

EPAM Systems • Montenegro

Híbrido
BRL 355 000 - 533 000
Unlimited access to Internal Learning 
Free English classes with certified te
Employee Stock Purchase Plan
+3
Chief Forward Deployed Engineer
Chief Forward Deployed Engineer

EPAM Systems • Brasil

Presencial
BRL 300 000 - 420 000
Healthcare benefits
Paid time off
Learning & certification
+1
Senior AI Engineer
Senior AI Engineer

EPAM Systems • Brasil

Presencial
BRL 180 000 - 280 000
Healthcare benefits
Upskilling courses
Paid time off
Senior Java Software Engineer
Senior Java Software Engineer

EPAM Systems • Montenegro

Híbrido
BRL 385 000 - 533 000
Global team exposure
Learning platform access
Medical package
Lead Forward Deployed Engineer
Lead Forward Deployed Engineer

EPAM Systems • Brasil

Presencial
BRL 240 000 - 360 000
Healthcare benefits
Global career opportunities
LinkedIn Learning access
+1
Senior Data Software Engineer
Senior Data Software Engineer

EPAM Systems • Montenegro

Híbrido
BRL 414 000 - 710 000
Medical package
Free English classes
Employee Stock Purchase Plan
+1