AI-Augmented IAM Security Engineer

EPAM Systems

Polska

Hybrid

PLN 180,000 - 260,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Multisport
Shopping vouchers

Job summary

EPAM Systems, Inc. is hiring an AI-Augmented IAM Security Engineer to handle hands-on IAM implementation, configuration, automation and day-to-day operations.

The role operates within defined architectures and policies, focusing on provisioning, SSO, MFA, RBAC/ABAC and SoD rules while integrating AI agents and LLM-powered automations. You will monitor IAM health, run backups, and ensure secure AI usage, with collaboration across security, engineering and compliance teams.

Qualifications

  • Experience implementing or operating IAM solutions in enterprise settings.
  • Knowledge of identity lifecycle, authentication, authorization and least privilege.
  • Familiarity with SAML, OAuth2.0, OpenID Connect, LDAP, Kerberos is expected.

Responsibilities

  • Implement, configure and operate IAM controls and integrations.
  • Automate provisioning and deprovisioning across target systems.
  • Develop AI-assisted automations and maintain runbooks and documentation.

Skills

IAM concepts
SSO
MFA
RBAC/ABAC
SCIM
REST APIs
Terraform
PowerShell
Python
Cloud IAM

Education

Bachelor's degree in Computer Science or related field

Tools

Azure
AWS
GCP
Microsoft Entra ID
Okta
SailPoint
CyberArk

Job description

We are seeking an AI-Augmented IAM Security Engineer to handle the hands-on implementation, configuration, automation and day-to-day operation of enterprise Identity and Access Management. This is a delivery-and-operations role that works within the designs, standards, role models and policies set by IAM architects and security leadership. The focus is building, configuring, scripting, running and troubleshooting IAM, not defining target-state architecture, role models or governance policy.ResponsibilitiesImplement, configure and operate IAM solutions and controls based on architecture, standards and designs defined by IAM architects and security leadershipMaintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning across target systemsConfigure core IAM capabilities, including SSO, federation, MFA and passwordless authentication, conditional access, RBAC/ABAC role models and least-privilege accessDevelop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases and APIsExecute access certification and review campaigns, perform entitlement clean-up and configure segregation-of-duties (SoD) rules according to access policies defined by architects and the businessOperate Privileged Access Management controls, including credential vaulting, secrets rotation, session management and just-in-time and just-enough accessDevelop automation scripts, workflows and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologiesMonitor IAM platform health, troubleshoot and resolve incidents and access issues, and perform patching, upgrades and configuration hardeningMaintain IAM logging, alerting and monitoring, and run backup and recovery procedures according to defined runbooks and resilience requirementsDeploy AI-assisted automations and agentic workflows that reduce manual effort across daily IAM operations, such as access request triage, entitlement analysis, anomaly detection, root-cause analysis, privileged access review support, compliance evidence collection and documentation generationIntegrate AI agents and LLM-backed automations into IAM systems and operational pipelines, connecting models to internal tools, APIs, directories, ticketing and IAM platforms via function calling, SCIM, REST and webhooksDevelop and maintain reusable prompts, structured-prompting patterns and prompt templates, and implement retrieval over IAM policies, role catalogs, runbooks and documentation (for example RAG) so AI assistants answer from current authoritative internal sourcesImplement output verification, human-in-the-loop approval gates and rollback paths in AI-assisted IAM workflows, so no AI-driven change reaches production access without reviewImplement security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data and full auditability of AI-driven actionsMonitor AI-assisted IAM automations in production, measure their accuracy and impact, continuously tune prompts, tools and workflows, and produce operational documentation, runbooks and standard operating procedures while supporting audits and compliance evidence requestsRequirementsBachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience2+ years of hands-on experience implementing or operating Identity and Access Management solutionsExperience with at least one enterprise IAM, IGA, PAM or federation platformUnderstanding of IAM concepts, including identity lifecycle, authentication and authorization, SSO, federation, MFA, RBAC/ABAC, least privilege and privileged accessKnowledge of common IAM protocols and standards such as SAML, OAuth 2.0 and OpenID Connect, alongside SCIM, LDAP and KerberosExperience configuring IAM controls, policies, connectors and access governance workflowsWorking knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS or GCPScripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM or TerraformCapability to work closely with developers, architects, infrastructure engineers, security operations, compliance teams and business stakeholdersCompetency to follow, maintain and improve defined IAM and security processes, executing changes from tickets, runbooks and designs while escalating design-level questionsPractical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including building AI agents, automating repetitive IAM tasks, integrating LLMs with tools and documents, prompt engineering and using AI tools securely with awareness of sensitive identity dataGood communication skills and the ability to explain IAM issues, technical decisions and remediation steps to both technical and non-technical stakeholdersNice to haveFamiliarity with IAM platforms such as Microsoft Entra ID, Active Directory and Okta, alongside Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt or CyberArkExperience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios, plus SIEM/SOAR integrations for IAM monitoring, alerting and automated responseExperience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changesFamiliarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock and Microsoft Copilot Studio, alongside LangChain, AutoGen or Power AutomateUnderstanding of AI security risks, including data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposureSC-300, Okta Certified Professional / Administrator / Consultant, SailPoint, Saviynt, CyberArk or Ping Identity certifications, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900 or AWS Certified AI PractitionerWe offerWe gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and an agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:We will reach out to selected candidates exclusivelyEPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM Systems • Poznań

On-site
PLN 180,000 - 240,000
Hybrid by design
Remote within Poland
Health insurance
+4
Lead AI Security Engineer
Lead AI Security Engineer

EPAM Systems • Polska

Hybrid
PLN 300,000 - 420,000
Health insurance
Employee stock plan
Relocation opportunities
+1
Lead AI Security Engineer at EPAM Systems
Lead AI Security Engineer at EPAM Systems

EPAM Systems Inc • Polska

Hybrid
PLN 180,000 - 260,000
Senior IAM Engineer (SailPoint)
Senior IAM Engineer (SailPoint)

EPAM Systems • Polska

Hybrid
PLN 180,000 - 260,000
Health insurance
Employee Stock Purchase Plan (ESPP)
Hybrid by design; remote within Poland
+1
Senior AI Security Engineer - Data & AI Platform
Senior AI Security Engineer - Data & AI Platform

EPAM Systems • Polska

Hybrid
PLN 180,000 - 240,000
Health insurance
Multisport
Shopping vouchers
+2
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Łódź

On-site
PLN 250,000 - 400,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Senior Cybersecurity Delivery Manager
Senior Cybersecurity Delivery Manager

EPAM Systems • Polska

Hybrid
PLN 260,000 - 360,000
Health insurance
English classes
Employee stock purchase plan
+1
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Poland

On-site
PLN 240,000 - 320,000
Hybrid by design remote within Poland
Relocation opportunities
Health insurance
Senior AI-Native Engineer
Senior AI-Native Engineer

EPAM Systems • Wrocław

On-site
PLN 180,000 - 260,000
Health insurance
Multisport
Employee Stock Purchase Plan
Senior AI-Native Engineer
Senior AI-Native Engineer

EPAM Systems • Kraków

On-site
PLN 240,000 - 360,000
Hybrid work model
Career development programs
Relocation opportunities
+2