Cloud security engineer - IAM (Azure & AWS)

BEC Financial Technologies

Warszawa

On-site

PLN 240,000 - 360,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Mental health support
Free lunch at the office
Professional development budget
Referral bonus up to PLN 10,000
PLN 600 on a benefit platform a month

Job summary

BEC Financial Technologies in Warszawa is seeking a Cloud Security Engineer to join our Cloud Center of Excellence. You will shape and secure a modern multi-cloud platform used across critical financial services workloads.

The role focuses on Identity and Access Management, Zero Trust, and cloud governance across Azure, AWS, and beyond, collaborating with cross-functional teams. Occasional travel to Denmark is expected.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field, or equivalent practical experience.
  • Hands-on experience with Microsoft Entra ID (Azure AD), Conditional Access, MFA, RBAC, Privileged Identity Management (PIM), and Identity Governance.
  • Experience with AWS IAM, IAM Identity Center, cross-account access, role-based access control, and cloud security best practices.
  • Strong understanding of Zero Trust principles, authentication, authorisation, federation, identity lifecycle management, and cloud platform operations in Azure and AWS in regulated environments.
  • Knowledge of Infrastructure as Code and automation technologies such as Terraform, Bicep, PowerShell, Python, or GitHub Actions, together with productivity tools like GitHub Copilot and M365 Copilot.

Responsibilities

  • Design, implement, and operate Identity and Access Management solutions across Azure and AWS environments.
  • Manage Microsoft Entra ID, Conditional Access, MFA, Privileged Identity Management (PIM), and Identity Governance capabilities.
  • Design and maintain AWS IAM, IAM Identity Center, permission models, federated access, and least-privilege controls.
  • Collaborate with Cloud Architects, Security Engineers, Platform Engineers, Compliance Specialists, and application teams to implement secure cloud onboarding and access models.
  • Automate identity lifecycle management, access provisioning, and governance processes using Infrastructure as Code and scripting.
  • Support audits, compliance reviews, security assessments, and operational risk initiatives related to cloud platforms.
  • Travel occasionally to Denmark (typically 2-4 times per year) and participate in workshops, PI Planning events, and stakeholder meetings.

Skills

Fluent English
Bachelor's degree in Computer Science,
Hands-on IAM security
Zero Trust

Education

Bachelor's degree in Computer Science, Information Security, Engineering, or related field

Tools

Microsoft Entra ID (Azure AD)
Azure
AWS IAM
IAM Identity Center
RBAC
PIM
Identity Governance
Terraform
Bicep
PowerShell
Python
GitHub Actions
GitHub Copilot
M365 Copilot

Job description

You will join our Cloud Center of Excellence. The team is responsible for shaping and securing a modern multi-cloud platform used across critical financial services workloads.

The Cloud Security Engineer role offers an opportunity to work with Microsoft Entra ID, Azure, AWS, and cloud security technologies while driving Identity and Access Management, Zero Trust, and cloud governance initiatives across the organisation.

Your direct manager will be Krystian Gorzkiewicz , Head of Cloud Center of Excellence.

Primary tasks and responsibilities include:
  • Design, implement, and operate Identity and Access Management solutions across Azure and AWS environments.
  • Manage Microsoft Entra ID, Conditional Access, MFA, Privileged Identity Management (PIM), and Identity Governance capabilities.
  • Design and maintain AWS IAM, IAM Identity Center, permission models, federated access, and least-privilege controls.
  • Collaborate with Cloud Architects, Security Engineers, Platform Engineers, Compliance Specialists, and application teams to implement secure cloud onboarding and access models.
  • Automate identity lifecycle management, access provisioning, and governance processes using Infrastructure as Code and scripting.
  • Support audits, compliance reviews, security assessments, and operational risk initiatives related to cloud platforms.
  • Travel occasionally to Denmark (typically 2-4 times per year) and participate in workshops, PI Planning events, and stakeholder meetings.
To succeed you will have:
  • A curious mindset, an open nature, and a strong willingness to share knowledge with others.
  • Fluent English communication skills, both written and spoken.
  • A Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
  • Hands‑on experience with Microsoft Entra ID (Azure AD), Conditional Access, MFA, RBAC, Privileged Identity Management (PIM), and Identity Governance.
  • Experience with AWS IAM, IAM Identity Center, cross‑account access, role‑based access control, and cloud security best practices.
  • Strong understanding of Zero Trust principles, authentication, authorisation, federation, identity lifecycle management, and cloud platform operations in Azure and, preferably, AWS within regulated or enterprise‑scale environments.
  • Knowledge of Infrastructure as Code and automation technologies such as Terraform, Bicep, PowerShell, Python, or GitHub Actions, together with proficiency in GitHub Copilot and M365 Copilot as productivity and engineering accelerators.
It's nice‑to‑have:
  • Microsoft Certified: Azure Administrator Associate (AZ-104) or Microsoft Certified: Identity and Access Administrator Associate (SC-300), or equivalent certification.
  • AWS Certified Security - Specialty, or other AWS security-focused certifications.
  • Experience with Microsoft Defender or AWS security services such as GuardDuty, Security Hub, and CloudTrail.
  • Experience implementing Zero Trust transformation programmes.
  • Experience working in the financial sector or other highly regulated industries.
  • Knowledge of Active Directory, hybrid identity, and federation solutions.
  • Experience supporting audit, compliance, or regulatory requirements such as DORA, ISO 27001, NIS2, or similar.
Be your best self with BEC's benefits!
  • Mental health support
  • Free lunch at the office
  • Professional development budget
  • Referral bonus up to PLN 10,000
  • PLN 600 on a benefit platform a month
  • Passion clubs and social events (tennis, salsa dancing, board games, family picnics and more)
What does the recruitment process look like?

If you have any questions about the position, please contact Robert Piec .

BEC is in the process of being acquired by our largest customer and co-owner, Nykredit, which is Denmark's largest mortgage provider and third-largest bank. We will become part of a new and larger organization called Nykredit Financial Technologies. In the transition phase, we are recruiting for roles that we expect to be highly needed in our future organization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud security engineer - IAM (Azure & AWS)
Cloud security engineer - IAM (Azure & AWS)

PARETO SECURITIES AS • Warszawa

On-site
PLN 180,000 - 260,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2
Senior Software Engineer (I*Net Basement)
Senior Software Engineer (I*Net Basement)

PARETO SECURITIES AS • Warszawa

Hybrid
PLN 180,000 - 260,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2
Senior AI engineer
Senior AI engineer

PARETO SECURITIES AS • Warszawa

On-site
PLN 240,000 - 320,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2
DB2 Subject‑matter expert
DB2 Subject‑matter expert

PARETO SECURITIES AS • Warszawa

On-site
PLN 180,000 - 300,000
Mental health support
Free lunch at the office
Referral bonus
+2
Java software engineer (Senior)- Core Banking
Java software engineer (Senior)- Core Banking

BEC Financial Technologies • Warszawa

On-site
PLN 180,000 - 240,000
Mental health support
Free lunch at the office
Professional development budget
+3
Senior Java Platform Engineer — OpenShift Modernization
Senior Java Platform Engineer — OpenShift Modernization

PARETO SECURITIES AS • Warszawa

Hybrid
PLN 180,000 - 260,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2
Cloud Security Engineer: IAM & Zero Trust (Azure & AWS)
Cloud Security Engineer: IAM & Zero Trust (Azure & AWS)

PARETO SECURITIES AS • Warszawa

On-site
PLN 180,000 - 260,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2
Multi-Cloud Identity & Access Security Engineer
Multi-Cloud Identity & Access Security Engineer

BEC Financial Technologies • Warszawa

On-site
PLN 240,000 - 360,000
Mental health support
Free lunch at the office
Professional development budget
+2
OpenShift Platform Engineer
OpenShift Platform Engineer

PARETO SECURITIES AS • Warszawa

On-site
PLN 201,000 - 357,000
Flexible working hours
Mental health support
Free lunch at the office
+3
Senior Data Engineer
Senior Data Engineer

BEC Financial Technologies • Warszawa

On-site
PLN 180,000 - 270,000
Mental health support
Free lunch at the office
Professional development budget
+3