IAM Security Architect IRC302833

GlobalLogic

Kraków

On-site

PLN 180,000 - 300,000

Full time

7 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Empowering Projects
Empowering Growth
DE&I Matters
Career Development
Comprehensive Benefits
Flexible Opportunities

Job summary

GlobalLogic in Kraków is seeking an experienced cybersecurity IAM engineer to design and implement identity and access management architectures for workforce and customer identities, including SSO and MFA, across cloud and hybrid environments.

You will lead migrations between IdPs, implement provisioning and lifecycle controls (OAuth2/OIDC, SAML, SCIM), and help embed IAM within Zero Trust patterns while collaborating with engineering teams.

Qualifications

  • 5+ years in IAM / identity security, including architecture experience.
  • Hands-on with major identity providers (e.g. Entra ID / Azure AD, Okta, Ping, ForgeRock, Keycloak, AWS IAM).
  • Strong with OAuth2, OIDC, SAML, SCIM, federation, SSO and MFA.
  • Proven identity-provider migration / consolidation and IAM modernization experience.
  • PAM, RBAC / ABAC, authorization and identity lifecycle management.
  • Zero Trust, cloud IAM and hybrid environments.
  • Good grasp of adjacent security domains and standards (NIST, ISO 27001).
  • Working understanding of and hands-on experience with different LLMs, and how AI can support identity security and automation.
  • Ability to build AI agents / agentic workflows and integrate them into IAM processes.
  • Understanding of how LLMs are embedded into the SDLC
  • Awareness of AI / LLM security risks (prompt injection, data exposure).
  • Nice to have: relevant certifications (CISSP, vendor IdP certs); scripting / automation.

Responsibilities

  • Design and implement IAM architectures (workforce and customer identity, SSO, MFA, federation).
  • Lead identity-provider migrations and consolidations between IdPs.
  • Build, integrate and upgrade access management, provisioning and lifecycle (OAuth2 / OIDC, SAML, SCIM).
  • Design privileged access management (PAM) and least-privilege / authorization models (RBAC / ABAC).
  • Embed IAM into Zero Trust architecture and secure cloud patterns.
  • Define IAM standards, policies and reference architectures.
  • Assess existing identity estates for risks and gaps, and plan remediation or upgrade.
  • Contribute to adjacent security topics (application, cloud and data security).
  • Advise and support engineering teams during implementation.

Skills

IAM expertise
OAuth2 / OIDC
SAML / SCIM
Zero Trust
IAM migrations
PAM / RBAC / ABAC
AI in IAM
LLMs in SDLC
Security standards
Certifications

Tools

Azure AD / Entra ID
Okta
Ping Identity
Keycloak
ForgeRock
AWS IAM

Job description

Description

A cybersecurity engineering team builds and modernizes identity and access management across a large, multi-company technology group and its clients. Projects range from migrating and consolidating identity providers to designing new IAM architectures and upgrading legacy access systems. The work covers workforce and customer identity, single sign-on, privileged access and Zero Trust, across cloud and hybrid environments. Alongside IAM, the role contributes to broader security topics such as application, cloud and data protection. It is a hands-on, design-and-build role in a fast-growing, high-impact area.

Requirements
  • 5+ years in IAM / identity security, including architecture experience.
  • Hands-on with major identity providers (e.g. Entra ID / Azure AD, Okta, Ping, ForgeRock, Keycloak, AWS IAM).
  • Strong with OAuth2, OIDC, SAML, SCIM, federation, SSO and MFA.
  • Proven identity-provider migration / consolidation and IAM modernization experience.
  • PAM, RBAC / ABAC, authorization and identity lifecycle management.
  • Zero Trust, cloud IAM and hybrid environments.
  • Good grasp of adjacent security domains and standards (NIST, ISO 27001).
  • Working understanding of and hands-on experience with different LLMs, and how AI can support identity security and automation.
  • Ability to build AI agents / agentic workflows and integrate them into IAM processes.
  • Understanding of how LLMs are embedded into the SDLC
  • Awareness of AI / LLM security risks (prompt injection, data exposure).
  • Nice to have: relevant certifications (CISSP, vendor IdP certs); scripting / automation.
Job responsibilities
  • Design and implement IAM architectures (workforce and customer identity, SSO, MFA, federation).
  • Lead identity-provider migrations and consolidations between IdPs.
  • Build, integrate and upgrade access management, provisioning and lifecycle (OAuth2 / OIDC, SAML, SCIM).
  • Design privileged access management (PAM) and least-privilege / authorization models (RBAC / ABAC).
  • Embed IAM into Zero Trust architecture and secure cloud patterns.
  • Define IAM standards, policies and reference architectures.
  • Assess existing identity estates for risks and gaps, and plan remediation or upgrade.
  • Contribute to adjacent security topics (application, cloud and data security).
  • Advise and support engineering teams during implementation.
What we offer

Empowering Projects: With 500+ clients spanning diverse industries and domains, we provide an exciting opportunity to contribute to groundbreaking projects that leverage cutting-edge technologies. As a team, we engineer digital products that positively impact people’s lives.

Empowering Growth: We foster a culture of continuous learning and professional development. Our dedication is to provide timely and comprehensive assistance for every consultant through our dedicated Learning & Development team, ensuring their continuous growth and success.

DE&I Matters: At GlobalLogic, we deeply value and embrace diversity. We are dedicated to providing equal opportunities for all individuals, fostering an inclusive and empowering work environment.

Career Development: Our corporate culture places a strong emphasis on career development, offering abundant opportunities for growth. Regular interactions with our teams ensure their engagement, motivation, and recognition. We empower our team members to pursue their career goals with confidence and enthusiasm.

Comprehensive Benefits: In addition to equitable compensation, we provide a comprehensive benefits package that prioritizes the overall well-being of our consultants. We genuinely care about their health and strive to create a positive work environment.

Flexible Opportunities: At GlobalLogic, we prioritize work-life balance by offering flexible opportunities tailored to your lifestyle. Explore relocation and rotation options for diverse cultural and professional experiences in different countries with our company.

About GlobalLogic

GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward-thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Security Architect IRC302833
IAM Security Architect IRC302833

GlobalLogic • Poland

On-site
PLN 180,000 - 280,000
Learning & Development
Diversity & Inclusion
Relocation options
+1
CIAM Engineer IRC300978
CIAM Engineer IRC300978

GlobalLogic • Kraków

On-site
PLN 120,000 - 180,000
IAM Architect: Zero Trust & AI-Driven Identity
IAM Architect: Zero Trust & AI-Driven Identity

GlobalLogic • Poland

On-site
PLN 180,000 - 280,000
Learning & Development
Diversity & Inclusion
Relocation options
+1
Sr Director of Identity & Access Management
Sr Director of Identity & Access Management

Hitachi Digital • Warszawa

On-site
PLN 400,000 - 700,000
AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM • Poland

On-site
PLN 100,000 - 120,000
Senior Penetration Testing Engineer IRC301690
Senior Penetration Testing Engineer IRC301690

GlobalLogic • Kraków

On-site
PLN 180,000 - 280,000
Empowering Projects
Empowering Growth
DE&I Matters
+3
Forward-Deployed AI Architect – CEE IRC302351
Forward-Deployed AI Architect – CEE IRC302351

GlobalLogic • Kraków

On-site
PLN 300,000 - 420,000
Relocation options
Flexible opportunities
Global project exposure
Security Identity and Access Management Specialist
Security Identity and Access Management Specialist

Emergeconsulting • Warszawa

Hybrid
PLN 180,000 - 280,000
Remote-friendly model
Office visits in Warsaw
Senior DevOps Engineer (with Azure) IRC301377
Senior DevOps Engineer (with Azure) IRC301377

GlobalLogic • Kraków

On-site
PLN 180,000 - 280,000
Empowering Projects
Empowering Growth
DEI Matters
+3
Technical Pre-Sales Manager IRC302834
Technical Pre-Sales Manager IRC302834

GlobalLogic • Kraków

On-site
PLN 180,000 - 240,000
Empowering Projects
Growth & Learning
Diversity & Inclusion
+3