Lead Azure AI Security Engineer

EPAM Systems

Łódź

Hybrid

PLN 250,000 - 400,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid by design
Remote within Poland
Relocation opportunities
Career development programs
English classes

Job summary

EPAM Systems is seeking a Lead Azure AI Security Engineer to provide technical leadership and domain expertise in securing Azure and Microsoft cloud environments at enterprise scale.

You will design and improve security architecture across Azure, Microsoft 365, Entra ID, and hybrid/multi-cloud environments, leveraging AI-powered tooling to automate and enhance security operations. The role emphasizes collaboration with cross-functional teams and advance Zero Trust initiatives.

Qualifications

  • 3+ years of experience in software development or security engineering.
  • Hands-on with Microsoft Azure services and cloud security concepts.
  • Strong understanding of enterprise-scale cloud environments and security controls.

Responsibilities

  • Provide technical leadership in securing Azure and Microsoft cloud environments at enterprise scale.
  • Design and implement security architecture across Azure, M365, Entra ID, and multi-cloud environments.
  • Develop and maintain automation scripts and security tooling using PowerShell, Python, and REST APIs.
  • Embed security into the full delivery lifecycle by collaborating with engineering, DevOps, and operations teams.
  • Support zero-trust implementations, secure authentication, conditional access and identity protection.

Skills

Azure
Python
PowerShell
KQL
REST APIs

Education

Bachelor's degree in Computer Science or related field

Tools

Azure CLI
Logic Apps
Azure Functions

Job description

We are seeking a Lead Azure AI Security Engineer to provide technical leadership and subject matter expertise in securing Azure and Microsoft cloud environments at enterprise scale. In this role you will design and improve security architecture while leveraging AI-powered tools to automate and enhance daily security engineering activities across hybrid and multi-cloud environments.

Responsibilities
  • Provide technical leadership and subject matter expertise in securing Azure and Microsoft cloud environments at enterprise scale
  • Design, implement and improve security architecture across Azure, Microsoft 365, Microsoft Entra ID, hybrid and multi-cloud environments, with Azure as the primary cloud platform
  • Work across key cloud security domains including CSPM/CNAPP, Identity and Access Management, Privileged Access Management, Data Protection and Data Loss Prevention, Microsoft Defender security stack, SIEM/SOAR, Business Continuity and Disaster Recovery, DevSecOps, container and Kubernetes security and policy-as-code
  • Plan, design and implement security controls for cloud workloads, applications, infrastructure and data
  • Collaboration with engineering, infrastructure, development, DevOps, database, operations and compliance teams to embed security into the full delivery lifecycle
  • Support implementation and continuous improvement of Zero Trust architecture, secure authentication, conditional access, least privilege and identity protection
  • Develop and maintain automation scripts, workflows and security tooling using PowerShell, Python, Azure CLI, Logic Apps, Azure Functions, KQL and REST APIs
  • Use AI-powered tools and agentic workflows to automate and improve security activities such as findings triage, log analysis, incident investigation support, configuration review, compliance evidence collection and vulnerability analysis
  • Design or integrate AI agents and AI-assisted automations using modern AI platforms and frameworks while ensuring proper security, privacy and governance controls
  • Contribute to secure adoption of AI technologies by defining guardrails for data protection, access control, prompt security, model usage, auditability and human-in-the-loop processes
  • Train and support other team members on cloud security practices, security processes and AI-assisted automation approaches
Requirements
  • 3+ years of experience in software development
  • Bachelor's degree in Computer Science, Information Security, Engineering or equivalent practical experience
  • Hands‑on experience with Microsoft Azure services
  • Strong understanding of cloud security concepts, Azure architecture and enterprise-scale cloud environments
  • Practical experience with Microsoft Entra ID/Azure Active Directory, Microsoft Defender for Cloud and Microsoft Defender XDR
  • Skills in Microsoft Sentinel, Microsoft Purview and Microsoft Intune
  • Proficiency in Conditional Access, Identity Protection and Privileged Identity Management
  • Competency in Key Vault, Azure Policy and Azure Monitor/Log Analytics
  • Strong engineering background including experience with Active Directory, Microsoft Entra ID, Microsoft 365, Exchange Online and hybrid identity
  • Security engineering experience in at least one business or technology domain along with participation in at least several production projects
  • Understanding of software development lifecycle, DevOps/DevSecOps practices, cloud security assessment methodologies and secure-by-design principles
  • Ability to work closely with developers, business analysts, QA engineers, architects, project managers, infrastructure and operations teams and to follow, maintain and improve defined security processes
  • Practical understanding of AI‑assisted productivity and automation including building or configuring AI agents, integrating LLMs with tools, APIs and workflows, prompt engineering and using AI tools securely with awareness of sensitive data handling
  • Good communication skills and ability to explain security risks, technical decisions and remediation plans to both technical and non-technical stakeholders
Nice to have
  • Skills in scripting and automation using PowerShell, Python, Bash, Azure CLI, Terraform or Bicep
  • Familiarity with SIEM/SOAR platforms, especially Microsoft Sentinel, KQL and Logic Apps
  • Experience with CNAPP/CSPM/CWPP/CIEM tools such as Prisma Cloud, Wiz and Orca or Lacework, Check Point CloudGuard and CrowdStrike or Tenable and Rapid7
  • Understanding of compliance frameworks such as ISO 27001, NIST and CIS Benchmarks or PCI DSS, HIPAA and HITRUST
  • Knowledge of container and Kubernetes security including AKS, container registries and image scanning
  • Familiarity with AI/LLM platforms such as Azure OpenAI, Azure AI Foundry and Microsoft Copilot Studio or Semantic Kernel, LangChain and AutoGen
  • Understanding of AI security risks including data leakage, prompt injection, excessive agency and AI supply chain risks
  • Experience implementing AI governance and secure AI usage policies aligned with frameworks such as NIST AI RMF, OWASP Top 10 for LLM Applications or ISO/IEC 42001
  • AZ-500, SC-100, SC-200
  • SC-300, SC-400, AZ-104
  • AZ-305, CISSP, CISM
  • CISA, CCSK, CCSP, SSCP
  • AI-900, AI-102, PL-900/PL-200
We offer
  • We gather like-minded people:
  • Top tech minds driving innovation in AI, cloud and digital platform modernization
  • Supportive team and agile, startup-like culture
  • Hybrid by design mode and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • We provide growth opportunities:
  • Career development programs
  • Thought leadership, mentoring, soft skills and well-being programs
  • Certification (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • We cover it all:
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
  • Corporate, social and well-being events
  • Please, note:
  • Benefits listed above are available to employees only
  • We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
  • We will reach out to selected candidates exclusively

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI‑Native enterprises, driving measurable value from innovation and digital investments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Azure Cloud Engineer
Lead Azure Cloud Engineer

EPAM Systems • Poland

Hybrid
PLN 240,000 - 360,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Lead AI Security Engineer
Lead AI Security Engineer

EPAM Systems • Poland

Hybrid
PLN 280,000 - 480,000
Health insurance
Employee stock purchase plan
Hybrid by design (Poland)
+1
AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM Systems • Poznań

Hybrid
PLN 180,000 - 240,000
Hybrid by design
Remote within Poland
Health insurance
+4
Senior Python Automation Engineer - Cyber Security Implementation & Adoption
Senior Python Automation Engineer - Cyber Security Implementation & Adoption

EPAM Systems • Województwo pomorskie

Hybrid
PLN 150,000 - 210,000
Hybrid by design mode
Work remotely within Poland
Work abroad up to 60 days annually
+4
AI Architect
AI Architect

EPAM Systems • Województwo pomorskie

Hybrid
PLN 260,000 - 380,000
Hybrid by design
Remote work within Poland
Relocation opportunities
+4
Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

EPAM Systems • Poland

Hybrid
PLN 180,000 - 320,000
Hybrid by design
Remote within Poland
Work abroad up to 60 days/year
+8
Senior AI/ML Solution Engineer (AI Agentic Security Testing)
Senior AI/ML Solution Engineer (AI Agentic Security Testing)

EPAM Systems • Łódź

Hybrid
PLN 250,000 - 390,000
Hybrid work model
Relocation opportunities
English classes
+2
Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

EPAM Systems, Inc. • Poland

Hybrid
PLN 180,000 - 260,000
Health insurance
Multisport card
Shopping vouchers
+2
Senior Cloud Engineer (Blockchain) - Digital Assets
Senior Cloud Engineer (Blockchain) - Digital Assets

EPAM Systems • Kraków

On-site
PLN 180,000 - 300,000
Hybrid by design
Remote work within Poland
Work abroad up to 60 days annually
+5
Senior Systems Engineer - Unix/Windows
Senior Systems Engineer - Unix/Windows

EPAM Systems • Województwo pomorskie

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Remote within Poland
Relocation opportunities
+3