Policy Engineer (Cedar Implementation)

Intellias

Poland

On-site

PLN 180,000 - 260,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Intellias invites an experienced Policy Engineer to design, implement, and validate fine-grained authorization policies for AI agent platforms and cloud-native services. You will work with Cedar policy language, integrate with Entra/Okta/Cognito, and build Python tooling for policy validation and governance.

The role focuses on policy enforcement, access control models, and secure access governance across distributed systems, partnering with platform and security teams to ensure best practices.

Qualifications

  • 3+ years security engineering or backend engineering.
  • Identity provider integration with Entra, Okta, Cognito.
  • Policy definitions in ABAC or RBAC systems.

Responsibilities

  • Design, implement, and maintain Cedar-based authorization policies.
  • Develop policy definitions, validation workflows, and enforcement mechanisms.
  • Integrate authorization with identity providers and token-based flows.
  • Build Python tooling for policy validation and governance.
  • Create auditability and traceability for authorization decisions.

Skills

Cedar policy language
Python
ABAC / RBAC concepts
OAuth 2.0 / JWT
Policy as code

Tools

AWS AgentCore Policy
Entra
Okta
Cognito

Job description

We are looking for a Policy Engineer to design, implement, and validate fine-grained authorization policies for AI agent platforms and cloud-native services. The role focuses on Cedar policy development, identity provider integrations, policy enforcement, and attribute-based access control. The ideal candidate combines hands-on security engineering experience with strong Python skills and a deep understanding of modern authorization architectures.

What project we have for you

Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.

Intellia’s mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.

The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.

What you will do

  • Design, implement, and maintain authorization policies using Cedar policy language.
  • Develop and test policy definitions, validation workflows, and policy enforcement mechanisms.
  • Configure and manage AWS AgentCore Policy in LOG_ONLY and ENFORCE modes.
  • Build Python-based tooling for policy validation, testing, and governance.
  • Integrate authorization frameworks with Microsoft Entra ID and other identity providers.
  • Design claims mapping and token-based authorization flows using OAuth 2.0 and JWT.
  • Implement fine-grained and parameter-level access control models.
  • Develop and maintain ABAC and RBAC authorization patterns for platform services and AI agents.
  • Partner with platform and security teams to ensure secure access governance across distributed systems.
  • Create auditability and traceability mechanisms for authorization decisions.
  • Support adoption of policy-as-code practices and authorization best practices.

What you need for this

Cedar policy language — authoring and testing

Experience:

3+ years security engineering or backend engineering

Identity provider integration (Entra, Okta, Cognito)

Policy definition in any ABAC or RBAC system

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cedar Policy Engineer: Fine-Grained Access for AI & Cloud
Cedar Policy Engineer: Fine-Grained Access for AI & Cloud

Intellias • Poland

On-site
PLN 180,000 - 260,000
Senior Security Engineer with Cedar
Senior Security Engineer with Cedar

EPAM Systems • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work design
Remote within Poland
Relocation opportunities
+1
Senior Security Engineer — Cedar Policy & IAM (Remote/Hybrid)
Senior Security Engineer — Cedar Policy & IAM (Remote/Hybrid)

EPAM Systems • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work design
Remote within Poland
Relocation opportunities
+1
Security Test Engineer (Python)
Security Test Engineer (Python)

Intellias • Poland

On-site
PLN 120,000 - 210,000
Security & Test Engineer (A2A)
Security & Test Engineer (A2A)

Intellias • Poland

On-site
PLN 120,000 - 180,000
Security & AI Trust Engineer for Agent Networks
Security & AI Trust Engineer for Agent Networks

Intellias • Poland

On-site
PLN 120,000 - 180,000
Senior Platform Security Engineer for AI & IAM
Senior Platform Security Engineer for AI & IAM

Intellias • Poland

On-site
PLN 260,000 - 380,000
AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM • Poland

On-site
PLN 100,000 - 120,000
Senior Security & Test Engineer - A2A
Senior Security & Test Engineer - A2A

EPAM Systems • Łódź

Hybrid
PLN 200,000 - 280,000
Health insurance
Multisport card
Relocation opportunities
+1
Senior Backend Engineer (TypeScript / Nest.js / AWS)
Senior Backend Engineer (TypeScript / Nest.js / AWS)

Talanto • Warszawa

Hybrid
PLN 290,000 - 357,000