security engineer for enterprise AI services

HireHi

United States

Remote

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

HireHi ищет опытного инженера по безопасности облачных сервисов для разработки централизованного слоя авторизации для enterprise AI и облачных приложений.

Вы будете проектировать политики на Cedar, реализовывать policy-as-code, настраивать ABAC и интеграцию с Entra ID, OAuth 2.0 и OIDC, и поддерживать аудит и требования соответствия.

Qualifications

  • Опыт не менее 5 лет в инженерии облачной безопасности/идентификации.
  • Практический опыт проектирования и внедрения ABAC.
  • Глубокие знания OAuth 2.0, JWT, OIDC и федерации идентификации.
  • Опыт инспекции токенов и сопоставления утверждений с политиками.

Responsibilities

  • Разрабатывать и внедрять фреймворки авторизации на Cedar.
  • Разрабатывать и поддерживать решения policy-as-code для корпоративных платформ и AI-сервисов.
  • Определять и применять модели ABAC в приложениях и облаке.
  • Интегрировать сервисы авторизации с Microsoft Entra ID, OAuth2, JWT и OIDC.
  • Проектировать модели доступа по умолчанию с запретом по умолчанию.
  • Разрабатывать аудит логирования решений авторизации и оценок политик.
  • Сотрудничать с архитектурой безопасности и правовым отделом.
  • Картировать identity claims и token attributes к политикам.
  • Участвовать в обзоре дизайна и улучшениях контроля.
  • Вносить вклад в стандарты безопасности и документацию.
  • Поддерживать принципы zero-trust в облачных средах.

Skills

ABAC доступ
OAuth 2.0
OIDC
Cedar язык политики
Policy-as-code
Аудит-логирование
Zero Trust

Tools

AWS Cedar
AWS Verified Permissions

Job description

Описание

The project is building a centralized authorization layer for enterprise AI services and cloud applications. The platform enables secure, policy-based access decisions, integrates with enterprise identity providers, and supports governance, compliance, and audit requirements across distributed environments.

Задачи
  • Design and implement authorization frameworks using Cedar-based policies
  • Develop and maintain policy-as-code solutions for enterprise platforms and AI services
  • Define and enforce attribute-based access control models across applications and cloud environments
  • Integrate authorization services with Microsoft Entra ID, OAuth 2.0, JWT, and OpenID Connect-based identity systems
  • Design default-deny access models and secure authorization patterns
  • Build and maintain audit logging mechanisms for authorization decisions and policy evaluations
  • Collaborate with security architecture and governance teams on security reviews and compliance requirements
  • Map identity claims and token attributes to authorization policies and access control models
  • Review platform designs and recommend improvements to authorization, governance, and security controls
  • Contribute to enterprise security standards, documentation, and best practices
  • Support zero-trust initiatives and secure access programs across cloud environments
Требования
  • At least 5 years of experience in cloud security engineering, identity engineering, or a related security field
  • Hands-on experience designing and implementing attribute-based access control solutions
  • Strong understanding of OAuth 2.0, JWT, OpenID Connect, and identity federation concepts
  • Experience inspecting authentication tokens and mapping claims to authorization policies
  • Experience designing, implementing, or governing policy-based access control systems
  • Knowledge of Cedar policy language concepts, including principals, actions, resources, and conditions
  • Experience with policy-as-code methodologies and authorization frameworks
  • Experience participating in enterprise security reviews, architecture review boards, or information security governance processes
  • Understanding of secure audit logging and authorization decision traceability
  • Strong written and verbal communication skills
  • Будет плюсом: experience with AWS Cedar or other Cedar-based authorization frameworks, AWS Verified Permissions or AWS AgentCore Policy services, zero-trust architecture principles and implementation patterns, enterprise AI platforms and authorization governance initiatives, cloud-native security services and modern identity architectures, scalable authorization platforms for distributed systems
Условия

Work location options include Armenia (Yerevan); Bulgaria (remote, Sofia, Varna); Cyprus (Larnaca); Georgia (remote, Tbilisi); Kazakhstan (Almaty, Astana, remote); Latvia (Riga); Poland (Krakow, Lodz, Lublin, remote, Warsaw, Wroclaw); Romania (Cluj-Napoca); Serbia (Belgrade); and Ukraine (Dnipro, Kharkiv, Kyiv, Lviv, Odesa)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer with Cedar Policy
Security Engineer with Cedar Policy

Aether Biomedical • United States

On-site
USD 110,000 - 150,000
Vacation days 26+
Sick days 10
Health and life insurance
+7
Security Engineer with Cedar Policy
Security Engineer with Cedar Policy

Jobo • United States

Remote
USD 110,000 - 160,000
security engineer for agent authorization
security engineer for agent authorization

HireHi • United States

Remote
USD 130,000 - 170,000
security engineer for financial and payment data
security engineer for financial and payment data

HireHi • United States

Hybrid
USD 110,000 - 150,000
Relocation support to company hubs
Flexible work from offices or remote
Healthcare coverage
+3
Security Engineer: Authorization Policy & Identity
Security Engineer: Authorization Policy & Identity

Jobo • United States

Remote
USD 110,000 - 160,000
cloud engineer (IaaS)
cloud engineer (IaaS)

HireHi • United States

Remote
USD 47,000 - 68,000
ai engineer
ai engineer

HireHi • United States

Remote
USD 140,000 - 190,000
—
security engineer in cloud environments
security engineer in cloud environments

HireHi • United States

Remote
USD 90,000 - 130,000
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
devops engineer in cloud infrastructure
devops engineer in cloud infrastructure

HireHi • United States

Remote
USD 120,000 - 180,000
Private health insurance
Remote or hybrid work options
Career growth & mentoring
+5