AI-Augmented IAM Security Engineer w Kraków, Polska is listed on Jobeax. Browse 110,000+ vacancies available.
We are seeking an AI-Augmented IAM Security Engineer to handle the hands-on implementation, configuration, automation and day-to-day operation of enterprise Identity and Access Management. This is a delivery-and-operations role that works within the designs, standards, role models and policies set by IAM architects and security leadership. The focus is building, configuring, scripting, running and troubleshooting IAM, not defining target-state architecture, role models or governance policy. Responsibilities Implement, configure and operate IAM solutions and controls based on architecture, standards and designs defined by IAM architects and security leadershipMaintain identity lifecycle (Joiner / Mover / Leaver) processes, including automated provisioning and deprovisioning across target systemsConfigure core IAM capabilities, including SSO, federation, MFA and passwordless authentication, conditional access, RBAC/ABAC role models and least-privilege accessDevelop and deploy IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases and APIsExecute access certification and review campaigns, perform entitlement clean-up and configure segregation-of-duties (SoD) rules according to access policies defined by architects and the businessOperate Privileged Access Management controls, including credential vaulting, secrets rotation, session management and just-in-time and just-enough accessDevelop automation scripts, workflows and IAM tooling using PowerShell, Python, REST APIs, SCIM, Terraform or similar technologiesMonitor IAM platform health, troubleshoot and resolve incidents and access issues, and perform patching, upgrades and configuration hardeningMaintain IAM logging, alerting and monitoring, and run backup and recovery procedures according to defined runbooks and resilience requirementsDeploy AI-assisted automations and agentic workflows that reduce manual effort across daily IAM operations, such as access request triage, entitlement analysis, anomaly detection, root-cause analysis, privileged access review support, compliance evidence collection and documentation generationIntegrate AI agents and LLM-backed automations into IAM systems and operational pipelines, connecting models to internal tools, APIs, directories, ticketing and IAM platforms via function calling, SCIM, REST and webhooksDevelop and maintain reusable prompts, structured-prompting patterns and prompt templates, and implement retrieval over IAM policies, role catalogs, runbooks and documentation (for example RAG) so AI assistants answer from current authoritative internal sourcesImplement output verification, human-in-the-loop approval gates and rollback paths in AI-assisted IAM workflows, so no AI-driven change reaches production access without reviewImplement security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data and full auditability of AI-driven actionsMonitor AI-assisted IAM automations in production, measure their accuracy and impact, continuously tune prompts, tools and workflows, and produce operational documentation, runbooks and standard operating procedures while supporting audits and compliance evidence requests Requirements Bachelor's degree in Computer Science, Cybersecurity, Engineering or equivalent practical experience2+ years of hands-on experience implementing or operating Identity and Access Management solutionsExperience with at least one enterprise IAM, IGA, PAM or federation platformUnderstanding of IAM concepts, including identity lifecycle, authentication and authorization, SSO, federation, MFA, RBAC/ABAC, least privilege and privileged accessKnowledge of common IAM protocols and standards such as SAML, OAuth 2.0 and OpenID Connect, alongside SCIM, LDAP and KerberosExperience configuring IAM controls, policies, connectors and access governance workflowsWorking knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS or GCPScripting and automation experience using at least one of PowerShell, Python, Bash, REST APIs, SCIM or TerraformCapability to work closely with developers, architects, infrastructure engineers, security operations, compliance teams and business stakeholdersCompetency to follow, maintain and improve defined IAM and security processes, executing changes from tickets, runbooks and designs while escalating design-level questionsPractical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including building AI agents, automating repetitive IAM tasks, integrating LLMs with tools and documents, prompt engineering and using AI tools securely with awareness of sensitive identity dataGood communication skills and the ability to explain IAM issues, technical decisions and remediation steps to both technical and non-technical stakeholders Nice to have Familiarity with IAM platforms such as Microsoft Entra ID, Active Directory and Okta, alongside Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt or CyberArkExperience with CIAM, B2B/B2C identity, customer identity, external identity or partner access scenarios, plus SIEM/SOAR integrations for IAM monitoring, alerting and automated responseExperience with CI/CD-based IAM deployment, configuration-as-code and automated testing of IAM changesFamiliarity with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock and Microsoft Copilot Studio, alongside LangChain, AutoGen or Power AutomateUnderstanding of AI security risks, including data leakage, prompt injection, excessive agency, insecure tool use, model governance and sensitive identity data exposureSC-300, Okta Certified Professional / Administrator / Consultant, SailPoint, Saviynt, CyberArk or Ping Identity certifications, CISSP, CISM, CISA, CCSK, CCSP, SSCP, AI-900 or AWS Certified AI Practitioner We offer We gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and an agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:We will reach out to selected candidates exclusively EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.