security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
EPAM is a leading global provider of digital platform engineering and development services committed to making a positive impact on customers, employees, and communities while fostering a dynamic and inclusive culture.
задачи
- Deploy, configure, and run IAM solutions and controls guided by architecture, standards, and designs set by IAM architects and security leadership;
- Establish and sustain identity lifecycle processes, covering automated provisioning and deprovisioning across target systems;
- Set up and maintain core IAM capabilities such as SSO, federation, MFA, passwordless authentication, conditional access, RBAC/ABAC role models, and least-privilege access;
- Create, roll out, and maintain IAM integrations and connectors with cloud platforms, SaaS applications, enterprise systems, directories, authoritative source systems, databases, and APIs;
- Run access certification and review campaigns, carry out entitlement clean-up, and configure segregation-of-duties rules in line with access policies set by architects and the business;
- Deploy and operate Privileged Access Management controls, including credential vaulting, secrets rotation, session management, and just-in-time and just-enough access;
- Build and maintain automation scripts, workflows, and IAM tooling with PowerShell, Python, REST APIs, SCIM, Terraform, or comparable technologies;
- Track IAM platform health, diagnose and resolve incidents and access issues, and handle patching, upgrades, and configuration hardening;
- Set up and maintain IAM logging, alerting, and monitoring, and execute backup and recovery procedures per defined runbooks and resilience requirements;
- Create, deploy, and maintain AI-assisted automations and agentic workflows that cut manual effort across daily IAM operations;
- Develop and embed AI agents and LLM-backed automations into IAM systems and operational pipelines;
- Build, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring IAM tasks;
- Set up retrieval over IAM policies, role catalogs, runbooks, and documentation so AI assistants respond from current, authoritative internal sources;
- Put in place output verification, human-in-the-loop approval gates, and rollback paths within AI-assisted IAM workflows;
- Apply security and privacy controls for IAM AI usage, including least-privilege access for agents, secrets and credential handling, prompt-injection resistance, redaction of sensitive identity data, and complete auditability of AI-driven actions;
- Oversee AI-assisted IAM automations in production, gauge their accuracy and impact, and continually refine prompts, tools, and workflows;
- Create and maintain operational documentation, runbooks, and standard operating procedures, and assist with audits and compliance evidence requests.
требования
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience;
- Minimum 2 years of hands-on experience deploying or operating Identity and Access Management solutions;
- Hands-on experience with at least one enterprise IAM, IGA, PAM, or federation platform;
- Strong grasp of IAM concepts, including identity lifecycle, authentication, authorization, SSO, federation, MFA, RBAC/ABAC, least privilege, and privileged access;
- Practical familiarity with common IAM protocols and standards, such as SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and Kerberos;
- Experience setting up IAM controls, policies, connectors, and access governance workflows;
- Working knowledge of cloud IAM concepts across at least one major cloud platform such as Azure, AWS, or GCP;
- Scripting and automation experience with at least one of PowerShell, Python, Bash, REST APIs, SCIM, or Terraform;
- Capacity to collaborate closely with developers, architects, infrastructure engineers, security operations, compliance teams, and business stakeholders;
- Capacity to follow, maintain, and enhance defined IAM and security processes;
- Comfortable carrying out changes from tickets, runbooks, and designs supplied by senior engineers and architects, and escalating design-level questions rather than owning them;
- Practical grasp of AI-assisted productivity and automation beyond basic chatbot usage;
- Strong communication skills and the ability to explain IAM issues, technical decisions, and remediation steps to technical and non-technical stakeholders;
- Hands-on proficiency is essential;
- English proficiency at B2 level or higher;
- Nice to have: experience with Microsoft Entra ID, Active Directory, Okta, Ping Identity, ForgeRock, Auth0, SailPoint, Saviynt, CyberArk, or similar IAM platforms, experience with CIAM, B2B/B2C identity, customer identity, external identity, or partner access scenarios, experience with SIEM/SOAR integrations for IAM monitoring, alerting, and automated response, experience with CI/CD-based IAM deployment, configuration-as-code, and automated testing of IAM changes, experience with AI/LLM platforms or frameworks such as Azure OpenAI, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen, or Power Automate, awareness of AI security risks, security or IAM certifications such as SC-300, Okta Certified Professional / Administrator / Consultant, SailPoint, Saviynt, CyberArk, or Ping Identity certifications, CISSP, CISM, CISA, CCSK, CCSP, SSCP, or similar, AI-related certifications such as AI-900 or AWS Certified AI Practitioner.
условия
- Diverse multicultural, multi-functional, and multilingual work environment;
- Global scope and international projects in different business domains;
- Career development opportunities with a transparent career path;
- Professional training, career advisory and coaching, sponsored professional certifications, well-being programs, and LinkedIn Learning Solutions;
- Knowledge-sharing with colleagues from global tech communities;
- English language courses;
- 25 Days holiday per annum;
- 5 Days of sick leave without medical certification;
- Private health insurance for employees and discount for private health insurance for family members;
- Discount for Fit Pass program;
- Comfortable modern offices in Belgrade and Novi Sad or remote work from any location in Serbia;
- Regular corporate and social events;
- Learning programs for kids.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.