2 окт

security engineer for enterprise AI services

ориентир по рынку
вакансия зп не указана
в среднем 188 293 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

описание

The project delivers a centralized authorization framework for enterprise AI services and cloud applications. The platform provides policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.

задачи

  • Develop and maintain authorization policies using the Cedar policy language
  • Author, test, and validate policy definitions for enterprise applications and AI services
  • Implement and support access control models using attribute-based and role-based authorization approaches
  • Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito
  • Map identity claims and token attributes to authorization decisions and policy rules
  • Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes
  • Develop Python-based tooling for policy validation, testing, and automation
  • Design and implement parameter-level access control patterns for secure tool and service interactions
  • Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls
  • Contribute to audit logging and authorization decision traceability practices
  • Support security reviews and help maintain authorization governance standards

требования

  • 3+ Years of experience in security engineering, backend engineering, or a related field
  • Hands-on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito
  • Experience defining and managing policies within an ABAC or RBAC authorization framework
  • Hands-on experience with Open Policy Agent, Cedar, or similar policy-based authorization technologies
  • Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures
  • Experience with claims mapping and token-based authorization models
  • Understanding of secure authorization design principles and policy lifecycle management
  • Experience with Python development for automation, validation, or backend services
  • Strong analytical and problem-solving skills
  • Good written and verbal communication skills
  • Будет плюсом: experience with LangGraph tool invocation patterns, experience integrating with AWS AgentCore Gateway, knowledge of enterprise AI platform architecture and governance principles, experience implementing policy-as-code methodologies, familiarity with cloud-native security services and authorization platforms, exposure to audit logging and compliance reporting requirements

условия

  • Условий в вакансии нет

Глобальная software engineering компания, которая разрабатывает custom software и решения в области data, AI и cloud.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.