Security Engineer with Cedar Policy
12000 - 16500 złDataArt Poland sp. z o.o.
Security Engineer with Cedar Policy
Miejsce pracy: Warszawa
Technologies we use
Expected
- C#
- Python
- OpenAI API
Optional
- LangGraph
- AWS
- Microsoft Azure
- OpenAI API
Operating system
- Windows
- Linux
About the project
The project focuses on delivering a centralized authorization framework for enterprise AI services and cloud applications. The platform provides secure policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.
This is how we organize our work
Team size
10-20
This is how we work
- you have influence on the technological solutions applied
- you have influence on the product
- you develop the code "from scratch"
- you focus on product development
- agile
Team members
- backend developer
- technical leader
- architect
- devOps
- product owner
Your responsibilities
- Develop and maintain authorization policies using the Cedar policy language
- Author, test, and validate policy definitions for enterprise applications and AI services
- Implement and support access control models using attribute based and role based authorization approaches
- Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito
- Map identity claims and token attributes to authorization decisions and policy rules
- Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes
- Develop Python based tooling for policy validation, testing, and automation
- Design and implement parameter level access control patterns for secure tool and service interactions
- Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls
- Contribute to audit logging and authorization decision traceability practices
- Support security reviews and help maintain authorization governance standards
Our requirements
- 3+ years of experience in security engineering, backend engineering, or a related field
- Hands on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito
- Experience defining and managing policies within an ABAC or RBAC authorization framework
- Hands on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies
- Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures
- Experience working with claims mapping and token based authorization models
- Understanding of secure authorization design principles and policy lifecycle management
- Experience with Python development for automation, validation, or backend services
- Strong analytical and problem solving skills
- Good written and verbal communication skills
Optional
- Experience with LangGraph tool invocation patterns
- Experience integrating with AWS AgentCore Gateway
- Knowledge of enterprise AI platform architecture and governance principles
- Experience implementing policy as code methodologies
- Familiarity with cloud native security services and authorization platforms
- Exposure to audit logging and compliance reporting requirements
This is how we work on a project
- DevOps
- documentation
Development opportunities we offer
- substantive support from technological leaders
- time for development of your ideas
DataArt Poland sp. z o.o.
Our client is a UK financial services group operating in a highly regulated environment, currently rebuilding its data and analytics capability as part of a wider platform modernisation programme.
By applying, I consent to the processing of my personal data for the purpose of conducting the recruitment process. Informujemy, że administratorem danych jest DataArt Poland Sp z o o z siedzibą w Lublinie, Ul. Zana 39 a, 20-601 Lublin (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją
- security engineer cyber defense Warszawa
- security engineer Warszawa
- security engineer integrated risk management Warszawa
- cloud security engineer Warszawa
- IT security engineer Warszawa
- senior windows security engineer Warszawa
- network security engineer Warszawa
- senior network security engineer Warszawa
- senior security specialist security engineering Warszawa
- ochrona j Warszawa