Lead Security / Policy Engineer
EPAM Systems
- Praca zdalna
To stanowisko wymaga obecności na miejscu. Zobacz podobne oferty poniżej.
We are seeking a Lead Security / Policy Engineer to architect the policy engine, Cedar policy schema, and InfoSec review processes for an enterprise-grade Agent Development Platform. This production-grade, cloud-native ecosystem enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale, standardizing agent development across the organization using LangGraph and Strands Agents on AWS AgentCore Runtime. The role centers on authorization at the agent boundary, ensuring agents securely advertise and invoke each other's capabilities while enforcing consistent security, quality, and governance standards. Responsibilities Lead the architecture of the policy engine and Cedar policy schema design across the platformDefine authorization models that govern agent-to-agent capability advertisement and invocationDrive enterprise InfoSec review processes and ensure alignment with ARB requirementsEstablish default-deny authorization patterns for agent interactionsIntegrate identity-aware authorization using OAuth 2.0, JWT, and MS EntraBuild and maintain policy-as-code patterns to standardize governance across agent development teamsOversee audit logging mechanisms for policy decisions and enforcement outcomesGuide staged rollout strategies for policy enforcement, from monitoring to full enforcementCollaborate with engineering teams to reason about trust boundaries between interacting agents Requirements 5+ years of experience in cloud security or identity engineeringHands-on experience with authorization or policy-as-code for AI agents in a production agentic AI project, such as Cedar/OPA policy engines enforcing agent-to-agent boundaries, capability/agent-card discovery, or default-deny agent authorization modelsExpertise in identity-aware authorization, including OAuth 2.0, JWT token inspection and claims mapping, and OIDCSkills in RBAC and ABAC design patternsBackground in either direct policy-as-code experience (Cedar, OPA) or demonstrable A2A protocol depth, including agent identity, capability/agent-card discovery, and trust boundaries between interacting agentsExperience leading enterprise security review processes, including InfoSec and ARB workflowsKnowledge of AWS AgentCore Policy and Cedar policy language (principals, actions, resources, conditions)Proficiency in English at a B2+ level Nice to have Familiarity with Cedar specifically, or AWS Cedar (open source)Practical familiarity with a policy-decision-point pattern, including evaluation of requests against declarative rules, default-deny models, and staged rollout from LOG_ONLY to ENFORCEEarly experience with AWS Verified Permissions or AgentCore PolicyCloud-native AWS exposureSkills in zero-trust architecture design We offer We gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusively EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
- chief engineer Lublin
- główny inżynier Lublin
- software engineering group manager autonomous driving Lublin
- software engineering team manager Lublin
- lead engineer Lublin
- software engineer manager Lublin
- director of engineering Lublin
- lead data engineer Lublin
- IT security engineer Lublin
- security engineer integrated risk management Lublin