Lead Security / Policy Engineer @EPAM
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3d ago

[Hiring] Lead Security / Policy Engineer @EPAM

3d ago - EPAM is hiring a remote Lead Security / Policy Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Poland

Role Description

We are seeking a Lead Security / Policy Engineer to architect the policy engine, Cedar policy schema, and InfoSec review processes for an enterprise-grade Agent Development Platform. This production-grade, cloud-native ecosystem enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale, standardizing agent development across the organization using LangGraph and Strands Agents on AWS AgentCore Runtime. The role centers on authorization at the agent boundary, ensuring agents securely advertise and invoke each other's capabilities while enforcing consistent security, quality, and governance standards.

  • Lead the architecture of the policy engine and Cedar policy schema design across the platform
  • Define authorization models that govern agent-to-agent capability advertisement and invocation
  • Drive enterprise InfoSec review processes and ensure alignment with ARB requirements
  • Establish default-deny authorization patterns for agent interactions
  • Integrate identity-aware authorization using OAuth 2.0, JWT, and MS Entra
  • Build and maintain policy-as-code patterns to standardize governance across agent development teams
  • Oversee audit logging mechanisms for policy decisions and enforcement outcomes
  • Guide staged rollout strategies for policy enforcement, from monitoring to full enforcement
  • Collaborate with engineering teams to reason about trust boundaries between interacting agents

Qualifications

  • 5+ years of experience in cloud security or identity engineering
  • Hands-on experience with authorization or policy-as-code for AI agents in a production agentic AI project, such as Cedar/OPA policy engines enforcing agent-to-agent boundaries, capability/agent-card discovery, or default-deny agent authorization models
  • Expertise in identity-aware authorization, including OAuth 2.0, JWT token inspection and claims mapping, and OIDC
  • Skills in RBAC and ABAC design patterns
  • Background in either direct policy-as-code experience (Cedar, OPA) or demonstrable A2A protocol depth, including agent identity, capability/agent-card discovery, and trust boundaries between interacting agents
  • Experience leading enterprise security review processes, including InfoSec and ARB workflows
  • Knowledge of AWS AgentCore Policy and Cedar policy language (principals, actions, resources, conditions)
  • Proficiency in English at a B2+ level

Requirements

  • Familiarity with Cedar specifically, or AWS Cedar (open source)
  • Practical familiarity with a policy-decision-point pattern, including evaluation of requests against declarative rules, default-deny models, and staged rollout from LOG_ONLY to ENFORCE
  • Early experience with AWS Verified Permissions or AgentCore Policy
  • Cloud-native AWS exposure
  • Skills in zero-trust architecture design
Before You Apply
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead Security / Policy Engineer @EPAM
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 128,287+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later