JustJoin.IT Hybrydowo Senior

Senior Security Engineer – Identity and Access Management (IDAM)

ITDS

⚲ Krakow

27 720 - 33 600 PLN netto (B2B)

Wymagania

  • Identity and Access Management (IAM)
  • Zero Trust Architecture
  • Google Cloud Platform (GCP)
  • Kubernetes security
  • PKI and Cryptography
  • threat modeling
  • DevSecOps
  • Policy-as-Code (OPA)
  • Vulnerability Management
  • CISSP / Security Certifications

Opis stanowiska

Unleash the Power of Secure Identity — Shape the Future of IAM Innovation!
Kraków-based opportunity with a hybrid work model (up to 4 days remote per week).
As a Senior Security Engineer – Identity and Access Management (IDAM), you will be working for our client, a leading financial institution, spearheading the transformation of global Identity and Access Management. This role involves designing and implementing cutting-edge security controls to safeguard enterprise IDAM platforms, ensuring compliance, and supporting the evolution toward Zero Trust security principles. You will be pivotal in shaping secure digital environments that empower organizations to operate safely and efficiently at scale.

Your main responsibilities:
• Design and implement security controls across the IDAM 2.0 platform, embedding Secure by Design principles.
• Configure and maintain authentication and authorization mechanisms, including cloud security controls on GCP and Kubernetes.
• Support and operationalize Workload, Human, and Agent Identity security controls, leveraging cryptographic key management and PKI.
• Develop and maintain security standards, baselines, and hardening guides, and support vulnerability management activities.
• Conduct threat modeling, security risk assessments, and vulnerability reviews to identify and remediate security gaps.
• Collaborate with Security Operations, Incident Response teams, and third-party vendors during security events and audits.
• Support DevSecOps practices by contributing to tooling, automated security testing, and secure software delivery.

You're ideal for this role if you have:
• Minimum 5 years of experience in Information Security Engineering, with a focus on IAM, security controls, and cloud environments.
• Expertise in Zero Trust architecture, authentication, and authorization solutions.
• Proficiency with PKI, secrets management, cryptography, and security for GCP and Kubernetes.
• Experience implementing Policy-as-Code (OPA), threat modeling, vulnerability management, and security monitoring.
• Strong understanding of DevSecOps practices, secure software lifecycle, and incident response.
• Ability to produce comprehensive security documentation and operational procedures.

It is a strong plus if you have: (optional)• Certifications related to security (CISSP, CISA, etc.)
• Proven experience with service mesh security, API security, and security compliance frameworks.
Language Required for the role:
• Fluent English (spoken and written)

Eligibility to work on this role:
• Only candidates with an existing legal right to work in the European Union will be considered for this role.

#MAKEYourCareerBETTER
Interested? Apply now and include your CV (preferably in English) along with a statement confirming your consent to the processing and storage of your personal data.

🔍 Dekoder Ogłoszenia

🔴
Unleash the Power of Secure Identity — Shape the Future of IAM Innovation!
Chwytliwy slogan marketingowy, który może sugerować duży wpływ na strategię, ale faktyczny zakres decyzyjności będzie zależał od struktury firmy.
🔴
spearheading the transformation of global Identity and Access Management
Sugestia bycia liderem w procesie zmian, co może oznaczać znaczące wyzwania i potrzebę silnego wpływu na procesy, które mogą być jeszcze nieustalone.
🔴
evolution toward Zero Trust security principles
Wskazuje na ambitny cel, ale może oznaczać, że obecna infrastruktura jest daleka od tego modelu i wymaga znaczących prac transformacyjnych.
🔴
embedding Secure by Design principles
Choć brzmi profesjonalnie, może oznaczać, że procesy te nie są jeszcze w pełni dojrzałe i wymagają aktywnego wdrażania od podstaw.
🔴
Support DevSecOps prac
Może oznaczać zarówno aktywne uczestnictwo w budowaniu procesów DevSecOps, jak i jedynie wsparcie dla istniejących, potencjalnie niedojrzałych praktyk.