The Senior PBAC Engineer helps architect, deploy and operate a secure application infrastructure that aligns with business needs. The position is responsible for developing security solutions at scale and with resiliency to support business initiatives. In this role, the Senior IAM Engineer will focus on pBAC / PBAC (Policy-Based Access Control) capabilities, including centralized policy decisioning, distributed policy enforcement integration, attribute/context aggregation, and auditability to meet security and compliance expectations.
Req# 1025895901
Responsibilities
-
Be self-driven with minimal daily oversight required
-
Design and build security solutions
-
Design and implement security architectures and strategies to safeguard information system resources and assets
-
Ensure integration of technology that upholds the Information Security policies and standards, as well as meets firm business objectives
-
Mentor fellow team members and other associates in security best practices
-
Maintain awareness of security technology direction, trends, and related issues
-
Develop long-term strategy for supported security systems
-
Design and implement pBAC / PBAC platform components, including a central Policy Decision Point (PDP) with high availability, performance, and scale
-
Enable distributed Policy Enforcement Points (PEPs) by integration of enforcement with API gateways, SSO platforms, and target applications as needed
-
Coordinate attribute aggregation across identity, risk, device, transaction, location, and other enterprise data sources required for policy decisions
-
Implement audit & compliance pipelines by streaming PBAC decision logs to SIEM/compliance dashboards and support of reporting needs
-
Support delegated administration workflows and governance models for policy control across business units, IT, risk, and compliance stakeholders
Requirements
-
7+ years of experience with pBAC / PBAC implementations, including platform onboarding, policy lifecycle management, and integration patterns for policy decisioning and enforcement (PDP/PEP model)
-
Experience with implementation of PBAC across pilot applications and scaling to broader adoption, including policy development and enforcement integration into applications and/or gateways
-
Proficiency in JavaScript, Java or Python
-
General knowledge of Active Directory (AD) or other LDAP Directory Services, Intrusion Detection, Security Policies / GPOs, Operating System (OS) hardening, Single Sign-on (SSO), Federation (SAML and/or OIDC), Multi-Factor Authentication (MFA), Certificates/Public Key Infrastructure (PKI), Identity Management concepts, Cloud Technology and device authentication a plus
EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our clients, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
Engineer the Future with a Career at EPAM
EPAM Canada welcomes and encourages applications from candidates with disabilities. Please contact WFA Human Resource CA [email protected] if you have questions in this regard, or if you require an accommodation to complete the application process. Click here to review EPAM’s Accessibility for Ontarians with Disabilities Accessibility Policies and Multi-Year Access.
An artificial intelligence system is software that is developed with one or more techniques that can, for a given set of human-defined objectives, using algorithmic information processing, generate outputs such as content, predictions, recommendations, or decisions with varying levels of autonomy (“AI”). Tasks that humans have traditionally done by thinking and reasoning are increasingly being done by, or with the help of, AI to help create efficiencies.EPAM may use AI during the recruitment process, in connection with collecting or processing your personal data. Some (non-exhaustive) examples of tasks that EPAM may use AI for include conducting initial screening, creating transcripts of interviews, and assessing applications/CVs against defined job description criteria to make suggestions to the individuals evaluating your candidacy.Your personal data and the results of any processing are not shared with AI applications outside of EPAM infrastructure. While EPAM may use AI to help create efficiencies during the recruitment process, EPAM does not use AI to make hiring decisions, which is done by EPAM Talent Acquisition and management.