Summary
✨ AI‑Generated
A remote security engineering position responsible for designing and operating identity, access, and infrastructure security solutions. The role involves cloud environments, authentication systems, secrets management, and security monitoring.
Highlights
Remote security engineering role focused on identity management, cloud security, infrastructure protection, and advanced access control solutions.
Description
Security IAM Engineer (CloudStack & Active Directory)
Remote
200-220 zł/h netto + VAT on B2B Contract
Responsibilities
Map Active Directory OUs and Groups directly to Apache CloudStack Domains and Accounts to enforce strict multi-tenant segregation of duties.Operate Keycloak as the central IdP broker, federating AD/LDAP to provide OIDC/SAML authentication across CloudStack, Kubernetes (RKE2), Vault, and Grafana.Operate HashiCorp Vault for secrets, PKI, KMIP, and External Secrets Operator, mirroring the CloudStack hierarchy (Domain > Account > Project) within Vault namespaces.Run Privileged Access Management using Teleport or Boundary with just-in-time access and session recording.Operate runtime and vulnerability security tooling including Falco, Trivy, Cosign/Harbor image signing, OpenSCAP, and Wazuh.Operate SIEM integration, centrally aggregating audit logs from CloudStack, Kubernetes, Vault, and firewalls.Requirements
Deep expertise in enterprise Active Directory / LDAP integration and identity flows.Strong administrative experience with Apache CloudStack, particularly multi-tenant Domain/Account architectures.Experience with identity brokering and federation using Keycloak or a comparable OIDC/SAML broker.Experience with secrets management, cryptography, and PKI, preferably HashiCorp Vault.Experience with Privileged Access Management, such as Teleport, Boundary, or comparable.Experience with container and infrastructure security, including Falco, Trivy, image signing, and SIEM.Working knowledge of Kubernetes (RKE2) OIDC authentication and native RBAC mapping.Understanding of Zero Trust networking, including mTLS and TLS 1.2+, and storage encryption such as NetApp NVE/LUKS.Working knowledge of NIS2, DORA, and ISO 27001 control frameworks.