Security IAM Engineer

Incredevo — Poland · Posted ~3 hours ago

Senior Contract Remote 200-220 PLN/h netto + VAT

Skills

Active Directory LDAP IAM Keycloak CloudStack Kubernetes HashiCorp Vault security engineering Vault

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A remote security engineering position responsible for designing and operating identity, access, and infrastructure security solutions. The role involves cloud environments, authentication systems, secrets management, and security monitoring.

Highlights

Remote security engineering role focused on identity management, cloud security, infrastructure protection, and advanced access control solutions.

Description

Security IAM Engineer (CloudStack & Active Directory) Remote 200-220 zł/h netto + VAT on B2B Contract Responsibilities Map Active Directory OUs and Groups directly to Apache CloudStack Domains and Accounts to enforce strict multi-tenant segregation of duties.Operate Keycloak as the central IdP broker, federating AD/LDAP to provide OIDC/SAML authentication across CloudStack, Kubernetes (RKE2), Vault, and Grafana.Operate HashiCorp Vault for secrets, PKI, KMIP, and External Secrets Operator, mirroring the CloudStack hierarchy (Domain > Account > Project) within Vault namespaces.Run Privileged Access Management using Teleport or Boundary with just-in-time access and session recording.Operate runtime and vulnerability security tooling including Falco, Trivy, Cosign/Harbor image signing, OpenSCAP, and Wazuh.Operate SIEM integration, centrally aggregating audit logs from CloudStack, Kubernetes, Vault, and firewalls.Requirements Deep expertise in enterprise Active Directory / LDAP integration and identity flows.Strong administrative experience with Apache CloudStack, particularly multi-tenant Domain/Account architectures.Experience with identity brokering and federation using Keycloak or a comparable OIDC/SAML broker.Experience with secrets management, cryptography, and PKI, preferably HashiCorp Vault.Experience with Privileged Access Management, such as Teleport, Boundary, or comparable.Experience with container and infrastructure security, including Falco, Trivy, image signing, and SIEM.Working knowledge of Kubernetes (RKE2) OIDC authentication and native RBAC mapping.Understanding of Zero Trust networking, including mTLS and TLS 1.2+, and storage encryption such as NetApp NVE/LUKS.Working knowledge of NIS2, DORA, and ISO 27001 control frameworks.