Security Engineer with Cedar Policy
Offer summary

(Summary generated by AI based on the full job description)

The project delivers a centralized authorization framework for AI services and cloud apps focusing on policy enforcement, auditability and governance. The stack includes Cedar, Open Policy Agent, OAuth 2.0 / OIDC / JWT and integrations with Microsoft Entra ID, Okta, Amazon Cognito. Responsibilities cover authoring and validating ABAC/RBAC policies, claims mapping, supporting AWS AgentCore (LOG_ONLY/ENFORCE), developing Python tooling for validation and automation, and collaborating with security and platform teams on access control and audit traceability.

newquick apply

Security Engineer with Cedar Policy

Company: DataArt Poland sp. z o.o.

from: 17 September 2026
to: 17 October 2026
15 000 - 20 200net (+ VAT)/ mth.B2B contract (full-time)
12 000 - 16 500gross/ mth.contract of employment
Offer parameters
level:mid
working mode:remote • hybrid • full office
location:Warszawa, Masovian
Warszawa, Masovian

Requirements

Expected technologies

C#
Python
OpenAI API

Optional technologies

LangGraph
AWS
Microsoft Azure
OpenAI API

Operating system

Windows
Linux

Our requirements

  • 3+ years of experience in security engineering, backend engineering, or a related field
  • Hands on experience integrating enterprise identity providers, including Microsoft Entra ID, Okta, or Amazon Cognito
  • Experience defining and managing policies within an ABAC or RBAC authorization framework
  • Hands on experience with Open Policy Agent, Cedar, or similar policy based authorization technologies
  • Knowledge of OAuth 2.0, JWT, OpenID Connect, and modern identity architectures
  • Experience working with claims mapping and token based authorization models
  • Understanding of secure authorization design principles and policy lifecycle management
  • Experience with Python development for automation, validation, or backend services
  • Strong analytical and problem solving skills
  • Good written and verbal communication skills

Optional

  • Experience with LangGraph tool invocation patterns
  • Experience integrating with AWS AgentCore Gateway
  • Knowledge of enterprise AI platform architecture and governance principles
  • Experience implementing policy as code methodologies
  • Familiarity with cloud native security services and authorization platforms
  • Exposure to audit logging and compliance reporting requirements

Your responsibilities

  • Develop and maintain authorization policies using the Cedar policy language
  • Author, test, and validate policy definitions for enterprise applications and AI services
  • Implement and support access control models using attribute based and role based authorization approaches
  • Configure and maintain integrations with identity providers such as Microsoft Entra ID, Okta, and Amazon Cognito
  • Map identity claims and token attributes to authorization decisions and policy rules
  • Support the implementation of AWS AgentCore Policy in LOG_ONLY and ENFORCE modes
  • Develop Python based tooling for policy validation, testing, and automation
  • Design and implement parameter level access control patterns for secure tool and service interactions
  • Collaborate with security, platform, and engineering teams to review authorization requirements and implement policy controls
  • Contribute to audit logging and authorization decision traceability practices
  • Support security reviews and help maintain authorization governance standards

About the project

The project focuses on delivering a centralized authorization framework for enterprise AI services and cloud applications. The platform provides secure policy enforcement, identity integration, auditability, and governance capabilities to support scalable and compliant access management across distributed systems.

This is how we organize our work

This is how we work

you have influence on the technological solutions appliedyou have influence on the productyou develop the code "from scratch"you focus on product developmentagile

Team members

10-20 people:backend developertechnical leaderarchitectdevOpsproduct owner

This is how we work on a project

  • DevOps
  • documentation

Development opportunities we offer

  • substantive support from technological leaders
  • time for development of your ideas

DataArt Poland sp. z o.o.

Our client is a UK financial services group operating in a highly regulated environment, currently rebuilding its data and analytics capability as part of a wider platform modernisation programme.
Security Engineer with Cedar Policy
12k–16.5k zł / mth. (CoE), 15k–20.2k zł / mth. (B2B)
I apply to:
DataArt Poland sp. z o.o.
Warszawa, Masovian

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer