> Markdown version of [/jobs/ext/1801607-senior-security-software-engineer](https://www.wearedevelopers.com/jobs/ext/1801607-senior-security-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Software Engineer - **Company:** EPAM Systems, Inc. - **Location:** Newtown, PA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Python (Programming Language), Role-Based Access Control, Security Software, Okta - **Published:** July 31, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/p8u82i8h3h ## About the Role * 3+ years of experience in security engineering or backend engineering * Expertise in Cedar policy language including authoring and testing * Hands-on experience with Open Policy Agent (OPA) * Knowledge of AWS AgentCore Policy LOG_ONLY and ENFORCE modes * Proficiency in Python for policy validation tooling * Familiarity with MS Entra claims mapping and parameter-level access control patterns * Skills in identity provider integration with Entra Okta and Cognito * Understanding of policy definition in any ABAC or RBAC system Nice to have * Familiarity with LangGraph tool invocation patterns * Knowledge of AWS AgentCore Gateway integration ## Description * Implement the baseline Cedar policy library and policy authoring standard for the platform * Author and test Cedar policies governing agent access control * Configure AWS AgentCore Policy LOG_ONLY and ENFORCE modes for staged policy rollout * Build Python-based tooling to validate policy definitions * Map MS Entra claims to platform policy attributes * Design parameter-level access control patterns for agent tooling * Establish governance standards for policy authoring across engineering teams * Collaborate with platform and security teams to enforce consistent access control practices ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)