Security Engineer with MCP Security, AI Governance Platform

DataArt·Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, Ukraine·Удалённо, Офис·вчера

About the Position

We are looking for a Security Engineer with hands on experience securing Model Context Protocol (MCP) environments and AI enabled platforms. In this role, you will help design and implement security controls for agent to tool communication, identity and access management, and cloud based AI infrastructure. You will collaborate with engineering, platform, and governance teams to ensure secure adoption of AI technologies while supporting scalable and compliant architectures.

About the Project

The project focuses on building and securing an enterprise AI platform that enables agents, tools, and services to interact through MCP based architectures. The platform emphasizes security, governance, observability, and controlled access to enterprise resources while supporting modern AI driven workflows.

About the Team

You will work within a multidisciplinary team of security engineers, cloud engineers, AI platform specialists, architects, and product stakeholders. The team collaborates closely through design reviews, security assessments, and continuous improvement initiatives to deliver secure and reliable solutions.

Responsibilities

  • Design and implement security controls for MCP server environments and agent to tool communications
  • Define authentication and authorization mechanisms using OAuth 2.0, OIDC, JWT, and related identity standards
  • Conduct security reviews of MCP server implementations and validate trust boundaries between agents, tools, and services
  • Develop and maintain threat models for agentic AI systems and MCP based architectures
  • Assess risks related to tool access, excessive agent permissions, sensitive data exposure, and prompt related threats
  • Implement data classification controls and security requirements for MCP tool payloads
  • Support network isolation strategies using VPC, PrivateLink, and cloud native security services
  • Collaborate with engineering teams to enforce secure communication channels using TLS 1.3 and related security standards
  • Contribute to enterprise AI governance initiatives, security policies, and compliance requirements
  • Review platform architectures and recommend security improvements across AI and cloud environments

Requirements

  • 4+ years of experience in application security engineering or cloud security engineering
  • Hands on experience with MCP server security, including authentication design, authorization enforcement, or security assessments of MCP server implementations
  • Experience with identity and access management technologies, including OAuth 2.0, JWT, and OpenID Connect
  • Knowledge of MCP server security models, including authentication, authorization, and tool descriptor trust boundaries
  • Experience securing server to agent communication using OAuth 2.0, SigV4, JWT, and related security mechanisms
  • Understanding of TLS 1.3 implementation and secure communication practices
  • Experience performing threat modeling for AI systems and Large Language Model based applications
  • Knowledge of OWASP Top 10 for LLMs and risks such as excessive agency, tool parameter exposure, and data leakage
  • Experience with data classification and protection of application payloads
  • Knowledge of cloud networking concepts, including VPC and PrivateLink
  • Strong communication skills and experience collaborating with cross functional teams

Nice to Have

  • Experience conducting security reviews of AWS AgentCore Gateway or Registry environments
  • Experience with AWS WAF, AWS Security Hub, and AWS Macie
  • Previous involvement in enterprise AI platform governance initiatives
  • Experience designing enforcement mechanisms that ensure agents route through centralized MCP hubs rather than communicating directly with MCP servers
  • Knowledge of cloud security monitoring, risk management, and governance best practices
  • Experience supporting secure AI platform adoption within enterprise environments

Technologies

Model Context Protocol (MCP), OAuth 2.0, OIDC, JWT, SigV4, TLS 1.3, AWS, AWS WAF, AWS Security Hub, AWS Macie, VPC, PrivateLink, Agentic AI, Large Language Models, AI Governance Frameworks, Cloud Security Controls

Похожие вакансии

Другие вакансии DataArt