Security & Test Engineer with A2A Security

DataArt·Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, Ukraine·Удалённо, Офис·сегодня

About the Position

We are looking for a Security & Test Engineer to support the quality, security, and governance of enterprise AI and agent based systems. In this role, you will design and execute security and functional testing strategies, validate agent to agent trust models, assess policy enforcement mechanisms, and help ensure that AI platforms operate securely, reliably, and in accordance with enterprise standards.

About the Project

The project focuses on building a secure enterprise agent ecosystem that enables communication between AI agents, services, and applications. The platform incorporates authentication, authorization, policy enforcement, auditability, and governance controls to support trusted agent interactions and enterprise compliance requirements.

About the Team

You will work within a cross functional team of security engineers, QA specialists, AI engineers, platform developers, and architects. The team follows an iterative delivery model with a strong focus on security, quality, observability, performance, and continuous improvement.

Responsibilities

  • Design and execute functional and security testing strategies for AI and agent based systems.
  • Develop and maintain automated security testing frameworks using Python and pytest.
  • Validate agent to agent trust models, including OAuth 2.0 authentication, JWT validation, signed agent identities, and token scope enforcement.
  • Perform API security testing based on established industry security practices.
  • Design and execute policy enforcement tests covering permit and deny logic, policy precedence, parameter level conditions, and enforcement modes.
  • Perform performance benchmarking and load testing for cloud based APIs and agent communication channels using k6, Locust, or similar tools.
  • Validate audit logging mechanisms and governance controls across distributed agent ecosystems.
  • Conduct threat modeling exercises for AI and agent based platforms, including assessment of prompt injection risks, excessive agent permissions, and tool parameter exposure scenarios.
  • Collaborate with security, architecture, and engineering teams to identify vulnerabilities and recommend mitigation strategies.
  • Create and maintain security test plans, test cases, automation frameworks, and technical documentation.
  • Support compliance, governance, and operational readiness initiatives.
  • Contribute to continuous improvement of testing, security validation, and quality assurance processes.

Requirements

  • 3+ years of experience in security engineering, quality assurance, or software testing.
  • Experience designing and implementing automated security testing frameworks.
  • Experience with API security testing and secure API validation practices.
  • Experience performing performance benchmarking and load testing for cloud based services.
  • Experience designing security testing approaches for AI systems, agent platforms, or distributed application architectures.
  • Experience validating authentication, authorization, and policy enforcement mechanisms.
  • Strong Python programming skills and experience with pytest.
  • Understanding of OAuth 2.0, JWT based authentication, and access control concepts.
  • Knowledge of threat modeling methodologies and security assessment techniques.
  • Experience creating security test plans, test strategies, and automation solutions.
  • Strong analytical, troubleshooting, and documentation skills.
  • Experience working within agile software development environments.

Nice to Have

  • Experience with multi agent communication security patterns.
  • Experience performing trust model assessments and gap analysis for agent ecosystems.
  • Experience with Cedar policy testing tools and policy validation frameworks.
  • Experience with AWS security testing and cloud security reviews.
  • Knowledge of AI security risks, including prompt injection, excessive agency, identity spoofing, and tool parameter exposure.
  • Experience with regulatory compliance validation and governance frameworks.
  • Understanding of enterprise audit, risk management, and security monitoring practices.
  • Experience working with large scale AI, cloud, or distributed platform environments.

Technologies

Python, pytest, OAuth 2.0, JWT, Cedar, k6, Locust, AWS, REST APIs, Agent to Agent Communication Frameworks

Похожие вакансии

Другие вакансии DataArt