Security & Test Engineer with A2A Security
Tech Stack / Keywords
Firma i stanowisko
The project focuses on building a secure enterprise agent ecosystem that enables communication between AI agents, services, and applications. The platform incorporates authentication, authorization, policy enforcement, auditability, and governance controls to support trusted agent interactions and enterprise compliance requirements.
The team consists of 10-20 people and includes security engineers, QA specialists, AI engineers, platform developers, and architects working in an iterative delivery model focused on security, quality, observability, performance, and continuous improvement.
Wymagania
- 3+ years of experience in security engineering, quality assurance, or software testing.
- Experience designing and implementing automated security testing frameworks.
- Experience with API security testing and secure API validation practices.
- Experience performing performance benchmarking and load testing for cloud based services.
- Experience designing security testing approaches for AI systems, agent platforms, or distributed application architectures.
- Experience validating authentication, authorization, and policy enforcement mechanisms.
- Strong Python programming skills and experience with pytest.
- Understanding of OAuth 2.0, JWT based authentication, and access control concepts.
- Knowledge of threat modeling methodologies and security assessment techniques.
- Experience creating security test plans, test strategies, and automation solutions.
- Strong analytical, troubleshooting, and documentation skills.
- Experience working within agile software development environments.
Obowiązki
- Design and execute functional and security testing strategies for AI and agent based systems.
- Develop and maintain automated security testing frameworks using Python and pytest.
- Validate agent to agent trust models, including OAuth 2.0 authentication, JWT validation, signed agent identities, and token scope enforcement.
- Perform API security testing based on established industry security practices.
- Design and execute policy enforcement tests covering permit and deny logic, policy precedence, parameter level conditions, and enforcement modes.
- Perform performance benchmarking and load testing for cloud based APIs and agent communication channels using k6, Locust, or similar tools.
- Validate audit logging mechanisms and governance controls across distributed agent ecosystems.
- Conduct threat modeling exercises for AI and agent based platforms, including assessment of prompt injection risks, excessive agent permissions, and tool parameter exposure scenarios.
- Collaborate with security, architecture, and engineering teams to identify vulnerabilities and recommend mitigation strategies.
- Create and maintain security test plans, test cases, automation frameworks, and technical documentation.
- Support compliance, governance, and operational readiness initiatives.
- Contribute to continuous improvement of testing, security validation, and quality assurance processes.
Benefity
- Vacation days: Up to 26 business days per year.
- 10 illness/special days off per year (fully paid, no medical papers needed) for all contract types.
- Health and life insurance (Luxmed).
- MyBenefit platform with Multisport option.
- Internal psychological support service.
- English language classes from the first working day.
- Access to external learning platforms: O’Reilly, LinkedIn Learning, Udemy, and a wide catalog of diverse internal training.
- Flexible workplace: work from the office, from home, or choose a hybrid option.
- Tech Skills Mentoring Program.
- Opportunities to develop as a public speaker, mentor, or technical interviewer.
- Fully paid idle (bench) when not involved in a project.
- Certification reimbursement (AWS, GCP, Microsoft, etc.).
Inne informacje
Informujemy, że administratorem danych jest DataArt Poland Sp z o o z siedzibą w Lublinie, Ul. Zana 39 a, 20-601 Lublin (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
DataArt
26 aktywnych ofert