DataArt
DataArt
New

QA Engineer with Security Testing

13k - 16k PLN/ mies.B2B
11k - 13k PLN/ mies.UoP
SeniorFull-time·B2B·Umowa o pracę
#440440·Dodano 2 dni temu·1
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Security Engineeringsecurity testing frameworksAPI Security TestingAPI validation practicesOAuth 2.0PythonpytestOWASP API

Firma i stanowisko

The project focuses on building and securing an enterprise AI platform that enables agent interactions, policy based authorization, workflow governance, and auditability. The team comprises QA engineers, security specialists, AI engineers, platform developers, and architects working collaboratively. The company is DataArt, with multiple office locations in Poland including Wrocław, Warszawa, Lublin, Kraków, and Łódź.

Wymagania

  • 3+ years of experience in quality assurance, security testing, or software testing
  • Experience implementing automated security testing frameworks
  • Experience with API security testing and OWASP API security principles
  • Experience designing functional and security test cases and test strategies
  • Strong Python programming skills with experience using pytest
  • Knowledge of threat modeling methodologies and security testing practices
  • Experience validating authentication, authorization, and policy enforcement controls
  • Experience working with enterprise applications and distributed systems
  • Strong analytical, troubleshooting, and documentation skills
  • Experience collaborating within agile software development environments
  • Experience testing AI applications, agent based platforms, or machine learning systems

Nice to have:

  • Experience with AWS security testing and cloud security validation
  • Experience with Cedar policy testing tools and policy validation frameworks
  • Experience with regulatory compliance testing, including GDPR and SOC 2 requirements
  • Knowledge of audit, governance, and risk management frameworks
  • Experience validating agent to agent communication and authorization controls
  • Understanding of AI security risks, including prompt injection attacks and agent identity spoofing
  • Experience with CloudWatch and security monitoring solutions
  • Experience with multi agent communication security patterns
  • Experience performing trust model assessments and gap analysis for agent ecosystems
  • Experience with regulatory compliance validation and governance frameworks
  • Understanding of enterprise audit, risk management, and security monitoring practices
  • Experience working with large scale AI, cloud, or distributed platform environments

Obowiązki

  • Design and execute functional and security testing strategies for AI platforms and agent based applications
  • Develop and maintain automated security testing frameworks using Python and pytest
  • Perform API security testing aligned with OWASP API security best practices
  • Validate authorization and policy enforcement mechanisms across agent workflows
  • Design and execute tests covering permit and deny logic, policy precedence, parameter level conditions, and enforcement controls
  • Verify audit logging capabilities and ensure compliance with governance requirements
  • Perform threat modeling and security assessments for AI and agent based systems
  • Validate protections against AI specific attack scenarios, including prompt injection and identity spoofing
  • Develop and maintain test documentation, test cases, and quality assurance standards
  • Collaborate with engineering, architecture, and security teams to identify and resolve vulnerabilities
  • Support compliance validation and governance testing activities
  • Contribute to continuous improvement of quality and security testing processes

Benefity

  • Up to 26 business vacation days per year
  • 10 fully paid illness/special days off per year without medical papers for all contract types
  • Health and life insurance (Luxmed)
  • MyBenefit platform with Multisport option
  • Internal psychological support service
  • English language classes from the first working day
  • Access to external learning platforms including O’Reilly, LinkedIn Learning, and Udemy
  • Flexible workplace options: office, home, or hybrid
  • Tech Skills Mentoring Program
  • Opportunities to develop as a public speaker, mentor, or technical interviewer
  • Fully paid idle time (bench) when not involved in a project
  • Certification reimbursement (e.g., AWS, GCP, Microsoft)
Elastyczne godziny
Płatny urlop
Opieka zdrowotna
Karta sportowa
Kursy językowe
Dofinansowanie szkoleń
Szkolenia wewnętrzne

Inne informacje

Informujemy, że administratorem danych jest DataArt Poland Sp z o o z siedzibą w Lublinie, Ul. Zana 39 a, 20-601 Lublin (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.

DataArt

DataArt

26 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz