Senior Security & Test Engineer - A2A

Brak informacji o wynagrodzeniu
SeniorFull-time
#441145·Dodano wczoraj·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Security testingAPI Security TestingCedar Policythreat modelingPythonOAuth 2.0JWTPerformance testingA2AK6

Firma i stanowisko

EPAM Systems is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, they empower clients to become AI-Native enterprises, driving measurable value from innovation and digital investments. This role is within a team building an Enterprise Agent Development Platform, a production-grade cloud-native ecosystem focused on AI agents.

Wymagania

  • 5+ years of experience in security engineering or quality assurance
  • Knowledge of the A2A trust model including OAuth 2.0 signed Agent Cards and JWT validation with token scope enforcement for agent channels
  • Proficiency in Python for security test automation
  • Skills in functional and security test design
  • Experience in performance testing using k6 and Locust along with performance benchmarking for cloud APIs
  • Expertise in Cedar policy testing including permit/deny correctness, forbid-overrides-permit logic, and LOG_ONLY vs ENFORCE mode
  • Background in agentic AI/LLM threat modeling covering OWASP Top 10 for LLMs, excessive agency, and tool parameter exfiltration
  • Expertise in API security testing
  • Background in security test design for AI/agent systems beyond REST APIs
  • Experience in enforcement mechanism design or implementation

Nice to have:

  • Familiarity with multi-agent communication security patterns
  • Background in trust model gap analysis for non-AgentCore A2A agents

Obowiązki

  • Own security, functional and performance test suites for the A2A gateway
  • Test Cedar policy enforcement correctness across LOG_ONLY and ENFORCE modes
  • Conduct trust model gap analysis for non-AgentCore A2A agents
  • Design and execute functional and security test plans for agentic AI systems
  • Validate authentication and authorization flows across agent communication channels
  • Identify and mitigate security risks specific to agentic AI and LLM-based systems
  • Collaborate with engineering teams to strengthen the platform's overall security posture
  • Report and track defects, vulnerabilities and performance bottlenecks uncovered during testing

Benefity

  • Opportunity to work with top professionals in AI, cloud, and digital platform modernization
  • Supportive team and agile, startup-like culture
  • Hybrid work mode and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including thought leadership, mentoring, soft skills, and well-being programs
  • Certifications including Anthropic, Gemini, GCP, Azure, AWS
  • English classes
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee
  • Corporate, social and well-being events
Elastyczne godziny
Pakiet relokacyjny
Budżet konferencyjny
Dofinansowanie szkoleń
Kursy językowe
Opieka zdrowotna
Karta sportowa
Premie
Udziały pracownicze
Darmowe przekąski
Napoje w biurze
Spotkania integracyjne

Inne informacje

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności.

EPAM Systems

EPAM Systems

869 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz