Senior Security & Test Engineer - A2A
Коротко
Senior Security & Test Engineer for Enterprise Agent Development Platform. Responsibilities include A2A gateway security, functional & performance testing, and threat modeling. Requires 5+ years of experience, Python, k6, Locust, and Cedar policy testing. Offers hybrid work, remote options in Poland, and growth opportunities.
Стислий виклад підготував ШІ на основі тексту оголошення.
We are looking for a Senior Security & Test Engineer to join our team building an Enterprise Agent Development Platform, a production-grade cloud-native ecosystem that enables engineering teams to define, orchestrate, deploy and observe AI agents at scale. This role focuses on securing the A2A gateway within a platform that standardizes agent development using LangGraph and Strands Agents on AWS AgentCore Runtime, reducing agent development time from months to days while enforcing consistent security, quality and governance standards.
ResponsibilitiesOwn security, functional and performance test suites for the A2A gateway
- Test Cedar policy enforcement correctness across LOG_ONLY and ENFORCE modes
- Conduct trust model gap analysis for non-AgentCore A2A agents
- Design and execute functional and security test plans for agentic AI systems
- Validate authentication and authorization flows across agent communication channels
- Identify and mitigate security risks specific to agentic AI and LLM-based systems
- Collaborate with engineering teams to strengthen the platform's overall security posture
- Report and track defects, vulnerabilities and performance bottlenecks uncovered during testingRequirements5+ years of experience in security engineering or quality assurance
- Knowledge of the A2A trust model including OAuth 2.0 signed Agent Cards and JWT validation with token scope enforcement for agent channels
- Proficiency in Python for security test automation
- Skills in functional and security test design
- Experience in performance testing using k6 and Locust along with performance benchmarking for cloud AP
- IsExpertise in Cedar policy testing including permit/deny correctness forbid-overrides-permit logic and LOG_ONLY vs ENFORCE mode
- Background in agentic AI/LLM threat modeling covering OWASP Top 10 for LLMs excessive agency and tool parameter exfiltration
- Expertise in API security testing
- Background in security test design for AI/agent systems beyond REST AP
- IsExperience in enforcement mechanism design or implementation
- Nice to have
- Familiarity with multi-agent communication security patterns
- Background in trust model gap analysis for non-AgentCore A2A agentsWe offerWe gather like-minded people:
Top tech minds driving innovation in AI, cloud and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid by design mode and opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunitiesWe provide growth opportunities:
Career development programs
Thought leadership, mentoring, soft skills and well-being programs
Certification (Anthropic, Gemini, GCP, Azure, AWS)
English classesWe cover it all:
Stable payParticipation in the Employee Stock Purchase Plan with a 15% discount
Benefits package (health insurance, multisport, shopping vouchers)
Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
Corporate, social and well-being events
Please, note:
Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusively
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
| Опубліковано | 2026-09-06 |
| Діє до | 2026-11-30 |
| Джерело |
|
Hexjobs App
Інструменти, налаштовані під цю вакансію.
Hexjobs App
Інструменти, налаштовані під цю вакансію.