Назад
Company hidden
1 день назад

Security & Test Engineer (AI Security)

Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Serbia/Ukraine/Poland +7 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security & Test Engineer with A2A Security (Python/pytest/AI): Building security and functional testing strategies for enterprise AI agent ecosystems with an accent on authentication, authorization, policy enforcement, auditability, and API security. Focus on validating agent-to-agent trust models, threat modeling prompt injection and excessive permissions, and benchmarking distributed agent communication channels.

Location: Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, or Ukraine

Company

hirify.global offers work on global projects in a supportive, flexible, and innovative technology environment.

What you will do

  • Design and execute functional and security testing strategies for AI and agent-based systems.
  • Develop automated security testing frameworks with Python and pytest.
  • Validate agent-to-agent trust models, OAuth 2.0 authentication, JWT validation, signed identities, token scopes, and policy enforcement.
  • Perform API security testing, performance benchmarking, and load testing for cloud APIs and agent communication channels using k6, Locust, or similar tools.
  • Validate audit logging and governance controls across distributed agent ecosystems.
  • Conduct threat modeling and collaborate with security, architecture, and engineering teams on vulnerability mitigation and operational readiness.

Requirements

  • 3+ years of experience in security engineering, quality assurance, or software testing.
  • Experience designing automated security testing frameworks, security test plans, test strategies, and automation solutions.
  • Experience with API security testing, cloud service performance benchmarking, and load testing.
  • Strong Python programming skills with experience in pytest.
  • Understanding of OAuth 2.0, JWT-based authentication, access control, authentication, authorization, and policy enforcement.
  • Knowledge of threat modeling, security assessment techniques, analytical troubleshooting, documentation, and agile software development.

Nice to have

  • Experience with multi-agent communication security patterns and trust model assessments.
  • Experience with Cedar policy testing tools and policy validation frameworks.
  • Experience with AWS security testing, cloud security reviews, and large-scale AI, cloud, or distributed platforms.
  • Knowledge of AI security risks, including prompt injection, excessive agency, identity spoofing, and tool parameter exposure.
  • Experience with regulatory compliance validation, governance, audit, risk management, and security monitoring.

Culture & Benefits

  • Cross-functional team of security engineers, QA specialists, AI engineers, platform developers, and architects.
  • Iterative delivery model focused on security, quality, observability, performance, and continuous improvement.
  • Vacation and state holidays according to the official calendar and laws of the employee's country.
  • Health insurance support and sick pay, including 10 days without a doctor's note.
  • IT certification cost coverage and access to courses and learning platforms.
  • Corporate events and technical and everyday workplace support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →