Назад
Company hidden
1 день назад

Security Engineer with MCP Security, AI Governance Platform (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Serbia/Ukraine/Poland +7 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer with MCP Security, AI Governance Platform (AI) (MCP, cloud security, AI governance): Designing and implementing security controls for MCP environments and enterprise AI infrastructure with an accent on identity and access management, agent-to-tool communication, and cloud security. Focus on threat modeling agentic AI systems, validating trust boundaries, protecting sensitive data, and enforcing secure architectures across AWS environments.

Location: Armenia, Bulgaria, Cyprus, Georgia, Kazakhstan, Latvia, Poland, Romania, Serbia, or Ukraine

Company

hirify.global delivers technology services and works on global software and AI projects.

What you will do

  • Design and implement security controls for MCP servers and agent-to-tool communications.
  • Define authentication and authorization mechanisms using OAuth 2.0, OIDC, JWT, and related identity standards.
  • Conduct security reviews, validate trust boundaries, and develop threat models for agentic AI systems.
  • Assess risks involving excessive agent permissions, tool access, prompt-related threats, sensitive data exposure, and payload classification.
  • Support network isolation using VPC, PrivateLink, and cloud-native security services.
  • Contribute to AI governance, security policies, compliance requirements, and architecture improvements.

Requirements

  • 4+ years of experience in application security or cloud security engineering.
  • Hands-on experience securing MCP server environments, including authentication, authorization, or security assessments.
  • Experience with OAuth 2.0, JWT, OpenID Connect, SigV4, and TLS 1.3.
  • Experience with threat modeling for AI systems and large language model applications.
  • Knowledge of OWASP Top 10 for LLMs, excessive agency, tool parameter exposure, and data leakage risks.
  • Knowledge of cloud networking concepts including VPC and PrivateLink, plus strong cross-functional communication skills.

Nice to have

  • Experience reviewing AWS AgentCore Gateway or Registry environments.
  • Experience with AWS WAF, AWS Security Hub, and AWS Macie.
  • Experience with enterprise AI governance, cloud security monitoring, risk management, or secure AI platform adoption.
  • Experience enforcing agent routing through centralized MCP hubs.

Culture & Benefits

  • Vacation and state holidays according to the laws and official calendar of the country of employment.
  • Health insurance for employees and their loved ones.
  • Ten sick days without a doctor's note, followed by leave according to local law.
  • Corporate events, colleague meet-ups, and workplace support services.
  • IT certification cost coverage and access to courses and learning platforms.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →