Security & Test Engineer (A2A)
Intellias·Publicat acum 3 săptămâni
CorporațieQA / Testare
Tehnologii și competențe
Security engineeringAPI securityPythonOAuth 2.0JWT validationAutomated testingPerformance testingK6LocustCedar policyAgentic AILLM threat modelingOWASP Top 10Trust modelsSecurity reviewsThreat modeling
Descrierea anunțului
About the Company
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications. Intellia's mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions.
About the Role
We are looking for a Security & Test Engineer to validate the security, reliability, and trustworthiness of agent-to-agent communication platforms. The role combines security testing, performance validation, policy verification, and AI threat modeling for multi-agent systems. The ideal candidate has hands-on experience in security engineering, automated testing, API security, and modern AI/agent security frameworks.
Responsibilities
Design and execute security and functional test strategies for A2A communication platforms.
Validate A2A trust models including OAuth 2.0 authentication, JWT validation, signed Agent Cards, and token scope enforcement.
Develop automated security test suites using Python.
Design and execute API security testing scenarios against agent communication channels and platform services.
Implement performance and load testing using tools such as k6 and Locust.
Design and maintain Cedar policy validation suites covering permit/deny behavior, policy precedence, forbid-overrides-permit logic, and policy mode transitions.
Validate LOG_ONLY versus ENFORCE behavior across authorization workflows.
Perform security reviews and threat modeling for agent ecosystems and AI-driven workflows.
Develop test scenarios covering prompt injection, excessive agency, tool misuse, parameter exfiltration, and other AI-specific attack vectors.
Verify authorization, policy enforcement, auditability, and trust boundaries between communicating agents.
Collaborate with platform, backend, and security teams to identify vulnerabilities and improve platform resilience.
Produce security reports, test documentation, risk assessments, and mitigation recommendations.
Qualifications
4+ years security engineering or QA
API security testing
Performance benchmarking for cloud APIs
Security test design for AI/agent systems (not just REST APIs)
Enforcement mechanism design or implementation
Required Skills
A2A trust model (OAuth 2.0 + signed Agent Cards, JWT validation, token scope enforcement for agent channels)
Python security test automation
Functional and security test design
Performance testing (k6, Locust)
Cedar policy testing (permit/deny correctness, forbid-overrides-permit, LOG_ONLY vs ENFORCE mode)
Agentic AI / LLM threat modelling (OWASP Top 10 for LLMs, excessive agency, tool parameter exfiltration)
Preferred Skills
Multi-agent communication security patterns
Trust model gap analysis for non-AgentCore A2A agents
Cât de complet e anunțul
Anunț complet
80/100
- Spune cum se lucrează (remote / hibrid / birou)
- Zilele de birou sunt clare
- Se poate deduce experiența cerută
- Nu afișează salariul
- Listează tehnologiile cerute
- Compania este identificabilă
Scorul măsoară cât de multe informații oferă anunțul, nu cât de atractiv e jobul. Un rol la birou și unul remote pornesc de la același scor.
- La birou
Rol care se lucrează de la birou.
Sursă: linkedin. DevStart nu găzduiește aplicări — te trimitem direct la anunț.