Security Test Engineer (Python)
Intellias·Publicat acum 3 săptămâni
CorporațieQA / Testare
Tehnologii și competențe
PythonPytestSecurity testingPenetration testingThreat modellingAPI securityOWASP Top 10Policy enforcementTest automationAgentic AIAudit log validationAuthorization systemsCompliance testingIoTDigital engineering
Descrierea anunțului
We are looking for a Security Test Engineer to validate the security, reliability, and correctness of authorization and policy enforcement systems used in AI agent platforms. The role combines security testing, automated test development, API security validation, and policy verification. The ideal candidate has strong experience in security-focused QA, test automation with Python, and modern application security practices.
Project Overview:
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
Intellia's mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.
The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.
Requirements:
Security testing (pen testing, threat modelling)
Agentic AI threat modelling (OWASP Top 10 for LLMs': 'prompt injection as policy bypass, agent identity spoofing ')
Python test automation (pytest)
A2A policy enforcement testing
Audit log validation
Functional policy test suite ownership (permit/deny correctness, forbid-overrides-permit, parameter-level conditions, LOG_ONLY → ENFORCE mode switching)
Functional and security test design
Experience:
4+ years of quality assurance or security testing
Automated security test suite implementation
API security testing (OWASP API Top 10)
Will be a plus:
AWS security testing experience
Cedar policy test tooling
Regulatory compliance testing (GDPR, SOC 2)
Responsibilities:
Design and execute functional and security test strategies for policy-driven authorisation systems.
Develop and maintain automated security and policy validation test suites using Python and pytest.
Validate permit/deny decisions, policy precedence rules, parameter-level access controls, and policy evaluation correctness.
Test transitions between LOG_ONLY and ENFORCE policy modes and verify expected enforcement behaviour.
Perform API security testing based on OWASP API Top 10 recommendations.
Conduct security assessments, penetration testing, and threat modelling exercises for platform services and AI agent workflows.
Design and execute test scenarios covering agent identity spoofing, prompt injection, policy bypass attempts, and other agentic AI attack vectors.
Validate audit logging, traceability, and security event generation for authorisation decisions.
Verify A2A policy enforcement mechanisms across agent interactions and distributed workflows.
Collaborate with engineering and security teams to identify vulnerabilities and improve platform security posture.
Maintain security test documentation, reports, and compliance evidence where required.
Cât de complet e anunțul
Anunț complet
80/100
- Spune cum se lucrează (remote / hibrid / birou)
- Zilele de birou sunt clare
- Se poate deduce experiența cerută
- Nu afișează salariul
- Listează tehnologiile cerute
- Compania este identificabilă
Scorul măsoară cât de multe informații oferă anunțul, nu cât de atractiv e jobul. Un rol la birou și unul remote pornesc de la același scor.
- La birou
Rol care se lucrează de la birou.
Sursă: linkedin. DevStart nu găzduiește aplicări — te trimitem direct la anunț.