Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Senior Security & Test Engineer

Senior • Remote

Kraków, Pl-06, Poland

Quick Facts

  • Role: Senior Security & Test Engineer

  • Focus: Security, functional, and performance testing for the A2A gateway in an enterprise agent platform

Description

Own security, functional, and performance test suites for the A2A gateway. Validate Cedar policy enforcement across LOG_ONLY and ENFORCE modes, run trust model gap analysis, and test authentication/authorization flows across agent communication channels. Identify and mitigate agentic AI and LLM-specific security risks, and report defects, vulnerabilities, and performance bottlenecks.

Responsibilities

  • Own security, functional and performance test suites for the A2A gateway

  • Test Cedar policy enforcement correctness across LOG_ONLY and ENFORCE modes

  • Perform trust model gap analysis for non-AgentCore A2A agents

  • Design and execute functional and security test plans for agentic AI systems

  • Validate authentication and authorization flows across agent communication channels

  • Identify and mitigate security risks specific to agentic AI and LLM-based systems

  • Collaborate with engineering teams to strengthen the platform’s overall security posture

  • Report and track defects, vulnerabilities and performance bottlenecks discovered during testing

Requirements

  • 5+ years of experience in security engineering or quality assurance

  • Knowledge of the A2A trust model including OAuth 2.0 signed Agent Cards and JWT validation with token scope enforcement for agent channels

  • Proficiency in Python for security test automation

  • Skills in functional and security test design

  • Experience in performance testing using k6 and Locust, plus performance benchmarking for cloud APIs

  • Expertise in Cedar policy testing, including permit/deny correctness and forbid-overrides-permit logic with LOG_ONLY vs ENFORCE mode

  • Background in agentic AI/LLM threat modeling covering OWASP Top 10 for LLMs, including excessive agency and tool parameter exfiltration

  • Expertise in API security testing

  • Background in security test design for AI/agent systems beyond REST APIs

  • Experience in enforcement mechanism design or implementation

Benefits

  • Stable pay

  • Employee Stock Purchase Plan with a 15% discount

  • Benefits package (health insurance, multisport, shopping vouchers)

  • Referral bonuses up to $2,000

  • Career development programs, mentoring, soft skills, and well-being programs

  • Certifications (Anthropic, Gemini, GCP, Azure, AWS)

  • English classes

  • Hybrid work (remote within Poland) and opportunity to work abroad up to 60 days annually

  • Business-driven relocation opportunities

  • Corporate, social, and well-being events; offices with entertainment and relaxation zones, table tennis/football, free snacks, and coffee

Benefits listed above are available to employees only. Contractors are also possible under individually agreed B2B terms.

Similar jobs you might like