Security & Test Engineer - A2A | Remote EU | Immediate Start
We are actively seeking an experienced Security & Test Engineer to join a significant enterprise AI platform initiative. This role is centered on establishing a production-grade environment for the development, deployment, and operation of AI agents at scale.
The role specifically focuses on the A2A gateway, where you will own the security, functional, and performance test suites. Your responsibilities will include validating Cedar policy enforcement and assessing the trust model for agents that operate outside the core runtime environment. This position is an excellent opportunity for individuals with a robust background in security testing who are transitioning into AI and agentic systems, rather than those with a traditional QA profile primarily focused on REST APIs.
Responsibilities
- Own security, functional, and performance test suites for the A2A gateway.
- Design and automate security tests using Python.
- Test A2A authentication, authorization, and trust mechanisms.
- Validate OAuth 2.0, JWT validation, and token scope enforcement.
- Test signed Agent Cards and agent identity mechanisms.
- Test and validate Cedar policy enforcement.
- Validate permit/deny policy behavior and policy conflicts.
- Test forbid-overrides-permit scenarios.
- Validate Cedar behavior across LOG_ONLY and ENFORCE modes.
- Identify security and trust-model gaps for non-AgentCore A2A agents.
- Conduct API security testing across cloud-native services.
- Design functional, negative, and security test scenarios.
- Perform performance and load testing using k6 and/or Locust.
- Conduct threat modeling for AI and agentic systems.
- Identify vulnerabilities related to excessive agency, tool misuse, and tool parameter exfiltration.
- Collaborate with engineering teams to ensure security controls are correctly implemented and enforced.
Required Experience
- 3+ years' experience in Security Engineering, Security QA, QA Engineering, or a closely related discipline.
- Strong hands-on experience with Cedar - MANDATORY.
- Experience testing or implementing Cedar authorization policies.
- Strong API security testing capabilities.
- Proficient in Python for security test automation.
- Experience in functional and security test design.
- Experience in performance testing cloud APIs.
- Familiarity with k6 and/or Locust.
- Understanding of OAuth 2.0, JWT validation, and token scopes.
- Experience with security testing of AI/agentic systems, beyond conventional REST APIs.
- Understanding of LLM/AI threat modeling.
- Knowledge of the OWASP Top 10 for LLM Applications.
- Understanding of risks including excessive agency and tool parameter exfiltration.
Desirable
- Experience with A2A / Agent-to-Agent communication security.
- Familiarity with multi-agent security patterns.
- AgentCore experience.
- Experience with non-AgentCore A2A agents.
- Trust model gap analysis.
- Experience designing or implementing security enforcement mechanisms.
- Experience with LangGraph or Strands Agents.
- AWS/cloud-native security experience.
Important
Cedar experience is a MUST. Candidates without genuine hands-on Cedar experience will not be considered for this position.
Apply online using the form below. Only applications matching the job profile will be considered.
Work locationPoland, Warsaw, Switzerland