Overview
We are seeking a Senior Security & Test Engineer to own the security, functional, and performance test suites for our A2A gateway within an enterprise-grade Agent Development Platform. This production-grade, cloud-native ecosystem enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale, standardizing agent development using LangGraph and Strands Agents on AWS AgentCore Runtime. The role focuses on validating Cedar policy enforcement correctness and conducting trust model gap analysis for non-AgentCore A2A agents, ensuring consistent security, quality, and governance standards across the platform.We are seeking a Senior Security & Test Engineer to own the security, functional, and performance test suites for our A2A gateway within an enterprise-grade Agent Development Platform. This production-grade, cloud-native ecosystem enables engineering teams to define, orchestrate, deploy, and observe AI agents at scale, standardizing agent development using LangGraph and Strands Agents on AWS AgentCore Runtime. The role focuses on validating Cedar policy enforcement correctness and conducting trust model gap analysis for non-AgentCore A2A agents, ensuring consistent security, quality, and governance standards across the platform.
- Own security, functional, and performance test suites for the A2A gateway
- Validate Cedar policy enforcement correctness across LOG_ONLY and ENFORCE modes
- Conduct trust model gap analysis for non-AgentCore A2A agents
- Design and execute functional and security test strategies for agentic AI systems
- Build and maintain Python-based security test automation frameworks
- Perform performance testing and benchmarking for cloud APIs using k6 and Locust
- Test permit/deny correctness and forbid-overrides-permit logic within Cedar policies
- Apply agentic AI and LLM threat modeling practices to identify risks such as excessive agency and tool parameter exfiltration
- Evaluate A2A trust model components, including OAuth 2.0, signed Agent Cards, JWT validation, and token scope enforcement for agent channels
- 3+ years of experience in security engineering or QA
- Expertise in API security testing and performance benchmarking for cloud APIs
- Skills in security test design for AI/agent systems beyond traditional REST APIs
- Background in enforcement mechanism design or implementation
- Knowledge of A2A trust model concepts, including OAuth 2.0, signed Agent Cards, JWT validation, and token scope enforcement
- Proficiency in Python security test automation, functional test design, and performance testing tools such as k6 and Locust
- Understanding of Cedar policy testing, including permit/deny correctness and LOG_ONLY vs ENFORCE modes
- Familiarity with agentic AI and LLM threat modeling frameworks, including OWASP Top 10 for LLMs
- English proficiency at B2 level or higher
- Delivering innovative solutions to industry leaders, making a global impact
- Enjoyable working environment, whether it is the vibrant office or the comfort of your home
- Opportunity to work abroad for up to two months per year
- Relocation opportunities within our offices in 55+ countries
- Corporate and social events
- Leadership development, career advising, soft skills and well-being programs
- Certifications, including GCP, Azure and AWS
- Unlimited access to EPAM's internal learning database
- Free English classes with certified teachers
- Participation in the Employee Stock Purchase Plan
- Monetary bonuses for engaging in the referral program
- Comprehensive medical & family care package
- Four trust days per year for personal needs
- Discounts for fitness clubs
- Benefits package (hotels, restaurants, stores and services)
- Familiarity with multi-agent communication security patterns
- Expertise in trust model gap analysis for non-AgentCore A2A agents
- Security.Testing
- A2A
- API Security Testing
- Performance Testing
- Python Test Automation Frameworks
- Multi-Agent Systems Evaluation and Testing
✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.
Please clearly mention that you have heard of this job opportunity on https://ijob.am.


