Senior Security and Test Engineer

Epam Systems — Kyrgyzstan · Posted ~6 hours ago

Senior Full-time

Skills

Security testing Functional testing Performance testing Test strategy Cloud-native platforms AWS LangGraph Cedar AI Agents

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An enterprise technology team is looking for a senior engineer to own security and testing practices for an AI-focused platform. The role involves designing test strategies, validating security controls, and improving reliability of complex cloud systems.

Highlights

Opportunity to work on advanced AI platform security, quality assurance, and governance challenges in an enterprise-scale environment.

Description

We are looking for a Senior Security & Test Engineer to take ownership of the security, functional, and performance test suites for our A2A gateway within an enterprise-grade Agent Development Platform. This production-ready, cloud-native ecosystem empowers engineering teams to define, orchestrate, deploy, and monitor AI agents at scale, standardizing agent development through LangGraph and Strands Agents on AWS AgentCore Runtime. This position centers on verifying Cedar policy enforcement accuracy and performing trust model gap analysis for non-AgentCore A2A agents, ensuring uniform security, quality, and governance standards throughout the platform. Responsibilities Own security, functional, and performance test suites for the A2A gatewayValidate Cedar policy enforcement correctness across LOG_ONLY and ENFORCE modesConduct trust model gap analysis for non-AgentCore A2A agentsDesign and execute functional and security test strategies for agentic AI systemsBuild and maintain Python-based security test automation frameworksPerform performance testing and benchmarking for cloud APIs using k6 and LocustTest permit/deny correctness and forbid-overrides-permit logic within Cedar policiesApply agentic AI and LLM threat modeling practices to identify risks such as excessive agency and tool parameter exfiltrationEvaluate A2A trust model components, including OAuth 2.0, signed Agent Cards, JWT validation, and token scope enforcement for agent channels Requirements 3+ years of experience in security engineering or QAExpertise in API security testing and performance benchmarking for cloud APIsSkills in security test design for AI/agent systems beyond traditional REST APIsBackground in enforcement mechanism design or implementationKnowledge of A2A trust model concepts, including OAuth 2.0, signed Agent Cards, JWT validation, and token scope enforcementProficiency in Python security test automation, functional test design, and performance testing tools such as k6 and LocustUnderstanding of Cedar policy testing, including permit/deny correctness and LOG_ONLY vs ENFORCE modesFamiliarity with agentic AI and LLM threat modeling frameworks, including OWASP Top 10 for LLMsExcellent command of written and spoken English (B2+ level) Nice to have Familiarity with multi-agent communication security patternsExpertise in trust model gap analysis for non-AgentCore A2A agents We offer We connect like-minded people:Delivering innovative solutions to industry leaders, making a global impactEnjoyable working environment, whether it is the vibrant office or the comfort of your own homeOpportunity to work abroad for up to two months per yearRelocation opportunities within our offices in 55+ countriesCorporate and social eventsWe invest in your growth:Leadership development, career advising, soft skills and well-being programsCertifications, including GCP, Azure and AWSUnlimited access to EPAM's internal learning databaseFree English classes with certified teachersWe cover it all:Monetary bonuses for engaging in the referral programMedical & family care packageSix trust days per year (sick leave without a medical certificate)Coverage of psychology sessions of your choiceDiscounts for fitness clubs and sports programsBenefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments. Experience the freedom of remote work from anywhere in Kyrgyzstan, whether it's the comfort of your home or our modern office in Bishkek.