Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
The project is building a secure enterprise agent ecosystem that enables communication between AI agents, services, and applications. The platform incorporates authentication, authorization, policy enforcement, auditability, and governance controls to support trusted agent interactions and enterprise compliance requirements.
задачи
Design and execute functional and security testing strategies for AI and agent-based systems
Develop and maintain automated security testing frameworks using Python and pytest
Validate agent-to-agent trust models, including OAuth 2.0 authentication, JWT validation, signed agent identities, and token scope enforcement
Perform API security testing based on established industry security practices
Design and execute policy enforcement tests covering permit and deny logic, policy precedence, parameter-level conditions, and enforcement modes
Perform performance benchmarking and load testing for cloud-based APIs and agent communication channels using k6, Locust, or similar tools
Validate audit logging mechanisms and governance controls across distributed agent ecosystems
Conduct threat modeling exercises for AI and agent-based platforms, including assessment of prompt injection risks, excessive agent permissions, and tool parameter exposure scenarios
Collaborate with security, architecture, and engineering teams to identify vulnerabilities and recommend mitigation strategies
Create and maintain security test plans, test cases, automation frameworks, and technical documentation
Support compliance, governance, and operational readiness initiatives
Contribute to continuous improvement of testing, security validation, and quality assurance processes
требования
3+ Years of experience in security engineering, quality assurance, or software testing
Experience designing and implementing automated security testing frameworks
Experience with API security testing and secure API validation practices
Experience performing performance benchmarking and load testing for cloud-based services
Experience designing security testing approaches for AI systems, agent platforms, or distributed application architectures
Experience validating authentication, authorization, and policy enforcement mechanisms
Strong Python programming skills and experience with pytest
Understanding of OAuth 2.0, JWT-based authentication, and access control concepts
Knowledge of threat modeling methodologies and security assessment techniques
Experience creating security test plans, test strategies, and automation solutions
Strong analytical, troubleshooting, and documentation skills
Experience working within agile software development environments
Будет плюсом: experience with multi-agent communication security patterns, trust model assessments and gap analysis for agent ecosystems, Cedar policy testing tools and policy validation frameworks, AWS security testing and cloud security reviews, AI security risks including prompt injection, excessive agency, identity spoofing, and tool parameter exposure, regulatory compliance validation and governance frameworks, enterprise audit, risk management and security monitoring practices, and large-scale AI, cloud, or distributed platform environments