L'annuaire des offres d'emploi en Suisse

Security Test Engineer

Entreprise
Red Commerce Schweiz GmbH
Lieu
Poland, Warsaw
Date de publication
25.08.2026
Référence
97112

Description

Security & Test Engineer - A2A | Remote EU | Immediate Start We are looking for an experienced Security & Test Engineer to join a major enterprise AI platform initiative, focused on building a production-grade environment for developing, deploying and operating AI agents at scale. The role will focus specifically on the A2A gateway, owning security, functional and performance test suites, validating Cedar policy enforcement, and assessing the trust model for agents operating outside the core runtime environment. This is an excellent opportunity for someone with a strong security testing background who has moved into AI/agentic systems, rather than a traditional QA profile focused purely on REST APIs. Responsibilities Own security, functional and performance test suites for the A2A gateway. Design and automate security tests using Python. Test A2A authentication, authorisation and trust mechanisms. Validate OAuth 2.0, JWT validation and token scope enforcement. Test signed Agent Cards and agent identity mechanisms. Test and validate Cedar policy enforcement. Validate permit/deny policy behaviour and policy conflicts. Test forbid-overrides-permit scenarios. Validate Cedar behaviour across LOG_ONLY and ENFORCE modes. Identify security and trust-model gaps for non-AgentCore A2A agents. Conduct API security testing across cloud-native services. Design functional, negative and security test scenarios. Perform performance and load testing using k6 and/or Locust. Conduct threat modelling for AI and agentic systems. Identify vulnerabilities relating to excessive agency, tool misuse and tool parameter exfiltration. Work with engineering teams to ensure security controls are correctly implemented and enforced. Required Experience 3+ years' experience in Security Engineering, Security QA, QA Engineering or a closely related discipline. Strong hands-on experience with Cedar - MANDATORY. Experience testing or implementing Cedar authorisation policies. Strong API security testing experience. Strong Python skills for security test automation. Experience with functional and security test design. Experience performance testing cloud APIs. Experience with k6 and/or Locust. Understanding of OAuth 2.0, JWT validation and token scopes. Experience with security testing of AI/agentic systems, not just conventional REST APIs. Understanding of LLM/AI threat modelling. Knowledge of the OWASP Top 10 for LLM Applications. Understanding of risks including excessive agency and tool parameter exfiltration. Desirable Experience with A2A / Agent-to-Agent communication security. Multi-agent security patterns. AgentCore experience. Experience with non-AgentCore A2A agents. Trust model gap analysis. Experience designing or implementing security enforcement mechanisms. Experience with LangGraph or Strands Agents. AWS/cloud-native security experience. Important Cedar experience is a MUST. Candidates without genuine hands-on Cedar experience should not be considered for this position.

Déposer ma candidature

Choisir
Obligatoire. PDF ou document texte, 3 MB maximum.