Security & Governance Engineer — MCP Protocol
Intellias
We are looking for a Security & Governance Engineer focused on securing MCP-based enterprise AI platforms and agent ecosystems. In this role, you will be responsible for designing and enforcing security controls for MCP (Model Context Protocol) servers, agent-to-tool communication, identity and access management, and governance mechanisms that enable safe and compliant operation of AI agents at scale. You will work closely with platform, AI, and cloud engineering teams to ensure that agentic systems operate within defined security boundaries while meeting enterprise compliance and governance requirements.
What project we have for you
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
Intellia’s mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.
The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.
What you will do
- Design and enforce security controls for MCP server deployments, including authentication, authorization, and trust boundary management for tool descriptors and agent interactions.
- Define and implement secure agent-to-tool communication patterns using OAuth 2.0, JWT, OIDC, SigV4, and TLS 1.3.
- Conduct security reviews and threat modeling exercises for agentic AI systems, MCP integrations, and LLM-powered workflows.
- Identify and mitigate risks related to prompt injection, excessive agency, unauthorized tool execution, sensitive data exposure, and tool parameter exfiltration.
- Establish data classification and protection mechanisms for MCP tool payloads and agent communication channels.
- Design network isolation and secure connectivity patterns using VPC, PrivateLink, private networking, and cloud-native security controls.
- Develop governance frameworks, security guardrails, and policy enforcement mechanisms for enterprise AI platforms.
- Collaborate with platform and engineering teams to ensure agents follow approved routing and access patterns rather than bypassing established security controls.
- Support IAM architecture and access management for agent-to-tool authentication and authorization workflows.
- Define security standards, operational controls, and best practices for MCP server onboarding and lifecycle management.
- Participate in incident investigation, security assessments, risk reviews, and remediation activities related to AI and MCP platforms.
- Contribute to security architecture decisions for AgentCore Gateway, Registry, and enterprise AI infrastructure components.
- Work closely with compliance, governance, and engineering stakeholders to ensure secure and auditable operation of AI-driven systems.
What you need for this
Skills:
• MCP server security model (authentication, authorization, tool descriptor trust boundaries) • OAuth 2.0 / SigV4 / JWT security for MCP server-to-agent traffic
• TLS 1.3 enforcement for MCP communication channels
• Agentic AI / LLM threat modeling (OWASP Top 10 for LLMs, excessive agency, tool parameter exfiltration)
• Data classification for MCP tool payloads
• Network isolation (VPC, PrivateLink) for MCP server infrastructure
• 4+ years application or cloud security engineering
• Hands-on security experience with MCP (Model Context Protocol) servers — authentication design, authorization enforcement, or security review of MCP server implementations
• Identity and access management (OAuth, JWT, OIDC) for agent-to-tool authentication Nice to have:
• AWS AgentCore Gateway or Registry security review experience
• AWS WAF, Security Hub, Macie
• Prior work on enterprise AI platform governance
• Enforcement mechanism design (ensuring agents route through the MCP Hub rather than calling MCP servers directly)
What it’s like to work at Intellias
At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. That’s why we offer a range of benefits that support your well-being and charge your professional growth.
We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.
We welcome and celebrate the uniqueness of every individual. Join Intellias for a career where your perspectives and contributions are vital to our shared success.
- ...We are looking for a Security Test Engineer to validate the security, reliability, and correctness of authorization and policy enforcement systems used in AI agent platforms. The role combines security testing, automated test development, API security validation, and policy...Suggested
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security & Governance Engineer — MCP Protocol. Be the first to apply!
