Intellias
Security & Test Engineer (A2A)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security & Test Engineer
We are looking for a Security & Test Engineer to validate the security, reliability, and trustworthiness of agent-to-agent communication platforms. The role combines security testing, performance validation, policy verification, and AI threat modeling for multi-agent systems. The ideal candidate has hands-on experience in security engineering, automated testing, API security, and modern AI/agent security frameworks.
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
What we offer you in the UK
- AXA private medical insurance
- Life insurance
- Aviva pension scheme: 5% employee + 3% employer contributions
- LinkedIn Learning
- Internal educational activities and blog development program
- Employee recognition with Kudos
- Welcome kits and corporate gifts for special occasions
- Referral programs with monetary bonuses
Requirements:
- 4+ years security engineering or QA
- A2A trust model (OAuth 2.0 + signed Agent Cards, JWT validation, token scope enforcement for agent channels)
- Python security test automation
- Functional and security test design
- Performance testing (k6, Locust)
- Cedar policy testing (permit/deny correctness, forbid-overrides-permit, LOG_ONLY vs ENFORCE mode)
- API security testing
- Performance benchmarking for cloud APIs
- Agentic AI / LLM threat modelling (OWASP Top 10 for LLMs, excessive agency, tool parameter exfiltration)
- Security test design for AI/agent systems (not just REST APIs)
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Will be a plus:
- Multi-agent communication security patterns
- Trust model gap analysis for non-AgentCore A2A agents
Responsibilities:
- Design and execute security and functional test strategies for A2A communication platforms.
- Validate A2A trust models including OAuth 2.0 authentication, JWT validation, signed Agent Cards, and token scope enforcement.
- Develop automated security test suites using Python.
- Design and execute API security testing scenarios against agent communication channels and platform services.
- Implement performance and load testing using tools such as k6 and Locust.
- Design and maintain Cedar policy validation suites covering permit/deny behavior, policy precedence, forbid-overrides-permit logic, and policy mode transitions.
- Validate LOG_ONLY versus ENFORCE behavior across authorization workflows.
- Perform security reviews and threat modeling for agent ecosystems and AI-driven workflows.
- Develop test scenarios covering prompt injection, excessive agency, tool misuse, parameter exfiltration, and other AI-specific attack vectors.
- Verify authorization, policy enforcement, auditability, and trust boundaries between communicating agents.
- Collaborate with platform, backend, and security teams to identify vulnerabilities and improve platform resilience.
- Produce security reports, test documentation, risk assessments, and mitigation recommendations.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
At Intellias, where technology takes center stage, people always come before processes. We're dedicated to cultivating a tech-savvy environment that empowers individuals to unlock their true potential and achieve extraordinary results. Our customized benefits not only prioritize your well-being but also charge your professional growth, making this opportunity an ideal match for tech enthusiasts like you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location