نحن نبحث عن مهندس أمن وحوكمة يركز على حماية منصات الذكاء الاصطناعي المؤسسية القائمة على MCP ونُظم العملاء. في هذا الدور، ستكون مسؤولاً عن تصميم وتنفيذ ضوابط الأمن لشُـدّاد MCP (Model Context Protocol) وخدمات التواصل بين الوكيل والأداة، وإدارة الهوية والوصول، وآليات الحوكمة التي تُمكّن التشغيل الآمن والمتوافق للوكيلات الذكية على نطاق واسع. ستعمل عن كثب مع فرق المنصة والذكاء الاصطناعي والهندسة السحابية لضمان أن تعمل الأنظمة الوكيلية ضمن حدود أمان محددة مع تلبية متطلبات الامتثال والحوكمة للمؤسسة.
ما المشروع الذي لدينا لك
عميلنا شركة متعددة الجنسيات ذات تاريخ يزيد عن قرن من الزمن ومكاتب في أكثر من 180 دولة. هدفهم الأكثر طموحًا في ذلك الوقت هو تقديم سلسلة من المنتجات منخفضة المخاطر (RRPs). جمهورهم المستهدف أكثر من 1 مليار مستهلك حول العالم. تستضيف منصة تكنولوجيا المعلومات 700+ تطبيق.
مهمة Intellia هي مساعدة العميل في هندسة منظومة برمجية شاملة لمنصة IoT مبتكرة على هامش تجربة مستهلكين حديثة وتكنولوجيا رائدة. تشارك فرقنا في هندسة مكونات المنصة الأساسية لحلول التجارة الإلكترونية المتفوقة، والتسويق الرقمي، وحلول IoT. بصفة مهندس، ستصبح جزءًا من فريق الهندسة الأساسية وتكون مسؤولاً عن الهندسة وتطبيق أفضل الممارسات في منصة الهندسة الرقمية للمؤسسة.
المنصة هي مجموعة خدمات وتطبيقات الإنترنت التي تسرّع تطوير وتسليم تطبيقات البرمجيات من خلال الاعتناء بتحديات دورة تطوير البرمجيات الشائعة. توفر المنصة الوصول والاستهلاك لفرق الهندسة إلى مجموعة من الخدمات والتقنيات والممارسات لتطويرها وتشغيل تطبيقاتها، مع ضمان مجموعة من متطلبات الامتثال وأفضل الممارسات.
ما ستقوم به
تصميم وتنفيذ ضوابط الأمن لنشر خوادم MCP، بما في ذلك المصادقة والتخويل وإدارة حدود الثقة للوصف الوكيل وتفاعلات الوكيل مع الأدوات.
تعريف وتنفيذ أنماط اتصال آمنة بين الوكيل والأداة باستخدام OAuth 2.0 وJWT وOIDC وSigV4 وTLS 1.3.
إجراء مراجعات أمان وتمارين نمذجة التهديدات للأنظمة الذكية الوكيلة وتكامل MCP وتدفقات العمل المدعومة بـ LLM.
تحديد وتخفيف المخاطر المتعلقة بحقن الأوامر، والوكالة المفرطة، وتنفيذ الأدوات غير المصرح به، وكشف البيانات الحساسة، وتسريب معلمات الأداة.
إنشاء آليات تصنيف البيانات وحمايتها لمحمّلات أدوات MCP وقنوات اتصال الوكيل.
تصميم عزل الشبكة وأنماط الاتصال الآمن باستخدام VPC وPrivateLink والشبكات الخاصة وضوابط أمان سحابية أصلية.
تطوير أطر الحوكمة وقيود الأمان وآليات فرض السياسات لمنصات الذكاء الاصطناعي المؤسسية.
التعاون مع فرق المنصة والهندسة لضمان اتباع الوكلاء لطرق التوجيه والوصول المعتمدة وعدم تجاوز ضوابط الأمن المقررة.
دعم هندسة IAM وإدارة الوصول لعمليات المصادقة والتفويض بين الوكيل والأداة.
تعريف معايير الأمن والضوابط التشغيلية وأفضل الممارسات لاستضافة MCP وإدارة دورة الحياة.
المشاركة في التحقيق في الحوادث، وتقييمات الأمن، ومراجعات المخاطر وأنشطة الإصلاح المتعلقة بمنصات AI وMCP.
المساهمة في قرارات هندسة الأمن لبوابة AgentCore والسجل وبنى تحتية enterprise AI.
التعاون الوثيق مع الشؤون الامتثال والحوكمة وأصحاب الهندسة لضمان تشغيل آمن وقابل للتدقيق للأنظمة المدفوعة بالذكاء الاصطناعي.
الملف المرشح المطلوب
We are looking for a Security & Governance Engineer focused on securing MCP-based enterprise AI platforms and agent ecosystems. In this role, you will be responsible for designing and enforcing security controls for MCP (Model Context Protocol) servers, agent-to-tool communication, identity and access management, and governance mechanisms that enable safe and compliant operation of AI agents at scale. You will work closely with platform, AI, and cloud engineering teams to ensure that agentic systems operate within defined security boundaries while meeting enterprise compliance and governance requirements.
What project we have for you
Our customer is a multinational corporation with more than a century of history and offices in over 180 countries. Their most ambitious goal at the time is to introduce a range of Reduced-Risk Products (RRPs). The target audience is more than 1 billion consumers around the globe. IT platform hosts 700+ applications.
Intellia’s mission is to help the client with the engineering of a comprehensive software ecosystem for a game-changing IoT product on the margin of innovative consumer experience and cutting-edge technology. Our teams are involved in the engineering of core platform components for best-in-class eCommerce, Digital Marketing and IoT solutions. As an Engineer, you will become a part of Core Architecture Team and be responsible for the architecture, implementation of best practices in our Digital Engineering Enterprise Platform.
The Platform is a set of services and internet applications that accelerate the development and delivery of software applications by taking care of common SDLC challenges. The Platform provides access and consumption for engineering teams to a set of services, technologies, practices for their development and for operating their application, ensuring a set of compliance and best practices.
What you will do
Design and enforce security controls for MCP server deployments, including authentication, authorization, and trust boundary management for tool descriptors and agent interactions.
Define and implement secure agent-to-tool communication patterns using OAuth 2.0, JWT, OIDC, SigV4, and TLS 1.3.
Conduct security reviews and threat modeling exercises for agentic AI systems, MCP integrations, and LLM-powered workflows.
Identify and mitigate risks related to prompt injection, excessive agency, unauthorized tool execution, sensitive data exposure, and tool parameter exfiltration.
Establish data classification and protection mechanisms for MCP tool payloads and agent communication channels.
Design network isolation and secure connectivity patterns using VPC, PrivateLink, private networking, and cloud-native security controls.
Develop governance frameworks, security guardrails, and policy enforcement mechanisms for enterprise AI platforms.
Collaborate with platform and engineering teams to ensure agents follow approved routing and access patterns rather than bypassing established security controls.
Support IAM architecture and access management for agent-to-tool authentication and authorization workflows.
Define security standards, operational controls, and best practices for MCP server onboarding and lifecycle management.
Participate in incident investigation, security assessments, risk reviews, and remediation activities related to AI and MCP platforms.
Contribute to security architecture decisions for AgentCore Gateway, Registry, and enterprise AI infrastructure components.
Work closely with compliance, governance, and engineering stakeholders to ensure secure and auditable operation of AI-driven systems.
Desired Candidate Profile