Vacancy catalog
EPAM
Open roleUpdated

Senior Security & QA Engineer

EPAMLithuania; Latvia
Work model
Hybrid
Experience
3+ years
Employment
Not specified
Compensation
Not disclosed
Technology signal
12 tags

Technology context

12

Parsed from the vacancy text; ordered by relevance to this role.

AWSMCPPythonAPI SecurityAPIAutomationAWS Multi-factor authenticationMCP AppsPytestSecurity TestingSecurity Testing ToolsTest Automation Frameworks

Full listing

Role description

We are seeking a Senior Security & QA Engineer responsible for validating the security, compliance, and reliability of the MCP Server Registry, ensuring proper authentication, credential protection, governance enforcement, and end-to-end registry quality.

Responsibilities

  • Validate authentication enforcement and identify credential exposure risks across the registry
  • Design and execute functional tests covering CRUD operations and validation rules
  • Build and maintain automated test suites using Python and pytest
  • Enforce lifecycle constraint testing, such as preventing deletion of active MCPs or setting in-use MCPs as inactive
  • Audit AWS CloudTrail logs to confirm compliance and traceability of registry actions
  • Assess registry and API endpoints for security vulnerabilities and compliance gaps
  • Collaborate with development teams to ensure governance policies are properly enforced throughout the registry lifecycle

Requirements

  • 3+ years of experience in security testing or QA engineering
  • Experience in registry or API security testing
  • Experience in AWS authentication flow testing
  • Proficiency in Python test automation with pytest
  • Knowledge of lifecycle constraint testing and functional test design for CRUD and validation rules
  • Familiarity with AWS CloudTrail audit log validation
  • English proficiency at B2 level or higher

Nice to have

  • Familiarity with MCP gateway enforcement testing
  • Knowledge of Vault secret exposure testing
  • Understanding of governance lifecycle gate validation