Ведущий инженер по информационной безопасности
Summary
Leads security design for an AI-first platform, implementing RBAC/ABAC, secrets management, audit, and threat modeling for MCP, RAG, and agent workflows.
Обязанности:
Проектировать security baseline для AI-first платформы: secrets, RBAC/ABAC, audit, PII, data residency, tenant isolation. Участвовать в разработке и внедрении сервисов guardrails / guard-сервисов для MCP, RAG, Agent workflows и tool calls. Разрабатывать методологии ролевой модели: роли, permissions, ownership, visibility, escalation, exceptions. Описывать и внедрять RBAC/ABAC-модели для платформенных сервисов и AI-capabilities. Настраивать security gates в CI/CD: policy-as-code, secret checks, dependency checks, baseline checks перед staging/production. Проводить threat modeling для MCP Hub, Platform API, agent routes, RAG-интеграций и tool execution
Требования:
Опыт с AI/LLM security: prompt injection, tool abuse, data leakage, jailbreak risks. Опыт с MCP, RAG, agent-based workflows или AI platform infrastructure. Опыт разработки внутренних security-сервисов, guardrails, policy engines, approval/exception workflows. Опыт с Vault, Kubernetes, GitLab CI/CD, OpenTelemetry, SIEM/logging.