About the role
We are building a unified, scalable AI security testing and benchmarking platform deeply integrated within the client’s Security ecosystem. This platform plays a critical role in evaluating AI usage monitoring at runtime to continuously validate AI agents and their embedded capabilities before adoption — ultimately reducing security, compliance, and remediation exposure across the client’s software delivery.
The remote work option is available to candidates residing and working within the Czech Republic.
Responsibilities
- Design, build, and scale automated AI security testing and benchmarking pipelines within the client’s Security ecosystem
- Evaluate and implement runtime AI usage monitoring to continuously assess AI agents and their embedded capabilities prior to production adoption
- Conduct dynamic and static testing against AI architectures (including MCP, LLMs, and RAG pipelines) to uncover vulnerabilities aligned with the OWASP Top 10 for LLMs and Web Applications
- Partner closely with engineering, core security teams, and stakeholders to align on security guardrails, write clear technical documentation, and report on security posture and testing metrics
Requirements
- Solid foundation in security engineering principles, secure software development, and integrating security practices throughout the delivery lifecycle
- Deep grasp of application security fundamentals, secure architectures, and vulnerability management — including familiarity with web application threats and the OWASP Top 10 (Web, LLM, and MCP)
- Comprehensive, up-to-date understanding of AI security paradigms, architectures, and threat models, specifically concerning Model Context Protocol (MCP), Large Language Models (LLMs), and Retrieval-Augmented Generation (RAG)
- Practical knowledge of both dynamic (DAST) and static (SAST) testing techniques to uncover and validate security flaws
Nice to have
- Basic ability to read code across multiple languages to understand functionality and implement small patches when needed
- Genuine interest in exploring the intersection of AI for security and security for AI
- Clear technical writing and reporting skills, with the ability to bridge technical concepts for non-technical stakeholders
- Experience driving cross-team alignment across engineering, security, and product groups
We offer
- Opportunity to work in a fast-paced, agile, software engineering culture
- Comfortable modern office in Prague 7, with support of hybrid or fully remote mode
- Benefit program (5 weeks of vacation, paid sick days, paid days off for special occasions, meal vouchers, flexi pass, Prague city public transport annual coupon, multisport cards, optional contribution to pension fund, health insurance for family member)
- EPAM Employee Stock Purchase Plan (ESPP) (subject to certain eligibility requirements)
- English language courses
- Czech language courses upon request
- Referral bonuses for recommended candidates
- Mobile Phone Tariff’s program for managerial-level candidates
- Great learning and development opportunities, including in-house professional training, career advisory and coaching, sponsored professional certifications, well-being programs, LinkedIn Learning Solutions and much more
Certain benefits and perks may be subject to eligibility requirements and may be available only after you have passed your probationary period.
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at EPAM Systems was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
