
Security Analyst β MCP & Application
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Argentina.
β’ Take charge of the security measures for the MCP infrastructure by defining and implementing JWT-based authentication, managing secrets, and creating controls for tool usage and agent interactions.
β’ Detect and address prompt injection vulnerabilities, unauthorized tool usage, and privilege escalation risks within the agentic layer.
β’ Assess and strengthen AWS infrastructure configurations including IAM policies, VPC rules, secrets exposure, logging, and alerting.
β’ Manage the clientβs existing application security backlog β tackling issues currently addressed on an ad hoc basis by IT and senior developers that require a dedicated, long-term owner.
β’ Collaborate with the engineering team to review new integrations and MCP components prior to release, establishing a standardized pre-release security review process.
β’ Record security controls, threat models, and remediation history to enable the client team to operate autonomously over time.
β’ Practical experience in application security engineering β with a focus beyond consulting or auditing.
β’ Proficiency in JWT token validation and API key management in production environments β including scoped access patterns, token lifecycle, and revocation processes.
β’ Knowledge of authentication and authorization design: OAuth 2.0, API key management, and scoped access patterns in live systems.
β’ Expertise in secrets management within cloud environments: AWS Secrets Manager, Vault, or similar β demonstrating ownership of the implementation rather than just awareness of their existence.
β’ Experience in identifying and mitigating prompt injection, tool misuse, and trust boundary vulnerabilities in AI/LLM systems β or a solid foundation in OWASP Top 10 with proven ability to apply it to emerging attack surfaces.
β’ Ability to function as the sole security representative on a team β capable of raising concerns diplomatically, maintaining technical standards, and prioritizing a backlog without the guidance of a security manager.
β’ Near-native English proficiency β engaging in daily asynchronous communication with a US-based client team and technical lead.
β’ Monthly compensation of $4000 - $5500 β paid in USD, bi-weekly through Deel.
β’ Working hours aligned with US Eastern Time (EST) β Monday to Friday, 9:00 AMβ6:00 PM EST.
β’ Fully remote position β the flexibility to work from anywhere in Latin America.
β’ Long-term contract β commencing with an initial 6-month agreement, with opportunities for extension.
β’ Paid PTO β accrual starts after a 3-month trial period.
β’ Referral Program β earn bonuses for recommending talent that is successfully hired.
Varicent
Cresol Cooperativa
Get handpicked remote jobs straight to your inbox weekly.