Staff Identity Engineer
Staff Identity Engineer
colossus technologies groupDenver, CO
2 days ago
Computer Systems Design ServicesCustom Computer Programming ServicesOther Scientific and Technical Consulting Services
Apply for this role →What You'll Do:
Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise Own App Sec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release Extend detection coverage to CLI agents (Codex, Open Code) and browser-based agents
Responsibilities:
Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise Own App Sec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release Extend detection coverage to CLI agents (Codex, Open Code) and browser-based agents Qualifications 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection
Required Skills:
Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines. Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses
Also on the board Same function, level within a rung
Level
Lead
Location
Denver, CO
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
2 days ago