Lead AI Security Engineer - MCP Security

  • Компания: Trimble
  • Город , ,
  • Зарплата:
  • Размещено: 2025-11-06 21:53:37

Описание

Transporeon is a SaaS company founded in 2000 in Ulm, Germany. The company provides logistics solutions across several areas, including:

Buying & selling of logistics services

Organizing shipment execution

Organizing dock, yard, truck, and driver schedules

Invoice auditing for logistics services


It has grown significantly over the years, reaching €150m in revenue before being acquired by Trimble for $2 billion USD in 2022. Transporeon has one of the largest networks of shippers and carriers in Europe, with approximately 1,400 employees:

Job Purpose

Lead the design and implementation of a defense-in-depth security framework for Model Context Protocol (MCP) servers and related agent ecosystems. Own enforceable scopes, egress control, and observability patterns that protect internal and customer data while preserving developer velocity. Operate as a Lead/Specialist: working independently, leading others to solve complex problems, and applying specialized expertise to influence product, platform, and policy decisions. This is a hands-on role: you will design, code, test, and ship production-grade security components and reference implementations.

About the Team

Join a lean Center of Excellence within the Applied AI Safety & Enablement group. We partner closely with other Trimble security and platform teams on identity, gateway policy, and secure remote deployment. We also collaborate with AI agent development teams on governance and AI-specific safeguards. The charter: standardize secure MCP deployment and operations across Trimble, starting with highest‑risk scenarios and expanding via quick wins and reusable reference architectures.

Main Tasks

Architect, implement, and maintain a secure ingress pattern for remote MCP (Model Context Protocol )servers behind an authenticated gateway, including policy enforcement, request logging, rate limiting, and abuse detection.

Define and implement scope-based authorization aligned to OAuth2/OIDC, including audience validation and JWKS discovery, with progressive adoption of enforceable scopes at the auth server.

Build or be able to adapt to egress controls and telemetry for remote and local/stdio MCP servers, including developer-friendly proxies, tagging, and baseline logging.

Ship and maintain production-ready reference implementations and hardened templates for Kubernetes-based deployments that product teams can adopt with minimal friction.

Integrate static and supply-chain scanning into CI for MCP servers. Automate checks in registration and deployment pipelines.

Partner with agent teams to align tool metadata linting, scope-to-tool mapping, and safety checks at the agent and gateway layers.

Build and maintain vetted libraries, CLIs, shims, and middleware for token validation, scope evaluation, logging, and egress controls.

Responsibilities

Lead cross-functional technical design with other Trimble security and platform teams to make the MCP gateway a first-class platform capability, including consent flows and registration in API Cloud.

Define policy-as-code for authorization, quotas, and abuse prevention. Measure effectiveness via auditability, adoption, and time-to-onboard metrics.

Publish developer guidance and guardrails for remote and local MCP scenarios. Provide vetted libraries and patterns for token validation, scope evaluation, and logging.

Triage and reduce top security risks first: high-impact data exfiltration, prompt-injection exposure at the agent boundary, and unobserved egress from local servers.

Operate as a Lead/Specialist: interpret internal and external challenges, recommend best practices, and lead others to solve complex problems with minimal oversight.

Influence platform roadmaps to enable enforceable scopes and centralized routing while maintaining clear separation of concerns between discovery, policy enforcement, and deployment.

Write and review code for gateways, policy enforcement, developer tooling, and integrations. Contribute high-quality code, tests, and documentation while leading technical direction.

Desired Skills

Deep hands-on expertise with OAuth2/OIDC, scopes, consent, and token validation patterns. Experience evolving toward enforceable scopes at the authorization server.

Understanding Kubernetes architecture and platform engineering fundamentals, including container security, service identity, and secret management.

Understanding of the current agent/MCP ecosystems and AI-specific risks, with a bias for controls at the tool, agent, and layers rather than intrusive network overseers.

Proficiency in one or more of: Python, TypeScript, .NET, or Java for platform, services, and tooling. Ability to choose the right tool for the component.

Experience translating security policy into policy-as-code and enforcing it through code-written integrations is a plus.

Specialized depth in security-focused application development with the ability to lead others on complex issues.

Works independently, receives guidance only on the most complex situations.

Communicates difficult concepts, negotiates trade-offs, and influences across teams.

Interprets business and regulatory challenges to recommend best practices with the ability to explain them to non-technical staff.


How to Apply: Please submit an online application for this position by clicking on the ‘Apply Now’ button located in this posting.


Application Deadline: Applications could be accepted until at least 30 days from the posting date.

Join a Values-Driven Team: Belong, Grow, Innovate. 

At Trimble, our core values of Belong, Grow, and Innovate aren't just words—they're the foundation of our culture. We foster an environment where you are seen, heard, and valued (Belong); where you have an opportunity to build a career and drive our collective growth (Grow); and where your innovative ideas shape the future (Innovate). We believe in empowering local teams to create impactful strategies, ensuring our global vision resonates with every individual. Become part of a team where your contributions truly matter. 

Trimble’s Privacy Policy

If you need assistance or would like to request an accommodation in connection with the application process, please contact om.

Похожие вакансии

Senior Security Officer

... existing policies and best practices. Lead and supervise the UEMCO Security Team, composed of three Security Officers located in Kyiv, Kharkiv, ...
Компания: UNOPS Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

Field Security Associate (FSA) - Training, NPSA-6, DS-Kyiv, UNDSS, Nationals only

... the Department of Safety and Security of Ukraine. This position is ... commercial companies used for UN security at offices and residences in ... is not a requirement.  Applicable security, police and or military training ...
Компания: PNUD Argentina Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

Security Officer, (NO-2), Odesa, Ukraine, post # 134572, Temporary Appointment (Open for Ukrainian nationals only)

... their potential but also will lead to sustained growth and stability ... into Area SRM documentation, Area Security plans, road and location specific ... meetings with the management of security service providers, as directed by ...
Компания: Unicef Город:, ,
Зарплата: Размещено:
ua.talent.com

Cyber Security DevOps Manager

... foundation in cloud and container security, Secure SDLC, application security tooling (e.g., SAST, DAST, ... Blackduck, Coverity on Polaris, Advanced Security, WIZ etc.Familiar with cloud-native security controls, secure coding practices, and ...
Компания: JTI Город:
Зарплата: Размещено:
jobs.jti.com

Application Security Engineer (Pentester / QA Automation)

... are looking for an Application Security Engineer (Pentester QA Automation) — a specialist ... стійкість наших послугМи шукаємо Application Security Engineer (Pentester QA Automation) — фахівця, який ...
Компания: Raiffeisen Bank Ukraine Город:, ,
Зарплата: Размещено:
ua.talent.com

System Security Engineer

... Engineer to join our dynamic team. If you thrive in a collaborative, fast-paced environment and want to help shape the security posture of Playtech and its subsidiaries, this is your opportunityJob DescriptionYour Influential Mission: You Will…Lead ...
Компания: Playtech Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

Data Security Solution Engineer

... safer place.As a Data Security Solution Engineer, you will work with a ... technical decisionsYou will remediate blockers, lead and ensure technical wins for Microsoft Security and adjacent technologies. Engages with ...
Компания: Microsoft Город:, ,
Зарплата: Размещено:
ua.talent.com

Safety and Security Director, Ukraine Response

... areas. Capacity Building & Staff Engagement Lead the professional development of safety and security teams across Ukraine. Provide training ...
Компания: Save the Children Город:, ,
Зарплата: Размещено:
ua.talent.com

System Security Engineer

... -on experience as an Information Security Expert Engineer (we value both strong technical ...
Компания: Playtech Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

Senior Security Engineer

... to date with the latest security and technology developments;Maintain the security appliances and services;Provide an active role in defining security practices for new and ongoing ...
Компания: Softjourn Город:
Зарплата: Размещено:
softjourn.com

Data Scientist (Generative AI)

... tools and technologies.We also lead Gen AI Lab — our internal innovation engine ... image generationCompetent in applying generative AI and language models to lead innovative NLP and AI-driven initiativesProficient with state-of- ...
Компания: SoftServe Город:, ,
Зарплата: Размещено:
ua.talent.com

Cybersecurity and Digital Resilience Strategist

... form holistic capacity building solutions. - Lead Ukraine-focused cybersecurity training, tabletop ... think like an attacker (offensive security mindset). Expertise in risk management. ... , CISM, CEH, ISO 27001 Lead Auditor, NIST CSF Practitioner). Experience ...
Компания: CRDF Global Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

AI Solutions Architect (#4156)

... through the transformative potential of AI ML technology. Key Responsibilities: Lead pre-sales efforts, including crafting ... Learning - Specialty, Microsoft Certified: Azure AI Engineer Associate) are highly desirable. Excellent ...
Компания: N-iX Город:, ,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Uzhhorod,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Chernivtsi,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ternopil,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ternopil,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Cherkasy,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ivano-Frankivsk,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Cherkasy,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ivano-Frankivsk,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Chernivtsi,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Cherkasy,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Chernivtsi,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Uzhhorod,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ivano-Frankivsk,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Uzhhorod,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, ,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, Ternopil,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, ,
Зарплата: Размещено:
ua.talent.com

AWS/Security Networking Engineer (Senior/Lead) ID42040

... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
Компания: AgileEngine Город:, ,
Зарплата: Размещено:
ua.talent.com

Senior Frontend Engineer, AI Experience Track

... curious  Senior Front End Engineer eager to build exceptional AI-driven product experiences within our ... business value through applied AI — creating intuitive interfaces and tools ... :Collaborate closely with AI engineers, product managers, and designers ...
Компания: PandaDoc Город:, ,
Зарплата: Размещено:
ua.talent.com

AI Software Engineer

... the Role: We’re seeking an AI Software Engineer to build a multi-agent system that integrates AI Agents into business teams. You’ll ... insights regularly.‬ Obsessively Innovating with AI - always refining how you use AI tools to reduce friction and ...
Компания: HelpFlow Город:, ,
Зарплата: Размещено:
ua.talent.com

Senior AI Engineer (RemotePass)

... Were looking for a Senior AI Engineer for our portfolio company, RemotePass. ... looking for a Senior AI Engineer to join our team and ... .What you will do:Lead the end-to-end lifecycle of AI-powered solutions, from rapid prototyping ...
Компания: Flyer One Ventures Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com

INFORMATION SECURITY RISK MANAGER

... now  Learn more: jti.comInformation Security Risk ManagerWe are seeking an experienced Information Security Risk Manager to play a ... cross-functional teams and communicating security concepts to non-technical stakeholders. ...
Компания: JTI Город:
Зарплата: Размещено:
jobs.jti.com

Senior Frontend Engineer – AI Agents

... language models and our internal AI platform.As a Senior Frontend Engineer on these teams, youll play ... , LlamaIndex, or similar);Understanding of security best practices for AI systems (prompt injection prevention, data ...
Компания: PandaDoc Город:, ,
Зарплата: Размещено:
ua.talent.com

Senior AI Automation Engineer (Remote - Worldwide)

... currently looking for a Senior AI Automation Engineer in Worldwide.As a Senior AI Automation Engineer, you will design, implement, and ...
Компания: Jobgether Город:, ,
Зарплата: Размещено:
ua.talent.com

Assistant Protection Cluster Coordination Officer (N)

... of Ukraine maintains a strong lead role in responding to the ... designated as the Protection Cluster Lead Agency under the Cluster Approach, ... work in a highly dynamic security environment where unexpected events occur ...
Компания: UNHCR Город:, Dnipro,
Зарплата: Размещено:
ua.talent.com

Social Media Manager

... , analytics, and optimization. You’ll use AI to scale high-quality content, automate workflows, and derive faster insights. You’ll lead engagement across platforms, amplify our ... thrive in a fast-paced, AI-first environment. Transparency, collaboration, and ...
Компания: Shae Group Город:, Kyiv,
Зарплата: Размещено:
ua.talent.com