Lead AI Security Engineer - MCP Security

Trimble , , 2025-11-06 21:53:37

Описание

Transporeon is a SaaS company founded in 2000 in Ulm, Germany. The company provides logistics solutions across several areas, including:

Buying & selling of logistics services

Organizing shipment execution

Organizing dock, yard, truck, and driver schedules

Invoice auditing for logistics services


It has grown significantly over the years, reaching €150m in revenue before being acquired by Trimble for $2 billion USD in 2022. Transporeon has one of the largest networks of shippers and carriers in Europe, with approximately 1,400 employees:

Job Purpose

Lead the design and implementation of a defense-in-depth security framework for Model Context Protocol (MCP) servers and related agent ecosystems. Own enforceable scopes, egress control, and observability patterns that protect internal and customer data while preserving developer velocity. Operate as a Lead/Specialist: working independently, leading others to solve complex problems, and applying specialized expertise to influence product, platform, and policy decisions. This is a hands-on role: you will design, code, test, and ship production-grade security components and reference implementations.

About the Team

Join a lean Center of Excellence within the Applied AI Safety & Enablement group. We partner closely with other Trimble security and platform teams on identity, gateway policy, and secure remote deployment. We also collaborate with AI agent development teams on governance and AI-specific safeguards. The charter: standardize secure MCP deployment and operations across Trimble, starting with highest‑risk scenarios and expanding via quick wins and reusable reference architectures.

Main Tasks

Architect, implement, and maintain a secure ingress pattern for remote MCP (Model Context Protocol )servers behind an authenticated gateway, including policy enforcement, request logging, rate limiting, and abuse detection.

Define and implement scope-based authorization aligned to OAuth2/OIDC, including audience validation and JWKS discovery, with progressive adoption of enforceable scopes at the auth server.

Build or be able to adapt to egress controls and telemetry for remote and local/stdio MCP servers, including developer-friendly proxies, tagging, and baseline logging.

Ship and maintain production-ready reference implementations and hardened templates for Kubernetes-based deployments that product teams can adopt with minimal friction.

Integrate static and supply-chain scanning into CI for MCP servers. Automate checks in registration and deployment pipelines.

Partner with agent teams to align tool metadata linting, scope-to-tool mapping, and safety checks at the agent and gateway layers.

Build and maintain vetted libraries, CLIs, shims, and middleware for token validation, scope evaluation, logging, and egress controls.

Responsibilities

Lead cross-functional technical design with other Trimble security and platform teams to make the MCP gateway a first-class platform capability, including consent flows and registration in API Cloud.

Define policy-as-code for authorization, quotas, and abuse prevention. Measure effectiveness via auditability, adoption, and time-to-onboard metrics.

Publish developer guidance and guardrails for remote and local MCP scenarios. Provide vetted libraries and patterns for token validation, scope evaluation, and logging.

Triage and reduce top security risks first: high-impact data exfiltration, prompt-injection exposure at the agent boundary, and unobserved egress from local servers.

Operate as a Lead/Specialist: interpret internal and external challenges, recommend best practices, and lead others to solve complex problems with minimal oversight.

Influence platform roadmaps to enable enforceable scopes and centralized routing while maintaining clear separation of concerns between discovery, policy enforcement, and deployment.

Write and review code for gateways, policy enforcement, developer tooling, and integrations. Contribute high-quality code, tests, and documentation while leading technical direction.

Desired Skills

Deep hands-on expertise with OAuth2/OIDC, scopes, consent, and token validation patterns. Experience evolving toward enforceable scopes at the authorization server.

Understanding Kubernetes architecture and platform engineering fundamentals, including container security, service identity, and secret management.

Understanding of the current agent/MCP ecosystems and AI-specific risks, with a bias for controls at the tool, agent, and layers rather than intrusive network overseers.

Proficiency in one or more of: Python, TypeScript, .NET, or Java for platform, services, and tooling. Ability to choose the right tool for the component.

Experience translating security policy into policy-as-code and enforcing it through code-written integrations is a plus.

Specialized depth in security-focused application development with the ability to lead others on complex issues.

Works independently, receives guidance only on the most complex situations.

Communicates difficult concepts, negotiates trade-offs, and influences across teams.

Interprets business and regulatory challenges to recommend best practices with the ability to explain them to non-technical staff.


How to Apply: Please submit an online application for this position by clicking on the ‘Apply Now’ button located in this posting.


Application Deadline: Applications could be accepted until at least 30 days from the posting date.

Join a Values-Driven Team: Belong, Grow, Innovate. 

At Trimble, our core values of Belong, Grow, and Innovate aren't just words—they're the foundation of our culture. We foster an environment where you are seen, heard, and valued (Belong); where you have an opportunity to build a career and drive our collective growth (Grow); and where your innovative ideas shape the future (Innovate). We believe in empowering local teams to create impactful strategies, ensuring our global vision resonates with every individual. Become part of a team where your contributions truly matter. 

Trimble’s Privacy Policy

If you need assistance or would like to request an accommodation in connection with the application process, please contact om.

Похожие вакансии

  • Senior Security Officer

    UNOPS , Kyiv, 24 дня назад
    ... existing policies and best practices. Lead and supervise the UEMCO Security Team, composed of three Security Officers located in Kyiv, Kharkiv, ...
    ua.talent.com
  • Security Officer, (NO-2), Odesa, Ukraine, post # 134572, Temporary Appointment (Open for Ukrainian nationals only)

    Unicef , , 8 дней назад
    ... their potential but also will lead to sustained growth and stability ... into Area SRM documentation, Area Security plans, road and location specific ... meetings with the management of security service providers, as directed by ...
    ua.talent.com
  • Cyber Security DevOps Manager

    JTI 14 часов назад
    ... foundation in cloud and container security, Secure SDLC, application security tooling (e.g., SAST, DAST, ... Blackduck, Coverity on Polaris, Advanced Security, WIZ etc.Familiar with cloud-native security controls, secure coding practices, and ...
    jobs.jti.com
  • Application Security Engineer (Pentester / QA Automation)

    Raiffeisen Bank Ukraine , , 16 дней назад
    ... are looking for an Application Security Engineer (Pentester QA Automation) — a specialist ... стійкість наших послугМи шукаємо Application Security Engineer (Pentester QA Automation) — фахівця, який ...
    ua.talent.com
  • System Security Engineer

    Playtech , Kyiv, месяц назад
    ... Engineer to join our dynamic team. If you thrive in a collaborative, fast-paced environment and want to help shape the security posture of Playtech and its subsidiaries, this is your opportunityJob DescriptionYour Influential Mission: You Will…Lead ...
    ua.talent.com
  • Data Security Solution Engineer

    Microsoft , , 20 дней назад
    ... safer place.As a Data Security Solution Engineer, you will work with a ... technical decisionsYou will remediate blockers, lead and ensure technical wins for Microsoft Security and adjacent technologies. Engages with ...
    ua.talent.com
  • System Security Engineer

    Playtech , Kyiv, 18 дней назад
    ... -on experience as an Information Security Expert Engineer (we value both strong technical ...
    ua.talent.com
  • Head of AI Consulting (#3887)

    N-iX , , месяц назад
    ... world-class AI consultant for both clients and internal delivery teams Engage in short- and mid-term AI projects as a consultant engineer to ensure successful execution and ... ) Build and lead a top-tier AI consulting team of passionate experts. ...
    ua.talent.com
  • AI/ML Engineer (IR-465)

    Intellectsoft , , 19 дней назад
    ... .We seek a highly skilled AI Engineer to drive the Clients transformation ... and workload orchestration.Familiarity with MCP and A2A protocols.Bachelors or ... experience leveraging the full Azure AI suite, including Azure AI Services, OpenAI on Azure, and ...
    ua.talent.com
  • AI/ML Engineer (IR-465)

    Intellectsoft , , 20 дней назад
    ... .We seek a highly skilled AI Engineer to drive the Clients transformation ... and workload orchestration.Familiarity with MCP and A2A protocols.Bachelors or ... experience leveraging the full Azure AI suite, including Azure AI Services, OpenAI on Azure, and ...
    ua.talent.com
  • Senior Security Engineer

    Softjourn 14 часов назад
    ... to date with the latest security and technology developments;Maintain the security appliances and services;Provide an active role in defining security practices for new and ongoing ...
    softjourn.com
  • Data Scientist (Generative AI)

    SoftServe , , 22 дня назад
    ... tools and technologies.We also lead Gen AI Lab — our internal innovation engine ... image generationCompetent in applying generative AI and language models to lead innovative NLP and AI-driven initiativesProficient with state-of- ...
    ua.talent.com
  • InfoSec (DevSecOps) Engineer

    LoopMe , Dnipro, 20 дней назад
    ... (e.g., CISSP, CISM, CompTIA Security+, GCP Security Engineer) are a plus.  Excellent communication ... want to work with patented-AI technology and develop high-performance ... . As the market leader in AI, LoopMe uses agile methodology to ...
    ua.talent.com
  • Cybersecurity and Digital Resilience Strategist

    CRDF Global , Kyiv, 10 дней назад
    ... form holistic capacity building solutions. - Lead Ukraine-focused cybersecurity training, tabletop ... think like an attacker (offensive security mindset). Expertise in risk management. ... , CISM, CEH, ISO 27001 Lead Auditor, NIST CSF Practitioner). Experience ...
    ua.talent.com
  • Senior Solution Area Specialist - Security

    Microsoft , Kyiv, 23 дня назад
    ... cross-functional initiatives.ResponsibilitiesBe the security expert for your assigned territory. Lead and plan for accounts across ... . Demo and whiteboard the cloud security solutions and the relevant security architecture. Lead and orchestrate V-Team to ...
    ua.talent.com
  • Junior InfoSec (DevSecOps) Engineer

    LoopMe , Dnipro, 20 дней назад
    ... Unix administration. Understanding of information security principles (encryption, authentication, access control) ... want to work with patented-AI technology and develop high-performance ... . As the market leader in AI, LoopMe uses agile methodology to ...
    ua.talent.com
  • Junior InfoSec (DevSecOps) Engineer

    LoopMe , Lviv, 20 дней назад
    ... Unix administration. Understanding of information security principles (encryption, authentication, access control) ... want to work with patented-AI technology and develop high-performance ... . As the market leader in AI, LoopMe uses agile methodology to ...
    ua.talent.com
  • AI Solutions Architect (#4156)

    N-iX , , месяц назад
    ... through the transformative potential of AI ML technology. Key Responsibilities: Lead pre-sales efforts, including crafting ... Learning - Specialty, Microsoft Certified: Azure AI Engineer Associate) are highly desirable. Excellent ...
    ua.talent.com
  • Intermediate Software Engineer (Python) - OP01921

    Dev.Pro , , 22 дня назад
    ... experienced and motivated Intermediate Software Engineer with strong Python skills to ... up-to-date with emerging AI technologies and suggest ideas for ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Cherkasy, 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , , 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , , 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ivano-Frankivsk, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ternopil, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Chernivtsi, 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Uzhhorod, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Cherkasy, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ivano-Frankivsk, 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Chernivtsi, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Chernivtsi, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ivano-Frankivsk, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Cherkasy, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Uzhhorod, 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ternopil, 16 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Ternopil, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , Uzhhorod, 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • AWS/Security Networking Engineer (Senior/Lead) ID42040

    AgileEngine , , 15 дней назад
    ... like application development and AI ML, and our people-first ... as a Senior AWS Security Networking Engineer to shape secure, scalable cloud ... -on experience with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, Shield, etc.);Understanding ...
    ua.talent.com
  • Senior Frontend Engineer, AI Experience Track

    PandaDoc , , 16 дней назад
    ... curious  Senior Front End Engineer eager to build exceptional AI-driven product experiences within our ... business value through applied AI — creating intuitive interfaces and tools ... :Collaborate closely with AI engineers, product managers, and designers ...
    ua.talent.com
  • AI Software Engineer

    HelpFlow , , 20 дней назад
    ... the Role: We’re seeking an AI Software Engineer to build a multi-agent system that integrates AI Agents into business teams. You’ll ... insights regularly.‬ Obsessively Innovating with AI - always refining how you use AI tools to reduce friction and ...
    ua.talent.com

Карточка вакансии:

  • Должность Lead AI Security Engineer - MCP Security
  • Размещено: 2025-11-06 21:53:37
  • Город , ,
  • Зарплата:
  • Компания: Trimble