Associate Security Engineer
Listed on 2026-08-31
-
IT/Tech
Cybersecurity
Description:
SPS Commerce is a leading provider of cloud-based supply chain management solutions, serving a global network of retail trading partners. We foster a collaborative and inclusive work environment where innovation and continuous improvement are highly valued. Join SPS Commerce and be part of a dynamic team that's transforming the global retail supply chain!
SPS Commerce is hiring an Associate Security Engineer to join Agentic Cyber Engineering (ACE), the function that builds and hardens the agentic tooling Cyber Defense, Cyber Security and adjacent engineering teams run: MCP servers, tool integrations, and AI-augmented security workflows. This role brings two capabilities to ACE, hands-on offensive-security skills to red-team agent tooling before it reaches production, and software engineering capacity to build and maintain offensive and other agentic tooling.
The ideal candidate finds the ways an agent and software tool's permissions, prompt boundaries, or integrations can be abused, before that abuse happens in production.
In this role, you will build agentic security tooling, enhancing the program’s offensive and defensive capabilities, reporting to the Lead Engineer, ACE. Build and maintain MCP servers and tool integrations for security-engineering agents, under the Lead Engineer’s architecture. Contribute to ACE’s internal tooling repositories - issues, PRs, documentation. Support integration of agent tooling with the existing security stack (Crowd Strike Falcon, Panther, Jira, OSS).
Apply offensive-security methodology (prompt injection, tool-abuse paths, permission-boundary testing, jailbreak attempts) to agents and MCP servers before they ship. Document findings in the same reproduction-steps / business-impact / remediation format used for traditional vulnerability disclosure. Partner with the Lead Engineer on remediation and re-verification. Write Python/SQL tooling to support ACE workflows - data pipelines, evaluation harnesses, internal dashboards. Extend existing automations as ACE’s agent fleet grows.
Produce a technical writeup for every agent evaluation: affected system, reproduction steps, risk severity, recommended fix. Keep tooling documentation current enough that another engineer can extend it without hand-holding.
Bachelor's degree in Cybersecurity, Computer Science, or equivalent practical experience. Working proficiency in at least one general-purpose language (Python preferred) with real shipped code, coursework alone is not sufficient. Hands-on experience with offensive-security tooling (e.g., Burp Suite, Nmap, Metasploit) in an authorized context (CTF, red-team internship, responsible disclosure program). Familiarity with SIEM/log analysis concepts. Comfortable with Git-based version control and collaborative development.
Familiarity with core AWS serverless technologies;
Lambda, Step Functions, DynamoDB, EC2, and similar, the building blocks of serverless compliance, governance, and security tooling.
Direct experience with LLM tooling, agent frameworks, or MCP, even personal-project level. OSINT / reconnaissance tooling experience (Shodan, Maltego, the Harvester, or peers). Prior red-team or C2 infrastructure exposure in an authorized engagement. A documented history of responsible vulnerability disclosure. Competitive security background (CTF, Cyber Skyline, NCL, or similar).
Location:This role follows a hybrid work model, with regular in-office presence required at our MSP office.
What We Offer:At SPS Commerce, we are committed to ensuring that each employee's compensation reflects their unique experiences, performance, and skills in their role. The salary range for this role considers several factors, including education, relevant skills, work history, certifications, location, and more. The annual salary range for this role is: $70,600.00 - $90,000 . The actual salary offered will be determined based on the factors listed above and may fall anywhere within the range.
SPS Commerce offers a comprehensive benefits package designed to support employees' health,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).