Staff Identity Engineer
colossus technologies groupDenver (CO)
About the role
What You'll Do:
Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise Own App Sec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release Extend detection coverage to CLI agents (Codex, Open Code) and browser-based agents
Responsibilities:
Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise Own App Sec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release Extend detection coverage to CLI agents (Codex, Open Code) and browser-based agents Qualifications 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection
Required Skills:
Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines. Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
