Overview
TITLE: MCP Gateway / AI Security Platform Engineer
DURATION: Contract 9-12 months, possibly longer.
PAY: Market Rate
LOCATION: Remote/ Hybrid: these are 90% offsite (maybe 100% for some). Onsite is downtown Manhattan.
NOTE: All expenses paid by the client for travel, lodging and per-diem
INDUSTRY: Investment firms for a financial-services cybersecurity engagement
CITIZENSHIP: Must be US Citizen or Legal/Permanent Resident Green Card
REQUIREMENTS: Clear written communication, experience, professionalism, and quality work are a must.
Lead or support enterprise Model Context Protocol (MCP) gateway/security work: gateway evaluation and deployment, MCP server/tool risk review, authentication/authorization safeguards, least privilege, observability, SIEM/monitoring, human-approval controls, incident/runbook design, and secure AI-agent/tool-integration patterns.
Strong fit: platform engineering, SRE, cloud/infrastructure, backend engineering, IAM, Kubernetes, API gateways/proxies, OAuth/OIDC/JWT, secrets management, CI/CD, observability, AI/LLM agents/tool calling/RAG, AI security, prompt-injection/tool-poisoning risk, and strong architecture documentation.
Application questions – Part 1
- Legal name and if you have a preferred or nickname:
- Linked In:
- Best contact info (Email, cell):
- Citizenship (US, Legal/Permanent Resident Green Card, or other):
- Availability:
- Where you live: (City, St, Zip)
- Willing to work 100% onsite, hybrid or remote:
- Willing to relocate if necessary:
- City, State, Zip and desired geographical work locations:
- Active passport and willing to travel if necessary
- Hourly/salary history and expectations:
- Sizes of Staff overseen:
- Budgetary Responsibility:
- Hierarchy/Report to:
- Education/Degrees/Active Certs:
JOB SCREENING QUESTIONS – Part 2
Please answer next to each question.
- How many years of experience and how recent is your experience in Leading and/or supporting enterprise Model Context Protocol (MCP) gateway/security work: gateway evaluation and deployment, MCP server/tool risk review, authentication/authorization safeguards, least privilege, observability, SIEM/monitoring, human-approval controls, incident/runbook design, and secure AI-agent/tool-integration patterns?
- How many years of experience and how recent is your experience in
- Platform engineering:
- SRE:
- Cloud/infrastructure:
- Backend engineering:
- IAM:
- Kubernetes:
- API gateways/proxies:
- OAuth/OIDC/JWT:
- Secrets management:
- CI/CD:
- Observability:
- AI/LLM agents/tool calling/RAG:
- AI security:
- Prompt-injection/tool-poisoning risk:
- Strong architecture documentation.
www.LinkedIn.com/in/DianeKrehbiel