Jobs Companies Infinity Security Engineer - Labrnyth

Über diese Security Engineer - Labrnyth Stelle bei Infinity

Infinity · Remote · United States

About Labrynth

Labrynth accelerates progress by streamlining regulatory complexity. We build AI-powered platforms that navigate complex regulations, generate audit-level documentation, and provide certainty, not shortcuts. Our technology serves clients across heavily regulated industries, including energy, compliance, and government.

We operate as a forward-deployed engineering organization: small, high-velocity teams embedded directly with clients to rapidly discover needs and ship production-quality solutions.

About the Role

Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application. Because it handles commercially sensitive (and potentially export-controlled) patent material, security is a first-class requirement.

This is a contract engagement (Agency / Statement of Work), with an initial term of 60–90 days and the option to extend, reporting to the Patent Project engineering lead and coordinating with GRC, Backend, DevOps/Platform, and Frontend.

The Security contractor reviews and adversarially tests the platform's boundaries, account isolation, external identity/access, and application and AI-agent security, and, alongside the live GRC program, drives SOC 2 Type II readiness. The role does not own application authorization policy (Backend) or the secure-defaults / infrastructure substrate (DevOps); it reviews and verifies these rather than building them. Meaningful overlap with US and Australian project hours is required for the weekly sync and incident response.

What You'll Do

  • Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface.

  • Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness.

  • Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM.

  • Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling.

  • Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned.

  • Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface.

  • Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.

What We're Looking For

  • Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles.

  • Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles.

  • Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services.

  • Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock.

  • Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program.

  • Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content.

  • Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface.

Nice to Have

  • Export-control / IP-sensitive data handling and client-segregation controls.

  • Serving legal disclosures / ToS and recording acceptance at onboarding.

  • Adversarial testing of RLS and pooled-connection authorization contexts.

  • VPC Lattice service-to-service authorization review (SigV4).

  • Incident-response tabletop exercises and coordinating third-party pen tests.

  • Privacy frameworks relevant to the clients' jurisdictions.

What We Offer

  • High-impact work at the intersection of AI and critical infrastructure regulation

  • Direct customer exposure and a seat at the table when we decide what to build

  • Small team with outsized influence; your field learning shapes the product roadmap

  • Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration)

  • Remote-first

  • Competitive compensation

Values We Hire For

  • Character: integrity and trustworthiness above all

  • Competency: evoking trust and reliably delivering

  • Togetherness: family-level support and alignment

  • Impact: meaningful outcomes over activity

  • Commitment: ownership and follow-through

What's In It For You

Labrynth is committed to fair and competitive pay, ensuring that compensation reflects both market conditions and the value each team member brings. Hourly rates are determined based on factors such as location, relevant experience, skills, internal pay equity, and market conditions.

During the interview process, your Talent Acquisition Partner will confirm the hourly rate range applicable to your location. For contractors outside the U.S., compensation is aligned with local market conditions and cost of living.

While every engagement is unique, our compensation philosophy is designed to ensure fairness, consistency, and competitiveness across Labrynth. Additional details regarding compensation, contract terms, and the scope of the engagement will be discussed throughout the hiring process.

Equal Opportunity Statement:

We’re an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status, or any other basis protected by law.

Bereit, sich bei Infinity zu bewerben?
Bei Infinity bewerben

Ähnliche Jobs

Paxos
Security Operations Engineer
Paxos
⚡ Früh bewerben Remote - United States · standortgebunden $169,000–$194,025
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
xAI
Security Engineer - GRC Fintech & Financial Services
xAI
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $152,000–$228,000
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
Reddit
Senior Machine Learning Engineer, GenAI Security
Reddit
⚡ Früh bewerben Remote - United States · standortgebunden $216,700–$303,400
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
Verisign
Senior InfoSec Tools Engineer
Verisign
⚡ Früh bewerben Reston,Virginia,United States Hybrid $135,800–$183,800
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
xAI
Security Engineer - GRC Frameworks & AI Governance
xAI
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $152,000–$228,000
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
FanDuel
Security Engineer
FanDuel
⚡ Früh bewerben Atlanta, Georgia, United State... Vor Ort $134,000–$168,000
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
FanDuel
Staff Security Engineer
FanDuel
⚡ Früh bewerben Atlanta, Georgia, United State... Vor Ort $184,000–$241,500
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
Referral Board
Principal Software Engineer - Security - Elasticsearch
Referral Board
⚡ Früh bewerben United States Vor Ort $159,800–$252,800
● Neu 👁 Gesehen ✓ Beworben vor 11 Std.
Referral Board
Senior Software Engineer - Security - Elasticsearch
Referral Board
⚡ Früh bewerben United States Vor Ort $133,100–$210,600
● Neu 👁 Gesehen ✓ Beworben vor 11 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Infinity

Alle Jobs bei Infinity ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos