Sobre este puesto de Senior Security / QA Lead | 12 weeks+ (569) en Ubiminds
SENIOR SECURITY / QA LEAD
About the opportunity
Lead adversarial security testing, validate deterministic decision paths, and prove audit-trail tamper resistance for an enterprise-ready AI-driven platform.
About our client
Our client is preparing two AI-driven platforms for enterprise readiness, with a focus on security, correctness, and financial integrity ahead of a production launch.
What you'll do
-
Design and lead adversarial security testing of the deterministic decision path.
-
Attempt to defeat default-DENY, escalate privileges, or cross tenant boundaries, and prove that the boundaries hold.
-
Test multi-tenant isolation and owner-versus-customer scoping through the platform’s roster subsystem, using real tenant-scoped identities.
-
Verify the tamper-resistance of the hash-chained audit trail, including append-only behavior, hash-chain linkage, and detection of attempted mutation.
-
Validate authentication and authorization across tenant and operator roles.
-
Review and extend the existing per-module freeze-audit self-tests.
-
Ensure every governance rule resolves through the live intake path to a real engine record.
-
Rank findings by severity and provide clear reproduction steps in GitHub Issues.
-
Keep findings in the same line of sight as the freeze-audit CI gate and uphold the merge gate (nothing lands unless freeze-audit CI is green).
-
Partner with the client on architectural sign-off for any governance-core change.
What you bring (must-haves)
-
Strong security-testing background, including penetration testing, authorization/access-control testing, or security QA against systems where boundary failure is the primary risk.
-
Hands-on experience with Python and comfort reading a real codebase to design tests against it.
-
Experience with multi-tenant SaaS and a practical understanding of tenant isolation failure modes.
-
Practical understanding of cryptographic audit trails / hash chaining and how tamper-evidence is proven.
-
Experience with Docker and CI-based workflows, including GitHub Actions or equivalent.
-
Ability to work against a green-CI merge gate.
-
Proficiency with Postgres for validating durable state and persistence.
-
Clear written English.
-
Strong ability to produce rigorous, reproducible defect reports.
Bonus points for (nice-to-haves)
-
Experience testing policy engines, authorization systems, or agentic-AI guardrails.
-
Exposure to SOC 2 controls and evidence expectations.
-
Familiarity with Render or comparable container hosting.
-
Background working in a regulated or safety-critical domain.
Perks & benefits
💻 Equipment provided — none of that "bring your own device" stuff here
🛡️ Full back-office support — Legal, Accounting, HR Business Partner, and Delivery team
🧭 Career and cultural mentoring — how to show up, stand out, and navigate US work culture
🗣️ Free English lessons with a native speaker
🤝 Referral bonus — recommend Ubi to your tech friends and get paid for it
🏖️ Florianópolis HQ always open — 100% remote, but the office is there whenever you want it.
How the process works
-
Interview with our Tech Recruiter (+ quick AI assessment, if needed)
-
Client interview process (varies by company)
-
Offer 🎉
-
Onboarding with full Ubiminds support
Why Ubiminds?
With 9 years in the market and GPTW-certified, Ubiminds connects Latin American tech professionals with software companies in the US and Canada. Hundreds of professionals in data, design, product, and engineering are already growing in North American teams with our support. We're with you throughout the entire journey — Recruitment, Legal, Accounting, PeopleOps, and career guidance — so you can thrive internationally with confidence.
Ready to go global? Apply now — it takes less than 5 minutes.