Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Infinity Constellation

Security Engineer

Infinity Constellation

Security Engineer focused on adversarial testing of a patent intelligence AI platform at Labrynth. Ensuring security and compliance for sensitive patent materials while collaborating with engineering teams.

Posted 7/28/2026contractRemote • 🇺🇸 United StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in threat modeling, multi-tenant isolation, and application security, with a strong focus on compliance and data protection. Proficient in securing cloud environments and implementing secure software development lifecycle practices.

Highest-signal resume keywords
Threat Modeling (STRIDE/PASTA)Multi-Tenant Isolation (PostgreSQL Forced RLS)Cloud Security (AWS, IAM, KMS)Compliance (SOC 2 Type II, Drata)Application Security (OWASP Top 10)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat ModelingMulti-Tenant IsolationApplication SecurityCloud SecurityData ProtectionSecure SDLCIncident Response PlanningSecure Code ReviewAuthorization ReviewEncryption in Transit/At Rest
Tools & Technologies
PostgreSQLAmazon CognitoAWSDrataIAMKMSSecrets ManagerVPC LatticeS3CI Security Gates
Industry Keywords
SOC 2 Type IIGRCAI RiskDependency ScanningContainer SecurityIaC SecurityData ClassificationTelemetryIncident ResponseSecurity Posture

Tech Stack

Tools & technologies
AWSCloudPostgresPythonSDLCSQLTypeScript

About the role

Key responsibilities & impact
  • Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface.
  • Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness.
  • Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM.
  • Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling.
  • Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned.
  • Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface.
  • Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.

Requirements

What you’ll need
  • Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles.
  • Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles.
  • Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services.
  • Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock.
  • Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program.
  • Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content.
  • Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface.

Benefits

Comp & perks
  • High-impact work at the intersection of AI and critical infrastructure regulation
  • Direct customer exposure and a seat at the table when we decide what to build
  • Small team with outsized influence; your field learning shapes the product roadmap
  • Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration)
  • Remote-first
  • Competitive compensation