Security Engineer - Labrnyth
Infinity Constellation
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role overview
Contract Security Engineer supporting a patent intelligence engagement and a new invite-only B2C AI-assisted patent intelligence platform. Because the platform handles commercially sensitive and potentially export-controlled patent material, security is treated as a first-class requirement.
The contractor will report to the Patent Project engineering lead and coordinate with GRC, Backend, DevOps/Platform, and Frontend. The engagement is an Agency/Statement of Work contract for an initial 60–90 days with an option to extend, requiring meaningful overlap with US and Australian project hours for weekly sync and incident response.
Responsibilities
- Threat model the B2C architecture (STRIDE/PASTA), with emphasis on:
- Account isolation (PostgreSQL forced RLS + account_id, S3, BFF boundary, Cognito)
- External identity/access
- Application and AI-agent security
- Run adversarial tenant-isolation testing to verify authorization fails closed, including scenarios involving forged/reused/stale/pooled connection contexts and cross-account denial even if BFF route authorization is bypassed in a test harness.
- Review authorization boundaries (BFF) and Amazon Cognito identity/access model (customer + operator pools).
- Verify security controls:
- Secrets management and least-privilege IAM
- Encryption in transit and at rest
- Data classification and customer-content-safe telemetry
- S3 Object Lock evidence integrity and export-controlled content handling
- Drive SOC 2 Type II readiness by mapping controls and collecting evidence via Drata, coordinated with the active GRC program.
- Review CI security gates (dependency/container/IaC/secret scanning) and assess LLM/AI risk such as prompt injection, tool data exfiltration, and over-broad tool access across a public read-only MCP surface.
- Build incident-response plans/runbooks, coordinate third-party pen tests, and deliver a prioritized remediation backlog plus documented security posture.
What the role does NOT do
- Does not own application authorization policy (Backend)
- Does not own secure-defaults/infrastructure substrate (DevOps)
- Instead, it reviews and verifies those implementations rather than building them
Requirements
- Multi-tenant isolation experience, including hard account isolation with:
- PostgreSQL forced RLS + account_id
- Transaction-bound authorization contexts
- Service/worker roles
- Identity & access review for external users using Cognito (customer + operator pools), including authentication/authorization and least-privilege roles.
- Application security capability:
- OWASP Top 10 in practice
- Threat modeling (STRIDE/PASTA)
- Secure code review across Python/TypeScript services
- Cloud security with AWS, including:
- IAM, KMS, Secrets Manager
- VPC Lattice with IAM authorization
- Network exposure and safe defaults
- S3 public-access blocking and Object Lock
- SOC 2 Type II readiness with hands-on evidence workflows; Drata strongly valued.
- Data protection: encryption in transit/at rest, data classification, and handling sensitive/export-controlled content.
- Secure SDLC & AI risk: reviewing CI scanning/security gates and assessing LLM/agent risks.
Nice-to-haves / valued
- Strong familiarity with Drata and active coordination with a GRC program.
About Infinity Constellation
Infinity Constellation (Labrynth) builds AI-powered platforms that simplify regulatory complexity. Its products navigate complex regulations, generate audit-level documentation, and help clients in heavily regulated industries such as energy, compliance, and government. The company operates as small, high-velocity, forward-deployed engineering teams embedded with clients to ship production-quality solutions.
Scraped 7/30/2026