xelys jobs xelys jobs

Security Engineer - Labrnyth

Infinity Constellation

midcontractsecurityoperations United States 2 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Security EngineeringThreat ModelingSTRIDEPASTASOC 2 Type IIDrataAWS SecurityCognitoMulti-tenant IsolationLLM/Agent Security

About the role

Role overview

Contract Security Engineer supporting a patent intelligence engagement and a new invite-only B2C AI-assisted patent intelligence platform. Because the platform handles commercially sensitive and potentially export-controlled patent material, security is treated as a first-class requirement.

The contractor will report to the Patent Project engineering lead and coordinate with GRC, Backend, DevOps/Platform, and Frontend. The engagement is an Agency/Statement of Work contract for an initial 60–90 days with an option to extend, requiring meaningful overlap with US and Australian project hours for weekly sync and incident response.

Responsibilities

  • Threat model the B2C architecture (STRIDE/PASTA), with emphasis on:
    • Account isolation (PostgreSQL forced RLS + account_id, S3, BFF boundary, Cognito)
    • External identity/access
    • Application and AI-agent security
  • Run adversarial tenant-isolation testing to verify authorization fails closed, including scenarios involving forged/reused/stale/pooled connection contexts and cross-account denial even if BFF route authorization is bypassed in a test harness.
  • Review authorization boundaries (BFF) and Amazon Cognito identity/access model (customer + operator pools).
  • Verify security controls:
    • Secrets management and least-privilege IAM
    • Encryption in transit and at rest
    • Data classification and customer-content-safe telemetry
    • S3 Object Lock evidence integrity and export-controlled content handling
  • Drive SOC 2 Type II readiness by mapping controls and collecting evidence via Drata, coordinated with the active GRC program.
  • Review CI security gates (dependency/container/IaC/secret scanning) and assess LLM/AI risk such as prompt injection, tool data exfiltration, and over-broad tool access across a public read-only MCP surface.
  • Build incident-response plans/runbooks, coordinate third-party pen tests, and deliver a prioritized remediation backlog plus documented security posture.

What the role does NOT do

  • Does not own application authorization policy (Backend)
  • Does not own secure-defaults/infrastructure substrate (DevOps)
  • Instead, it reviews and verifies those implementations rather than building them

Requirements

  • Multi-tenant isolation experience, including hard account isolation with:
    • PostgreSQL forced RLS + account_id
    • Transaction-bound authorization contexts
    • Service/worker roles
  • Identity & access review for external users using Cognito (customer + operator pools), including authentication/authorization and least-privilege roles.
  • Application security capability:
    • OWASP Top 10 in practice
    • Threat modeling (STRIDE/PASTA)
    • Secure code review across Python/TypeScript services
  • Cloud security with AWS, including:
    • IAM, KMS, Secrets Manager
    • VPC Lattice with IAM authorization
    • Network exposure and safe defaults
    • S3 public-access blocking and Object Lock
  • SOC 2 Type II readiness with hands-on evidence workflows; Drata strongly valued.
  • Data protection: encryption in transit/at rest, data classification, and handling sensitive/export-controlled content.
  • Secure SDLC & AI risk: reviewing CI scanning/security gates and assessing LLM/agent risks.

Nice-to-haves / valued

  • Strong familiarity with Drata and active coordination with a GRC program.

About Infinity Constellation

Infinity Constellation (Labrynth) builds AI-powered platforms that simplify regulatory complexity. Its products navigate complex regulations, generate audit-level documentation, and help clients in heavily regulated industries such as energy, compliance, and government. The company operates as small, high-velocity, forward-deployed engineering teams embedded with clients to ship production-quality solutions.

Scraped 7/30/2026