Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Security Engineer - Labrnyth

Infinity Constellation
CompanyInfinity Constellation
CategoryUncategorised
LocationUnited States
RemoteRemote
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted27 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
ABOUT LABRYNTH Labrynth accelerates progress by streamlining regulatory complexity. We build AI-powered platforms that navigate complex regulations, generate audit-level documentation, and provide certainty, not shortcuts. Our technology serves clients across heavily regulated industries, including energy, compliance, and government. We operate as a forward-deployed engineering organization: small, high-velocity teams embedded directly with clients to rapidly discover needs and ship production-quality solutions. ABOUT THE ROLE Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application. Because it handles commercially sensitive (and potentially export-controlled) patent material, security is a first-class requirement. This is a contract engagement (Agency / Statement of Work), with an initial term of 60–90 days and the option to extend, reporting to the Patent Project engineering lead and coordinating with GRC, Backend, DevOps/Platform, and Frontend. The Security contractor reviews and adversarially tests the platform's boundaries, account isolation, external identity/access, and application and AI-agent security, and, alongside the live GRC program, drives SOC 2 Type II readiness. The role does not own application authorization policy (Backend) or the secure-defaults / infrastructure substrate (DevOps); it reviews and verifies these rather than building them. Meaningful overlap with US and Australian project hours is required for the weekly sync and incident response. WHAT YOU'LL DO - Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface. - Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness. - Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM. - Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling. - Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned. - Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface. - Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture. WHAT WE'RE LOOKING FOR - Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles. - Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles. - Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services. - Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock. - Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program. - Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content. - Secure SDLC & AI risk: reviewing dependency/container/IaC/secr
HOUSE ADYou found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →
Security Engineer - Labrnyth — Infinity Constellation · Job Opportunities API