wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/Security Engineer Role(380)/Infinity (4) - Security Engineer
Pro members applied to this job 36 hours before you saw itGet Pro ›
Infinity

Infinity - Security Engineer

Remote - United States4d ago
RemoteNACloud ComputingArtificial IntelligenceSecurity EngineerPrivacy ManagerPostgreSQLSQLDocumentationPythonAWSLatticeTypeScriptPhoenixB2CHarness

Requirements

• Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles. • Multi-tenant isolation: • Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles. • Identity & access: • Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services. • Application security: • Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock. • Cloud security: • Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program. • Compliance (SOC 2 Type II): • Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content. • Data protection: • Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface. • Secure SDLC & AI risk: • Export-control / IP-sensitive data handling and client-segregation controls. • Serving legal disclosures / ToS and recording acceptance at onboarding. • Adversarial testing of RLS and pooled-connection authorization contexts. • VPC Lattice service-to-service authorization review (SigV4). • Incident-response tabletop exercises and coordinating third-party pen tests.

Responsibilities

• Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface. • Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness. • Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM. • Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling. • Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned. • Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface. • Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.

Benefits

• High-impact work at the intersection of AI and critical infrastructure regulation • Direct customer exposure and a seat at the table when we decide what to build • Small team with outsized influence; your field learning shapes the product roadmap • Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration) • Values We Hire For • Values We Hire For • Character: integrity and trustworthiness above all • Character: • Competency: evoking trust and reliably delivering • Competency: • Togetherness: family-level support and alignment • Togetherness: • Impact: meaningful outcomes over activity • Impact: • Commitment: ownership and follow-through • Commitment: • Labrynth is committed to fair and competitive pay, ensuring that compensation reflects both market conditions and the value each team member brings. Hourly rates are determined based on factors such as location, relevant experience, skills, internal pay equity, and market conditions. • During the interview process, your Talent Acquisition Partner will confirm the hourly rate range applicable to your location. For contractors outside the U.S., compensation is aligned with local market conditions and cost of living. • While every engagement is unique, our compensation philosophy is designed to ensure fairness, consistency, and competitiveness across Labrynth. Additional details regarding compensation, contract terms, and the scope of the engagement will be discussed throughout the hiring process. • Equal Opportunity Statement:

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

Simple Technology SolutionsSimple Technology Solutions - Security Engineer/ISSO Support1mo ago
·Remote - USA
RemoteNASeniorCybersecurityCloud ComputingSecurity EngineerPrivacy ManagerAWSPhoenixDocumentationGovernanceJira
TwilioTwilio - Senior Security Engineer, Incident Response1w ago
·Remote - CT (Central)·$142k - $177k/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerAWSGCPDocumentation
OpenAIOpenAI - Protection Scientist Engineer, Integrity1mo ago
·San Francisco, California, United States·$198k - $425k/year
In OfficeNAMidArtificial IntelligenceSoftwareSecurity EngineerSQLPython
ZocdocZocdoc - Senior Staff Security Engineer, Vulnerability Management1w ago
·Remote - USA Remote·$200k - $200k/year + Equity
RemoteNAStaffCloud ComputingArtificial IntelligenceSecurity EngineerGoRustPythonExecutive SupportAWSGCPAzureDockerKubernetesPhoenix
OpenAIOpenAI - Security Engineer, Agent Security1mo ago
·San Francisco, California, United States·$234k - $385k/year
In OfficeNACloud ComputingArtificial IntelligenceSecurity EngineerGoRustC++PythonAWS
ActiveCampaignActiveCampaign - Senior Security Engineer3w ago
·United States·$126k - $154k/year + Equity
In OfficeNASeniorCloud ComputingLogisticsSecurity EngineerPythonTerraformAWSDocumentationKubernetes
capecape - Security Engineer, Product Security3mo ago
·Remote - USA *·$200k - $255k/year + Equity
RemoteNAMidCybersecurityCloud ComputingSecurity EngineerAWSGoTerraformPythonTypeScript
Sporty GroupSporty Group - Identity & PAM Security Engineer1mo ago
·Remote - Europe
RemoteEMEAMidCloud ComputingSecurity EngineerPrivacy ManagerGovernancePythonAccount ManagementDocumentationVault
NPRNPR - Senior IT Security Engineer1w ago
·Remote - USA·$125k - $152k/year
RemoteNASeniorCybersecurityCloud ComputingSecurity EngineerAWSGCPSplunkBashDocumentationPythonGitReportingCross-functional Collaboration

Browse more by category

Show 380 moreSecurity EngineerShow 32 morePrivacy ManagerShow 606 morePostgreSQLShow 2,750 moreSQLShow 5,137 moreDocumentationShow 4,958 morePythonShow 2,946 moreAWSShow 19 moreLatticeShow 2,050 moreTypeScriptShow 132 morePhoenix
Privacy·Terms··Contact·FAQ·Wagey on X