Security Contractor (AI-Powered Patent Intelligence Platform)
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Role
Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application. Because it handles commercially sensitive (and potentially export-controlled) patent material, security is a first-class requirement.
This is a contract engagement (Agency / Statement of Work), with an initial term of 60–90 days and the option to extend, reporting to the Patent Project engineering lead and coordinating with GRC, Backend, DevOps/Platform, and Frontend.
The Security contractor reviews and adversarially tests the platform's boundaries, account isolation, external identity/access, and application and AI-agent security, and, alongside the live GRC program, drives SOC 2 Type II readiness. The role does not own application authorization policy (Backend) or the secure-defaults / infrastructure substrate (DevOps); it reviews and verifies these rather than building them. Meaningful overlap with US and Australian project hours is required for the weekly sync and incident response.
What You'll Do
Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface.
Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness.
Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM.
Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling.
Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned.
Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface.
Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.
What We're Looking For
Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles.
Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles.
Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services.
Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock.
Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program.
Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content.
Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface.
Nice to Have
Export-control / IP-sensitive data handling and client-segregation controls.
Serving legal disclosures / ToS and recording acceptance at onboarding.
Adversarial testing of RLS and pooled-connection authorization contexts.
VPC Lattice service-to-service authorization review (SigV4).
Incident-response tabletop exercises and coordinating third-party pen tests.
Privacy frameworks relevant to the clients' jurisdictions.
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.