Back to Jobs
Development Just now

Security Contractor (AI-Powered Patent Intelligence Platform)

United StatesUnited States
Contract
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOpsBestseller 🔥
Learn in 63 Hours
PythonBestseller 🔥
Learn in 56 Hours
BackendBestseller 🔥
Learn in 18 Hours
CybersecurityAWS

Want to know if you're a match for this job?

Calculate My Match Score

About the Role

Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application. Because it handles commercially sensitive (and potentially export-controlled) patent material, security is a first-class requirement.

This is a contract engagement (Agency / Statement of Work), with an initial term of 60–90 days and the option to extend, reporting to the Patent Project engineering lead and coordinating with GRC, Backend, DevOps/Platform, and Frontend.

The Security contractor reviews and adversarially tests the platform's boundaries, account isolation, external identity/access, and application and AI-agent security, and, alongside the live GRC program, drives SOC 2 Type II readiness. The role does not own application authorization policy (Backend) or the secure-defaults / infrastructure substrate (DevOps); it reviews and verifies these rather than building them. Meaningful overlap with US and Australian project hours is required for the weekly sync and incident response.

What You'll Do

  • Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface.

  • Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness.

  • Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM.

  • Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling.

  • Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned.

  • Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface.

  • Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.

What We're Looking For

  • Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles.

  • Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles.

  • Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services.

  • Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock.

  • Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program.

  • Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content.

  • Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface.

Nice to Have

  • Export-control / IP-sensitive data handling and client-segregation controls.

  • Serving legal disclosures / ToS and recording acceptance at onboarding.

  • Adversarial testing of RLS and pooled-connection authorization contexts.

  • VPC Lattice service-to-service authorization review (SigV4).

  • Incident-response tabletop exercises and coordinating third-party pen tests.

  • Privacy frameworks relevant to the clients' jurisdictions.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More