Security Engineer - Labrnyth
Job description
ABOUT LABRYNTH
Labrynth accelerates progress by streamlining regulatory complexity. We build AI-powered platforms that navigate complex regulations, generate audit-level documentation, and provide certainty, not shortcuts. Our technology serves clients across heavily regulated industries, including energy, compliance, and government.
We operate as a forward-deployed engineering organization: small, high-velocity teams embedded directly with clients to rapidly discover needs and ship production-quality solutions.
ABOUT THE ROLE
Patent Intelligence is an active Labrynth engagement delivering an AI-assisted patent intelligence platform. The next product is an invite-only B2C platform for personal and team accounts, built as a greenfield product alongside the current application. Because it handles commercially sensitive (and potentially export-controlled) patent material, security is a first-class requirement.
This is a contract engagement (Agency / Statement of Work), with an initial term of 60-90 days and the option to extend, reporting to the Patent Project engineering lead and coordinating with GRC, Backend, DevOps/Platform, and Frontend.
The Security contractor reviews and adversarially tests the platform's boundaries, account isolation, external identity/access, and application and AI-agent security, and, alongside the live GRC program, drives SOC 2 Type II readiness. The role does not own application authorization policy (Backend) or the secure-defaults / infrastructure substrate (DevOps); it reviews and verifies these rather than building them. Meaningful overlap with US and Australian project hours is required for the weekly sync and incident response.
WHAT YOU'LL DO
- Threat-model (STRIDE/PASTA) the B2C architecture, focused on account isolation (PostgreSQL forced RLS + account_id, S3, the BFF boundary, Cognito), external access, and the AI/agent surface.
- Run adversarial tenant-isolation testing: prove forged, reused, stale, and pooled-connection authorization contexts fail closed under direct runtime-role SQL, and that cross-account denial holds even when BFF route authorization is bypassed in a test harness.
- Review the BFF authorization boundary, the Amazon Cognito identity/access model (customer + operator pools), secrets management, and least-privilege IAM.
- Verify data-protection controls: encryption in transit/at rest, data classification, customer-content-safe telemetry, S3 Object Lock evidence integrity, and export-controlled content handling.
- Map SOC 2 Type II controls and drive evidence collection via Drata, coordinated with GRC, with owners assigned.
- Review CI security-gate policy (dependency/container/IaC/secret scanning) and assess AI/LLM risk (prompt injection, tool data-exfiltration, over-broad tool access) across the public read-only MCP surface.
- Build incident-response plans and runbooks, coordinate third-party pen tests, and hand over a prioritized remediation backlog and documented security posture.
WHAT WE'RE LOOKING FOR
- Multi-tenant isolation: hard account isolation via PostgreSQL forced RLS + account_id, transaction-bound authorization contexts, and service/worker roles.
- Identity & access: external-user identity/access over Cognito (customer + operator pools); authentication/authorization review and least-privilege roles.
- Application security: OWASP Top 10 in practice; threat modeling (STRIDE/PASTA); secure code review across Python/TypeScript services.
- Cloud security: securing AWS, IAM, KMS, Secrets Manager, VPC Lattice with IAM authorization, network exposure, safe defaults, S3 public-access blocking and Object Lock.
- Compliance (SOC 2 Type II): hands-on evidence workflows; Drata experience strongly valued, coordinating with an active GRC program.
- Data protection: encryption in transit/at rest, data classification, and handling of sensitive / export-controlled content.
- Secure SDLC & AI risk: reviewing dependency/container/IaC/secret scanning and CI security gates; LLM/agent risks relevant to a public read-only MCP surface.
NICE TO HAVE
- Export-control / IP-sensitive data handling and client-segregation controls.
- Serving legal disclosures / ToS and recording acceptance at onboarding.
- Adversarial testing of RLS and pooled-connection authorization contexts.
- VPC Lattice service-to-service authorization review (SigV4).
- Incident-response tabletop exercises and coordinating third-party pen tests.
- Privacy frameworks relevant to the clients' jurisdictions.
WHAT WE OFFER
- High-impact work at the intersection of AI and critical infrastructure regulation
- Direct customer exposure and a seat at the table when we decide what to build
- Small team with outsized influence; your field learning shapes the product roadmap
- Modern AI-native development environment (Claude Code, Cursor, multi-model orchestration)
- Remote-first
- Competitive compensation
VALUES WE HIRE FOR
- Character: in