Job Openings Application Security Engineer (part-time contract)

About the job Application Security Engineer (part-time contract)

About the role

We are looking for a Senior Application Security Engineer to support an AI-powered platform serving organizations in regulated industries.

You will assess and test the security of a new product that handles sensitive information, with a strong focus on account isolation, identity and access, application security, and AI-agent risks. You will also support SOC 2 Type II readiness alongside an established governance, risk, and compliance team.

This is a hands-on role working closely with Backend, Frontend, and DevOps engineers. Your focus will be reviewing and validating security controls, identifying vulnerabilities, and guiding remediation.

Day to Day:

  • Perform threat modeling and security assessments across application architecture, APIs, and AI-agent workflows.
  • Test isolation between customer accounts, including PostgreSQL row-level security and authorization controls.
  • Review authentication and access management using Amazon Cognito and AWS IAM.
  • Conduct secure code reviews across Python and TypeScript services.
  • Assess AWS security controls, encryption, secrets management, storage access, and sensitive-data protection.
  • Evaluate AI and LLM risks, including prompt injection, data leakage, and excessive tool permissions.
  • Review security checks within development pipelines, including dependency, container, infrastructure-as-code, and secrets scanning.
  • Support SOC 2 Type II control mapping and evidence collection in coordination with the GRC team.
  • Develop incident-response plans, coordinate external penetration tests, and deliver a prioritized remediation backlog.

What We're Looking For

  • Senior-level, hands-on experience in Application Security, Product Security, or a closely related engineering role.
  • Experience assessing multi-tenant applications and validating isolation between customer accounts.
  • Strong understanding of PostgreSQL row-level security, database access controls, and service or worker permissions.
  • Practical knowledge of OWASP Top 10, threat modeling methodologies such as STRIDE or PASTA, and secure code review.
  • Ability to review and understand Python and TypeScript code.
  • Experience with AWS security, including IAM, Cognito, KMS, Secrets Manager, and S3.
  • Hands-on involvement in SOC 2 readiness or audit evidence workflows.
  • Understanding of security risks associated with LLMs, AI agents, and their connected tools.
  • Ability to work independently, prioritize risks, and communicate actionable findings to engineering teams.
  • Advanced English skills.

Nice to Have

  • Experience using Drata for compliance evidence management.
  • Advanced testing of PostgreSQL RLS and authorization contexts across pooled database connections.
  • Familiarity with MCP security and AWS VPC Lattice authorization.
  • Experience protecting highly sensitive data in regulated environments.
  • Experience running incident-response exercises and coordinating third-party penetration tests.

Why Join This Project?

  • Work remotely on an AI-powered product with meaningful security challenges.
  • Compensation in USD.
  • Part-time engagement with overlap with US working hours - 4 hours per day.