Job Openings
Application Security Engineer (part-time contract)
About the job Application Security Engineer (part-time contract)
About the role
We are looking for a Senior Application Security Engineer to support an AI-powered platform serving organizations in regulated industries.
You will assess and test the security of a new product that handles sensitive information, with a strong focus on account isolation, identity and access, application security, and AI-agent risks. You will also support SOC 2 Type II readiness alongside an established governance, risk, and compliance team.
This is a hands-on role working closely with Backend, Frontend, and DevOps engineers. Your focus will be reviewing and validating security controls, identifying vulnerabilities, and guiding remediation.
Day to Day:
- Perform threat modeling and security assessments across application architecture, APIs, and AI-agent workflows.
- Test isolation between customer accounts, including PostgreSQL row-level security and authorization controls.
- Review authentication and access management using Amazon Cognito and AWS IAM.
- Conduct secure code reviews across Python and TypeScript services.
- Assess AWS security controls, encryption, secrets management, storage access, and sensitive-data protection.
- Evaluate AI and LLM risks, including prompt injection, data leakage, and excessive tool permissions.
- Review security checks within development pipelines, including dependency, container, infrastructure-as-code, and secrets scanning.
- Support SOC 2 Type II control mapping and evidence collection in coordination with the GRC team.
- Develop incident-response plans, coordinate external penetration tests, and deliver a prioritized remediation backlog.
What We're Looking For
- Senior-level, hands-on experience in Application Security, Product Security, or a closely related engineering role.
- Experience assessing multi-tenant applications and validating isolation between customer accounts.
- Strong understanding of PostgreSQL row-level security, database access controls, and service or worker permissions.
- Practical knowledge of OWASP Top 10, threat modeling methodologies such as STRIDE or PASTA, and secure code review.
- Ability to review and understand Python and TypeScript code.
- Experience with AWS security, including IAM, Cognito, KMS, Secrets Manager, and S3.
- Hands-on involvement in SOC 2 readiness or audit evidence workflows.
- Understanding of security risks associated with LLMs, AI agents, and their connected tools.
- Ability to work independently, prioritize risks, and communicate actionable findings to engineering teams.
- Advanced English skills.
Nice to Have
- Experience using Drata for compliance evidence management.
- Advanced testing of PostgreSQL RLS and authorization contexts across pooled database connections.
- Familiarity with MCP security and AWS VPC Lattice authorization.
- Experience protecting highly sensitive data in regulated environments.
- Experience running incident-response exercises and coordinating third-party penetration tests.
Why Join This Project?
- Work remotely on an AI-powered product with meaningful security challenges.
- Compensation in USD.
- Part-time engagement with overlap with US working hours - 4 hours per day.