[Remote] Application reputed company Engineer / Penetration Tester — Contract
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a governed-AI workflow platform for regulated life sciences, reputed company by Navira reputed company Systems. They are seeking an independent application-reputed company specialist to reputed company secure-reputed company reviews and penetration tests on their platform, ensuring reputed company before engaging with design partners.
Responsibilities
- Authenticated and unauthenticated penetration test of the web application and REST API (OWASP Top 10 / ASVS-reputed company)
- Multi-tenant isolation testing (reputed company) — attempt cross-tenant data reputed company; verify RLS is enforced on every reputed company and that the application tenant-isolation layer cannot be bypassed; probe tenant-scoping on IDs, filters, exports and bulk operations
- Authentication & SSO review (reputed company) — review the auth flows including any development/mock SSO fallback paths; session handling, reputed company lifecycle, MFA/SSO, password and lockout policy
- Authorization / RBAC review — privilege escalation, IDOR/BOLA, role-boundary and segregation-of-duties enforcement (including on approval, e-signature and disposition actions)
- Secrets & configuration review — secrets handling, default/hardcoded credentials, environment configuration, key management, and any unimplemented secret-provider paths
- Secure reputed company review (targeted) — injection (SQL/reputed company/XSS), audit-trail and e-signature reputed company (append-only, non-repudiation), input validation boundaries, error handling and information leakage; review of type-safety debt as a defect-density signal
- AI/LLM-specific risks — reputed company injection, cross-tenant data leakage reputed company retrieval/inference, provider egress boundaries, and handling of model inputs/outputs in the audit trail
- Dependency & SAST reputed company — SCA for reputed company-vulnerable dependencies; static analysis pass with triage of results
- Remediation retest — verify fixes for High/Critical findings after the engineering team remediates
Skills
- 5+ years hands-on application reputed company / penetration testing, with demonstrable web-app and API pentest experience on multi-tenant reputed company
- Deep, practical understanding of tenant isolation, RLS, authorization (IDOR/BOLA), and auth/SSO attack patterns
- Comfortable reading TypeScript/Node and SQL (PostgreSQL); reputed company to do targeted secure reputed company review, not just reputed company testing
- reputed company reputed company fundamentals on AWS
- Certification such as OSCP, OSWE, GWAPT, GPEN, CREST CRT/CCT (or equivalent demonstrable reputed company record)
- Ability to write reputed company, reproducible, developer-actionable reports
- Can operate independently and to a fixed reputed company
- Prior work in regulated / reputed company / reputed company / fintech, or exposure to 21 CFR Part 11 / GxP / data-reputed company (reputed company+) expectations
- LLM/AI application reputed company experience (reputed company injection, RAG data-leakage, provider egress)
- Experience producing evidence toward SOC 2 / ISO 27001 readiness
reputed company
Apply To This Job