Security Engineer - Labrnyth at Infinity
—
Jul 26, 2026
—
Jul 28, 2026
What this job asks for AI summary
A contract security engagement (60–90 days, extendable) on an AI-assisted patent intelligence platform. The contractor performs adversarial tenant-isolation testing, threat modeling, identity/access review, cloud security assessment, and SOC 2 Type II evidence collection — reviewing and verifying controls built by backend and DevOps teams rather than building them. Suits an experienced application/cloud security practitioner comfortable with AWS, PostgreSQL RLS, and LLM/agent risk.
Senior level · Remote · Contract
Quick apply — this platform usually takes a CV and a few fields.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 400 people nationally plausibly meet what this posting asks for (information security analysts). range 80–600
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
No overall years-of-experience requirement is stated in the posting.
Compensation is hourly but no rate range is disclosed; the posting states rates will be confirmed during the interview process and vary by location.
The role explicitly covers both US and Australian working hours for weekly syncs and incident response — the primary work location is remote with no country restriction stated, so the US-based flag defaults to true, but non-US contractors are explicitly welcomed.
Drata is listed under the requirements section but qualified as 'strongly valued' rather than a hard gate, so it is marked preferred.
STRIDE and PASTA are listed as interchangeable threat-modeling methodologies; STRIDE is used as the primary name with PASTA as an alternative.
The 'Nice to Have' section includes: export-control/IP-sensitive data handling, legal disclosure/ToS acceptance recording, adversarial RLS testing, VPC Lattice SigV4 review, incident-response tabletop exercises, third-party pen test coordination, and privacy frameworks — all marked preferred.
MCP (Model Context Protocol) refers to the public read-only AI/agent surface mentioned in the posting.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.