Senior Security / QA Lead | 12 weeks+ (569)
SENIOR SECURITY / QA LEAD
About the opportunity
Lead adversarial security testing, validate deterministic decision paths, and prove audit-trail tamper resistance for an enterprise-ready AI-driven platform .
About our client
Our client is preparing two AI-driven platforms for enterprise readiness, with a focus on security, correctness, and financial integrity ahead of a production launch .
What you'll do
-
Design and lead adversarial security testing of the deterministic decision path.
-
Attempt to defeat default-DENY, escalate privileges, or cross tenant boundaries, and prove that the boundaries hold.
-
Test multi-tenant isolation and owner-versus-customer scoping through the platform’s roster subsystem, using real tenant-scoped identities.
-
Verify the tamper-resistance of the hash-chained audit trail, including append-only behavior, hash-chain linkage, and detection of attempted mutation.
-
Validate authentication and authorization across tenant and operator roles.
-
Review and extend the existing per-module freeze-audit self-tests.
-
Ensure every governance rule resolves through the live intake path to a real engine record.
-
Rank findings by severity and provide clear reproduction steps in GitHub Issues.
-
Keep findings in the same line of sight as the freeze-audit CI gate and uphold the merge gate (nothing lands unless freeze-audit CI is green).
-
Partner with the client on architectural sign-off for any governance-core change.
What you bring (must-haves)
-
Strong security-testing background, including penetration testing, authorization/access-control testing, or security QA against systems where boundary failure is the primary risk.
-
Hands-on experience with Python and comfort reading a real codebase to design tests against it.
-
Experience with multi-tenant SaaS and a practical understanding of tenant isolation failure modes.
-
Practical understanding of cryptographic audit trails / hash chaining and how tamper-evidence is proven.
-
Experience with Docker and CI-based workflows, including GitHub Actions or equivalent.
-
Ability to work against a green-CI merge gate.
-
Proficiency with Postgres for validating durable state and persistence.
-
Clear written English.
-
Strong ability to produce rigorous, reproducible defect reports.
Bonus points for (nice-to-haves)
-
Experience testing policy engines, authorization systems, or agentic-AI guardrails.
-
Exposure to SOC 2 controls and evidence expectations.
-
Familiarity with Render or comparable container hosting.
-
Background working in a regulated or safety-critical domain.
Perks & benefits
💻 Equipment provided — none of that "bring your own device" stuff here
🛡️ Full back-office support — Legal, Accounting, HR Business Partner, and Delivery team
🧭 Career and cultural mentoring — how to show up, stand out, and navigate US work culture
🗣️ Free English lessons with a native speaker
🤝 Referral bonus — recommend Ubi to your tech friends and get paid for it
🏖️ Florianpolis HQ always open — 100% remote, but the office is there whenever you want it .
How the process works
- AI Assessment + Interview with our Tech Recruiter + Final interview
- Offer 🎉
- Onboarding with full Ubiminds support
Why Ubiminds?
With 9 years in the market and GPTW-certified, Ubiminds connects Latin American tech professionals with software companies in the US and Canada . Hundreds of professionals in data, design, product, and engineering are already growing in North American teams with our support . We're with you throughout the entire journey — Recruitment, Legal, Accounting, PeopleOps, and career guidance — so you can thrive internationally with confidence .
Ready to go global? Apply now — it takes less than 5 minutes .
Source: the employer's careers page. Last checked 2026-09-30. Posted 2026-09-10.