Senior Security / QA Lead | 12 weeks+ (569)
IT Services and IT Consulting · 51-200 employees
About the role
You will design and lead adversarial security testing to validate platform integrity, including multi-tenant isolation and audit-chain tamper-resistance. The role involves ranking security findings, providing clear reproduction steps, and ensuring all governance rules resolve through the live intake path.
What they look for
Requirements
The ideal candidate possesses a strong background in security testing, penetration testing, and hands-on experience with Python and multi-tenant SaaS architectures. You must be capable of working against a green-CI merge gate and producing rigorous, reproducible defect reports.
Benefits
Full description
SENIOR SECURITY / QA LEAD
About the opportunity
Lead adversarial security testing, validate deterministic decision paths, and prove audit-trail tamper resistance for an enterprise-ready AI-driven platform.
About our client
Our client is preparing two AI-driven platforms for enterprise readiness, with a focus on security, correctness, and financial integrity ahead of a production launch.
What you'll do
• Design and lead adversarial security testing of the deterministic decision path.
• Attempt to defeat default-DENY, escalate privileges, or cross tenant boundaries, and prove that the boundaries hold.
• Test multi-tenant isolation and owner-versus-customer scoping through the platform’s roster subsystem, using real tenant-scoped identities.
• Verify the tamper-resistance of the hash-chained audit trail, including append-only behavior, hash-chain linkage, and detection of attempted mutation.
• Validate authentication and authorization across tenant and operator roles.
• Review and extend the existing per-module freeze-audit self-tests.
• Ensure every governance rule resolves through the live intake path to a real engine record.
• Rank findings by severity and provide clear reproduction steps in GitHub Issues.
• Keep findings in the same line of sight as the freeze-audit CI gate and uphold the merge gate (nothing lands unless freeze-audit CI is green).
• Partner with the client on architectural sign-off for any governance-core change.
What you bring (must-haves)
• Strong security-testing background, including penetration testing, authorization/access-control testing, or security QA against systems where boundary failure is the primary risk.
• Hands-on experience with Python and comfort reading a real codebase to design tests against it.
• Experience with multi-tenant SaaS and a practical understanding of tenant isolation failure modes.
• Practical understanding of cryptographic audit trails / hash chaining and how tamper-evidence is proven.
• Experience with Docker and CI-based workflows, including GitHub Actions or equivalent.
• Ability to work against a green-CI merge gate.
• Proficiency with Postgres for validating durable state and persistence.
• Clear written English.
• Strong ability to produce rigorous, reproducible defect reports.
Bonus points for (nice-to-haves)
• Experience testing policy engines, authorization systems, or agentic-AI guardrails.
• Exposure to SOC 2 controls and evidence expectations.
• Familiarity with Render or comparable container hosting.
• Background working in a regulated or safety-critical domain.
Perks & benefits
💻 Equipment provided — none of that "bring your own device" stuff here
🛡️ Full back-office support — Legal, Accounting, HR Business Partner, and Delivery team
🧭 Career and cultural mentoring — how to show up, stand out, and navigate US work culture
🗣️ Free English lessons with a native speaker
🤝 Referral bonus — recommend Ubi to your tech friends and get paid for it
🏖️ Florianópolis HQ always open — 100% remote, but the office is there whenever you want it.
How the process works
• Interview with our Tech Recruiter (+ quick AI assessment, if needed)
• Client interview process (varies by company)
• Offer 🎉
• Onboarding with full Ubiminds support
Why Ubiminds?
With 9 years in the market and GPTW-certified, Ubiminds connects Latin American tech professionals with software companies in the US and Canada. Hundreds of professionals in data, design, product, and engineering are already growing in North American teams with our support. We're with you throughout the entire journey — Recruitment, Legal, Accounting, PeopleOps, and career guidance — so you can thrive internationally with confidence.
Ready to go global? Apply now — it takes less than 5 minutes.
\n
\n
Similar roles
-
Team Member - Offsite Audit, Concurrent Audit & QA| Mumbai
CSB Bank Mumbai, Maharashtra, India
-
Manufacturing Floor & QA Supervisor - HOLT Manufacturing
HOLT Group Waco, Texas, United States
-
QA Lab Relief III - Visalia - Shift Flex
Ventura Coastal, LLC Visalia, California, United States · $51K/yr
-
QA Lab Relief II - Visalia - Shift Flex
Ventura Coastal, LLC Visalia, California, United States · $49K/yr
-
Senior Manager, QA Compliance
Sarepta Therapeutics Andover, Massachusetts, United States · $136K–$170K/yr
-
Senior QA Engineer / Analyst
Perseus Group, Constellation Software Jacksonville, Florida, United States