Ubiminds

Senior Security / QA Lead | 12 weeks+ (569)

Ubiminds

IT Services and IT Consulting · 51-200 employees

Sep 10
Remote qa Senior (5-10 yrs) Full-time Contractor
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will design and lead adversarial security testing to validate platform integrity, including multi-tenant isolation and audit-chain tamper-resistance. The role involves ranking security findings, providing clear reproduction steps, and ensuring all governance rules resolve through the live intake path.

What they look for

Security testing Penetration testing Python Multi-tenant SaaS Cryptographic audit trails Hash chaining Docker GitHub Actions Postgres Authorization testing Access-control testing Defect reporting CI/CD workflows Adversarial testing

Requirements

The ideal candidate possesses a strong background in security testing, penetration testing, and hands-on experience with Python and multi-tenant SaaS architectures. You must be capable of working against a green-CI merge gate and producing rigorous, reproducible defect reports.

Benefits

Career guidance HR support Concierge services Remote-first policy MacBook provided Tech talks Chapter meetings English lessons Referral bonus Office amenities

Full description

SENIOR SECURITY / QA LEAD

About the opportunity

Lead adversarial security testing, validate deterministic decision paths, and prove audit-trail tamper resistance for an enterprise-ready AI-driven platform.

About our client

Our client is preparing two AI-driven platforms for enterprise readiness, with a focus on security, correctness, and financial integrity ahead of a production launch.

What you'll do

• Design and lead adversarial security testing of the deterministic decision path.

• Attempt to defeat default-DENY, escalate privileges, or cross tenant boundaries, and prove that the boundaries hold.

• Test multi-tenant isolation and owner-versus-customer scoping through the platform’s roster subsystem, using real tenant-scoped identities.

• Verify the tamper-resistance of the hash-chained audit trail, including append-only behavior, hash-chain linkage, and detection of attempted mutation.

• Validate authentication and authorization across tenant and operator roles.

• Review and extend the existing per-module freeze-audit self-tests.

• Ensure every governance rule resolves through the live intake path to a real engine record.

• Rank findings by severity and provide clear reproduction steps in GitHub Issues.

• Keep findings in the same line of sight as the freeze-audit CI gate and uphold the merge gate (nothing lands unless freeze-audit CI is green).

• Partner with the client on architectural sign-off for any governance-core change.

What you bring (must-haves)

• Strong security-testing background, including penetration testing, authorization/access-control testing, or security QA against systems where boundary failure is the primary risk.

• Hands-on experience with Python and comfort reading a real codebase to design tests against it.

• Experience with multi-tenant SaaS and a practical understanding of tenant isolation failure modes.

• Practical understanding of cryptographic audit trails / hash chaining and how tamper-evidence is proven.

• Experience with Docker and CI-based workflows, including GitHub Actions or equivalent.

• Ability to work against a green-CI merge gate.

• Proficiency with Postgres for validating durable state and persistence.

• Clear written English.

• Strong ability to produce rigorous, reproducible defect reports.

Bonus points for (nice-to-haves)

• Experience testing policy engines, authorization systems, or agentic-AI guardrails.

• Exposure to SOC 2 controls and evidence expectations.

• Familiarity with Render or comparable container hosting.

• Background working in a regulated or safety-critical domain.

Perks & benefits

💻 Equipment provided — none of that "bring your own device" stuff here

🛡️ Full back-office support — Legal, Accounting, HR Business Partner, and Delivery team

🧭 Career and cultural mentoring — how to show up, stand out, and navigate US work culture

🗣️ Free English lessons with a native speaker

🤝 Referral bonus — recommend Ubi to your tech friends and get paid for it

🏖️ Florianópolis HQ always open — 100% remote, but the office is there whenever you want it.

How the process works

• Interview with our Tech Recruiter (+ quick AI assessment, if needed)

• Client interview process (varies by company)

• Offer 🎉

• Onboarding with full Ubiminds support

Why Ubiminds?

With 9 years in the market and GPTW-certified, Ubiminds connects Latin American tech professionals with software companies in the US and Canada. Hundreds of professionals in data, design, product, and engineering are already growing in North American teams with our support. We're with you throughout the entire journey — Recruitment, Legal, Accounting, PeopleOps, and career guidance — so you can thrive internationally with confidence.

Ready to go global? Apply now — it takes less than 5 minutes.

\n

\n

Similar roles