Padmi

Contract Application Security Engineer / Penetration Tester

ChennaiPosted 1 month ago
CybersecurityMid-levelFull Time; Regular
Apply at Verixa

Opens the source posting on shine.com

Source description

About the role

View original

Company: Navira Quality Systems developer of the Verixa governed-AI workflow platform for regulated life sciences Engagement type: Independent contract (fixed-scope, ~23 weeks; option to retain for remediation retest)Location:Remote (US or India hours); occasional overlap with founder/engineering Reports to: Founder / CEO (acting product & QA authority), coordinating with the fractional vCISO Contact: Why this engagement Verixa is a multi-tenant SaaS platform used for regulated pharmaceutical quality workflows (GxP; 21 CFR Part 11 / EU Annex 11 posture). The codebase is substantially built and entering a hardening and validation phase ahead of first design partners. We need an independent application-security specialist to perform a focused secure-code review and authorized penetration test, produce a defensible findings report, and retest fixes. This is a gate before any customer engagement not a checkbox. You must be independent of the team that wrote the code. Your job is to try to break it and to document exactly how. Environment / stack TypeScript monorepo: Node/Express-style backend, React + Vite frontend, shared schema/validation (Zod). PostgreSQL with Row-Level Security (RLS) and an application tenant-isolation layer (per-tenant context enforcement). Multi-tenant SaaS; per-tenant data isolation is a core security property. Auth: session/JWT, RBAC, e-signature and human-in-the-loop (HITL) approval flows, hash-chained audit trail. Cloud: AWS (US-East and Mumbai regions); AI providers Anthropic and Azure OpenAI reached as subprocessors. Non-production test environment provided; testing is against non-prod with synthetic data only. Scope of work: Authenticated and unauthenticated penetration test of the web application and REST API (OWASP Top 10 / ASVS-aligned). Multi-tenant isolation testing (priority): attempt cross-tenant data access; verify RLS is enforced on every path and that the application tenant-isolation layer cannot be bypassed; probe tenant-scoping on IDs, filters, exports and bulk operations. Authentication & SSO review (priority): review the auth flows including any development/mock SSO fallback paths; session handling, token lifecycle, MFA/SSO, password and lockout policy. Authorization / RBAC review: privilege escalation, IDOR/BOLA, role-boundary and segregation-of-duties enforcement (including on approval, e-signature and disposition actions). Secrets & configuration review: secrets handling, default/hardcoded credentials, environment configuration, key management, and any unimplemented secret-provider paths. Secure code review (targeted): injection (SQL/command/XSS), audit-trail and e-signature integrity (append-only, non-repudiation), input validation boundaries, error handling and information leakage; review of type-safety debt as a defect-density signal. AI/LLM-specific risks: prompt injection, cross-tenant data leakage via retrieval/inference, provider egress boundaries, and handling of model inputs/outputs in the audit trail. Dependency & SAST scan: SCA for known-vulnerable dependencies; static analysis pass with triage of results. Remediation retest: verify fixes for High/Critical findings after the engineering team remediates. Deliverables: Rules-of-Engagement and scope sign-off before any testing. Penetration test report: each finding with severity (CVSS), business/regulatory impact, reproduction steps, evidence, and specific remediation guidance. Secure code review findings in the same format. Remediation retest report and a short attestation/summary letter suitable for sharing with design partners and answering security questionnaires (mapped where possible to SOC 2 / ISO 27001 control areas). Optional: prioritized remediation backlog the engineering team can execute directly. Required experience 5+ years hands-on application security / penetration testing, with demonstrable web-app and API pentest experience on multi-tenant SaaS. Deep, practical understanding of tenant isolation, RLS, authorization (IDOR/BOLA), and auth/SSO attack patterns. Comfortable reading TypeScript/Node and SQL (PostgreSQL); able to do targeted secure code review, not just black-box testing. Cloud security fundamentals on AWS. Certification such as OSCP, OSWE, GWAPT, GPEN, CREST CRT/CCT (or equivalent demonstrable track record). Ability to write clear, reproducible, developer-actionable reports. Can operate independently and to a fixed timeline. Nice to have Prior work in regulated / healthcare / pharma / fintech or exposure to 21 CFR Part 11 / GxP / data-integrity (ALCOA+) expectations. LLM/AI application security experience (prompt injection, RAG data-leakage, provider egress). Experience producing evidence toward SOC 2 / ISO 27001 r Company: Navira Quality Systems developer of the Verixa governed-AI workflow platform for regulated life sciences Engagement type: Independent contract (fixed-scope, ~23 weeks; option to retai

One address, no account. We’ll tell you when matching roles go live.

More at Verixa

Related open roles

View all roles