All roles
Security

Application Security Engineer / Penetration Tester — Contract

SecurityRemote (US or India hours)RemoteContract · 2–3 weeksPosted Jul 23, 2026

About the role

An independent, fixed-scope secure-code review and authorized penetration test of the Verixa platform — multi-tenant isolation, auth/SSO, RBAC and AI/LLM risks — with a defensible findings report and remediation retest, as a gate before first design partners.

Verixa is a multi-tenant SaaS platform used for regulated pharmaceutical quality workflows (GxP; 21 CFR Part 11 / EU Annex 11 posture). The codebase is substantially built and entering a hardening and validation phase ahead of first design partners. We need an independent application-security specialist to perform a focused secure-code review and authorized penetration test, produce a defensible findings report, and retest fixes. This is a gate before any customer engagement — not a checkbox. You must be independent of the team that wrote the code: the engagement is sponsored by Navira Quality Systems, independent of the Sense7ai implementation team. Your job is to try to break it and to document exactly how. You will report to the founder/CEO (acting product & QA authority), coordinating with the fractional vCISO, with occasional overlap with founder/engineering hours.

About Verixa

Verixa is a governed-AI workflow platform for regulated life sciences, built by Navira Quality Systems. We apply bounded AI assistance inside regulated quality workflows — deviation investigation, RCA, CAPA, audit preparation — with human review, source traceability, controlled approvals and workflow-level audit records on every AI-assisted step. AI can propose; qualified humans determine and approve the regulated decision.

The product is built and internally tested, and we are entering paid design-partner engagements with emerging pharma, biotech and CDMO quality teams — India first, US in parallel. The founder spent 20+ years in pharma quality (Genentech/Roche, BMS, Arcellx, Alumis) and leads every sale personally. You would be hire #1 in the Hyderabad market team.

What you’ll do

  • Authenticated and unauthenticated penetration test of the web application and REST API (OWASP Top 10 / ASVS-aligned).
  • Multi-tenant isolation testing (priority) — attempt cross-tenant data access; verify RLS is enforced on every path and that the application tenant-isolation layer cannot be bypassed; probe tenant-scoping on IDs, filters, exports and bulk operations.
  • Authentication & SSO review (priority) — review the auth flows including any development/mock SSO fallback paths; session handling, token lifecycle, MFA/SSO, password and lockout policy.
  • Authorization / RBAC review — privilege escalation, IDOR/BOLA, role-boundary and segregation-of-duties enforcement (including on approval, e-signature and disposition actions).
  • Secrets & configuration review — secrets handling, default/hardcoded credentials, environment configuration, key management, and any unimplemented secret-provider paths.
  • Secure code review (targeted) — injection (SQL/command/XSS), audit-trail and e-signature integrity (append-only, non-repudiation), input validation boundaries, error handling and information leakage; review of type-safety debt as a defect-density signal.
  • AI/LLM-specific risks — prompt injection, cross-tenant data leakage via retrieval/inference, provider egress boundaries, and handling of model inputs/outputs in the audit trail.
  • Dependency & SAST scan — SCA for known-vulnerable dependencies; static analysis pass with triage of results.
  • Remediation retest — verify fixes for High/Critical findings after the engineering team remediates.

What we’re looking for

  • 5+ years hands-on application security / penetration testing, with demonstrable web-app and API pentest experience on multi-tenant SaaS.
  • Deep, practical understanding of tenant isolation, RLS, authorization (IDOR/BOLA), and auth/SSO attack patterns.
  • Comfortable reading TypeScript/Node and SQL (PostgreSQL); able to do targeted secure code review, not just black-box testing.
  • Cloud security fundamentals on AWS.
  • Certification such as OSCP, OSWE, GWAPT, GPEN, CREST CRT/CCT (or equivalent demonstrable track record).
  • Ability to write clear, reproducible, developer-actionable reports.
  • Can operate independently and to a fixed timeline.

Nice to have

  • Prior work in regulated / healthcare / pharma / fintech, or exposure to 21 CFR Part 11 / GxP / data-integrity (ALCOA+) expectations.
  • LLM/AI application security experience (prompt injection, RAG data-leakage, provider egress).
  • Experience producing evidence toward SOC 2 / ISO 27001 readiness.

Environment & stack

  • TypeScript monorepo: Node/Express-style backend, React + Vite frontend, shared schema/validation (Zod).
  • PostgreSQL with Row-Level Security (RLS) and an application tenant-isolation layer (per-tenant context enforcement).
  • Multi-tenant SaaS; per-tenant data isolation is a core security property.
  • Auth: session/JWT, RBAC, e-signature and human-in-the-loop (HITL) approval flows, hash-chained audit trail.
  • Cloud: AWS (US-East and Mumbai regions); AI providers Anthropic and Azure OpenAI reached as subprocessors.
  • Non-production test environment provided; testing is against non-prod with synthetic data only.

Deliverables

  • Rules-of-Engagement and scope sign-off before any testing.
  • Penetration test report — each finding with severity (CVSS), business/regulatory impact, reproduction steps, evidence, and specific remediation guidance.
  • Secure code review findings in the same format.
  • Remediation retest report and a short attestation/summary letter suitable for sharing with design partners and answering security questionnaires (mapped where possible to SOC 2 / ISO 27001 control areas).
  • Optional: prioritized remediation backlog the engineering team can execute directly.

Engagement terms

  • Independent contractor, fixed-scope statement of work; est. 2–3 weeks of testing plus a retest window.
  • Testing only against the provided non-production environment with synthetic data; no production access, no real customer/PHI data.
  • Signed NDA, mutual authorization letter / rules of engagement, and agreed data-handling terms required before work begins.
  • All findings, tooling output and artifacts are the property of Navira Quality Systems and must be securely returned/destroyed on completion.
  • Work product must be original; report ownership and confidentiality per the contract.

Compensation. Fixed-fee or day-rate, quoted against the scope above.

We hire on merit; quality people know evidence beats narrative.