Privacy and Security Engineer
Prove the privacy and security properties we claim. Find abuse paths, harden trust boundaries, and verify controls.
RemoteUSD 246,000/year
Anistratenco is building a longitudinal health platform. Health Assistant brings conversations, records, and goals into a context people can inspect and correct. The underlying systems must support more products as that context grows. This full-time role is remote within the United States.
The mandate
Map trust boundaries across identity, files, models, storage, and deletion. Prioritize failure paths by exposure and impact.
Specify controls, verify them with repeatable tests, and make residual risk and incident ownership explicit before product expansion.
Show us the work
Send two files: a complete project case study and a proposal for this role. No CV or cover letter. Use public evidence and synthetic examples where needed. AI tools are welcome; the technical decisions, evidence, and proposed execution must withstand review.
Project case study
Document one substantial project from the original problem through launch and subsequent results. Explain the team, your own scope, timeline, constraints, architecture or operating stack, key decisions, implementation, and what changed along the way. Include work you can substantiate, a dated baseline, the measurement method and denominator, and the measured result. Discuss a failed approach or tradeoff. Label estimates and evidence you cannot verify.
Show a complete, authorized security or privacy engagement you carried from discovery through remediation and verification. Describe the asset, written scope, trust boundaries, abuse path, safe reproduction, affected controls, remediation, regression tests, and residual risk. Name the tools and your contribution, with measurable change in exposure, detection, or response time.
Role proposal
Reverse engineer the public deployment and find the most consequential problems in the current site and stack. This brief authorizes bounded live penetration testing of anistratenco.com public pages and accounts you control, under our responsible-disclosure rules. Use modest traffic; do not disrupt service, test third-party systems, use social engineering, or access another person's data. Stop at proof and report findings privately. Show sanitized reproduction, impact, root cause, and which observations are verified versus inferred. Then propose your own six-month security and privacy program: the first fixes you would ship, exact tools and stack, regression tests, owners, incident path, and measures of reduced exposure. Explain how the controls extend to files, model access, permissions, and deletion across the platform.